AVG alerts users to the presence of, but can't remove it. A brief Google search for was unhelpful. Other anti-virus, anti-trojan programs likewise couldn't remove The HijackThis log showed an item with sphlp32.exe running as well as the following registry items:
O17 - HKLM\System\CCS\Services\Tcpip\..\{496CA85A-13F9-4489-AB84-55CA84EF2642}: NameServer =,

O17 - HKLM\System\CCS\Services\Tcpip\..\{6D5D1233-6D59-40B6-9C60-71346BB03C7F}: NameServer =,

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer =

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer =
Simply inactivating these items from hijack this did not eliminate I began by deleting temporary internet files (not sure it's necessary, but it's good practice). I turned off a new item in the startup files (seen in msconfig). I then searched the registry and deleted items with "sphlp" and "85.255.113"

An AVG scan identified and deleted about 13 clicker files from system restore.