Just finished clearing several viruses from a PC. Was still having issues, e.g. http://labs.google.com would go to a Google search page ...

Also, pinging www.google.com would translate to 194.54.90.238

Found one virus had inserted a DNS server of 194.54.90.238 ...

A Google search finds a few comments that this is a known malicious server.

Does it make sense for you to check for that as a DNS entry?

Many thanks!