TeMerc Update Forum And, speaking of tutorials, here is one for hosts file. https://forums.techguy.org/threads/http-drusearch-com-user3.243861/

  The File Database - Search the file database for more information.

Spybot (erweiterte Version) gestartet > Werkzeuge > System-Start Bei mir hatten sich die Programme hrtcm.exe und szchost.exe eingeschlichen. Also ditch Spykiller.Use Adaware click here and SpyBot click here for free.

The file which is causing you the problem is rundll32.vbe, it's attached itself to hardcorenight.net About rundll32.vbe - there are legitimate files in the system32 folder with the name rundll32 but different file extensions, so make sure you're deleting .vbe

Does this mean I now need additional hosts file blockers as I do with spyware? This is a backup of the registry file.Back in regedit, with "Run" still highlighted, look to the right and find the entry called Windows Security Assistant. Do yourself a favor and study this list....stay away from these sites because they will help themselves to your browser and your computer.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5F1ABCDB-A875-46C1-8345-B72A4567E486} {4528BBE0-4E08-11D5-AD55-00010333D0AD} C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD} {4D5C8C25-D075-11d0-B416-00C04FB90376} C:\WINDOWS\System32\shdocvw.dll

Detects more than 500 potentially unwanted applications. You can use HijackThis for that: http://www.merijn.org/files/hijackthis.zip http://www.spywareinfo.com/~merijn/files/hijackthis.zip Windows XP (5.01.2600 SP1) Windows dir: C:\WINDOWS Windows system dir: C:\WINDOWS\system32 AppData folder: C:\Dokumente und Einstellungen\T\Anwendungsdaten Username: T Infected Registry value: HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL

When ever i log out and back in again browser is hijacked.Used hijack this, report as follows, any help would be appreciated.