For information TDL3 and TDL4 infections can and do cause redirects and Firefox is no safer that IE. In fact IE9 is a lot safer than firefox in most respects. Other apparent hijackers are zero access (very nasty), conserv.dll and four or five others that have no specific name.

On completion of this run can you let me know if the redirects have stoppped

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL [2010/03/27 13:32:50 | 000,002,025 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml O3 - HKU\S-1-5-21-4224829323-2091496230-1813202943-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKU\S-1-5-21-4224829323-2091496230-1813202943-1000\..\Toolbar\WebBrowser: (no name) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - No CLSID value found. O3 - HKU\S-1-5-21-4224829323-2091496230-1813202943-1000\..\Toolbar\WebBrowser: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No CLSID value found. O4 - HKU\S-1-5-21-4224829323-2091496230-1813202943-1000..\Run: [ACBHWSN] C:\Users\Jan\AppData\Roaming\lxbcinpaz.dll () O33 - MountPoints2\{af33459d-7952-11df-94a5-001e3366025b}\Shell\AutoRun\command - "" = D:\Startme.exe [2011/10/14 18:05:22 | 000,092,672 | RHS- | C] () -- C:\Users\Jan\AppData\Roaming\lxbcinpaz.dll

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.