Alice,
Global-Finder
http://www.mvps.org/inetexplorer/darnit_2.htm
Always use extreme care when fiddling around in the registry.
This is from Sandi Hardmeiers site - Darnit- B,G, and S:
Search engine/option hijackings:
global-finder.com (in the registry as out.true-counter.com/.../?344012)
searchalot.com
coolwebsearch (appearing in the registry as approvedlinks.com/hp.htm)
(coolwebsearch is also mentioned HERE)
The cleanup: Use Task Manager (ctrl, alt, del) to make sure iedll.exe is not
running. If it is, shut it down. Rename iedll.exe to iedll.old.
Export then delete the following registry keys:
HKCU\Software\Microsoft\Internet Explorer\SearchURL
HKCU\Software\Microsoft\Internet Explorer\Main\Search Bar
HKCU\Software\Microsoft\Internet Explorer\Main\Search Page
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKCU\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant
HKCU\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
HKLM\Software\Microsoft\Internet Explorer\Main\Search Bar
HKCU\Software\Microsoft\Internet Explorer\Main\HomeOldSP
HKCU\Software\Microsoft\Internet Connection Wizard\Shellnext
HKLM\Software\Microsoft\Internet Connection Wizard\Shellnext
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run [iedll]
C:\WINDOWS\iedll.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run [loader]
C:\WINDOWS\LOADER.EXE
NOTE: Loader.exe can be a legitimate Windows file. Do NOT delete or rename
the file - just delete the entry above from the registry!!