Hi, it appears a you also have a bit of vundo happening. So the next step…
Open HJT, run a system scan only, check mark these lines if present
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O4 - HKLM..\Run: [dcb5bdf7] rundll32.exe “C:\WINDOWS\system32\wbaqlcwi.dll”,b
O4 - HKLM..\Run: [BMdf868e6b] Rundll32.exe “C:\WINDOWS\system32\cbgtuucu.dll”,s
O20 - Winlogon Notify: qomnnkh - qomnnkh.dll (file missing)
Close all other browsers/windows, click fix, close HJT.
It is vitally important that combofix is renamed before it is even started to download
Please download ComboFix from Here or Here to your Desktop.
Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop
[*]If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to “Always ask me where to Save the files”.
[*]During the download, rename Combofix to Combo-Fix as follows:
http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_FF.gif
http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_rename.gif
[]It is important you rename Combofix during the download, but not after.
[]Please do not rename Combofix to other names, but only to the one indicated.
[]Close any open browsers.
[]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix
[*]Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
[*]Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don’t know how to disable it, please ask.
[*]Close any open browsers.
[*]WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
[]Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
[]If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
[*]Double click on combofix.exe & follow the prompts.
[*]When finished, it will produce a report for you.
[*]Please post the “C:\ComboFix.txt” along with a new HijackThis log for further review.
Note: Do not mouseclick combofix’s window while it’s running. That may cause it to stall
See you in a bit. combofix usually takes about 20 minutes. You can attach the logs by using the additional options button on the reply page, Yuo may have to scroll down a bit to see the browse button.