> Can someone please help me figure out how to find the pervasive code that
> is taking over my browser and eradicate it.
First thing, go off line. That hijacker will phone home and
reload over and over and over. Next, do a search for every file
that is dated at and after the time of infection ... you are looking
for the dropper. It will be there, and hard as hell to find. I've
found it in a 2nd recycle bin directory that is bogus ... also in
a "name" directory in System32 .. there's probably others.
Run AdWare6.0 that has been recently updated ( go to another
computer and dl it ) and delete all that crap. Run Spybot, and
delete all that crap. Reboot. If the stuff comes back .. AND IT
WILL ... search again for the dropper directory, and go delete
the entire directory. Delete Temporary Internet Files .. and
delete the Temp directory ( under local settings ). Go look
at Services and see if you see a weirdo running. See what
directory contains it, and go look there. If there are "new"
dated files in that directory .. that is probably the dropper.
Delete it if you feel safe doing so .. or if Adware or Spybot
has been in that directory. Note: if you are running XP, you
must shut off System Restore .. My Computer > properties
> System Restore .. uncheck box. Also Note: I never do
any of this. I have a whopping big hard drive, and I image
my C-drive. If a hijacker gets me .. I boot to floppy with
recovery disks, and reimage. Screw all that effort. Reimage
takes 30 - 40 minutes, and I spend that time ice skating
johns