Hello Kevin, you ran this scan in safe mode... it does not show us everything that is going on. Use normal mode.
Go to add/remove pgms and remove these :
NewDotNet
RXToolBar
Need2Find
==Download SmitfraudFix (by S!Ri) from http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract the content (a folder named SmitfraudFix) to your Desktop.
- Restart your computer in safe mode.
- Open the SmitfraudFix folder and double-click SmitfraudFix.cmd, select option #2 - Clean [type 2 and Enter]
You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer Y and Enter [which will remove the desktop background and clean registry keys associated with the infection].
The tool will next check if wininet.dll is infected- if it is you will be prompted to replace the file ; type Y and press "Enter".
It will also create a log named rapport.txt in the root of your drive, eg: Local Disk C:\
Restart in normal Windows.
Change the name of hijackthis.exe to imabunny.exe and make a fresh scan. Please post that plus C:\rapport.txt
[[You may also have to restore your desktop background...
If so, go Start >run, type regedit and . Navigate to this key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
Please export that key: in the left pane highlight system with a lclick, go File, export... , save as bluewall with file type .txt. Close regedit and post that txt file.]]
And I just noticed that this is a duplicate post of yours - Crunchie has posted to you already on your other thread. Please don't do this bumping/reposting... it wastes our time.