Here's how I solved this problem:
I went to
c:\documents and settings\all users\start menu\programs\startup
and deleted winlgn.exe (which might also be winlogon.exe or winlogin.exe or some such variant). Check the properties of the file you find there; if it is a fairly new file, it is probably a hijacker.
I then ran a deep registry scan with the latest version of AdAware and deleted the probable browser hijack files.
Next I ran HijackThis just to double check that AdAware had gotten everything.
Then I ran SpyBot.
Also, if you find a file called dllhelp.exe, it is probably a hijacker also so delete it.
Then reboot.
That's my story; can't guarantee it will work for you.
judgehopkins
judgehopkins
June 2004