Can we look at the MalwareBytes log? there's still this bad dll present in the log.
O20 - AppInit_DLLs: idnhkh.dll
also try running Combofix, if problem persists you might need to reset the router if this is one of those Zlob.DNS.Changer.
Please download ComboFix by sUBs:
http://download.bleep
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.





by: sharkbot221984Posted on 2008-12-10 at 13:44:52ID: 23143558
I didn't see any homepage or search settings in your hijackthis log, those are usually R1 or R0 lines. So it seems that there is still something lurking on the machine still hijacking your web browser. MIght go ahead and run Adaware, and Spybot S&D to see if they catch something as well. What AV did you run against it? Maybe try another one.