Thanks again, but last night before I read you post I had a play around.
hidr.exe and srosa.sys came back, so I booted in safe mode and removed them. It appears one of the IE Add-ons is responsible for re-infecting. I disabled all add-ons in safe mode, now in normal mode IE works fine. Before IE would lockup if it didn't have network access.
The DNS problem is caused by Comodo firewall. Even though I trust an application it is still blocking it, unless I select the 'Skip advanced security checks', in the miscellaneous tab in the application control rule.
I also un-installed avast and installed Comodos antivirus, because the infection kept deleting avast. However Comodo antivirus can't enable the on access scanner. At that point I gave up and went to bed
I'll give fsbl a go this evening and see what it comes up with.