Hi dustdogz.
===============
Let's look for, and delete, any program segments(prefetches) that might be present, and are associated with the 'problems' we're trying to remove from this system. To do this, let's:
1) Click "Start | Search", then search for each of these program's base name(s), in all files and folders:
m?hta.exe*
2) Then if any are found in the 'prefetch' folder, delete them.
Look closely, since the 'base' name will have a bunch of random numbers and letters attached to it.
===============
Run HiJackThis then:
1. Click "Config..."
2. Click "Misc Tools"
3. Click "Open Process manager"
-
Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:
C:\Documents and Settings\Dustin\Application Data\astr.exe
C:\WINDOWS\system32\m?hta.exe
Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain.
===============
Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:
regsvr32 /u qmhbhjxc.dll
It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.
===============
Run HiJackThis and click "Scan", then check(tick) the following, if present:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?T...ilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {054CECEC-2971-21F1-7D82-5087ECF3BC9D} - C:\WINDOWS\system32\qmhbhjxc.dll
O2 - BHO: (no name) - {0C4CECEA-2907-5387-7D8B-22879FF6BCEE} - C:\WINDOWS\system32\qmhbhjxc.dll
O2 - BHO: (no name) - {AF9ECF1C-0187-5E05-8A3F-7BC5397A1496} - (no file)
O3 - Toolbar: (no name) - {2CA511C5-C677-4e33-A018-EADF07E08299} - (no file)
O4 - HKCU\..\Run: [Tbsa] C:\Documents and Settings\Dustin\Application Data\astr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
...(Unless you've set these with a anti-spyware program like SpyBot's Immunize feature, have HiJackThis fix this.)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
Now, with all windows closed except HiJackThis, click "Fix checked".
===============
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
files...
C:\Documents and Settings\Dustin\Application Data\astr.exe
C:\WINDOWS\system32\qmhbhjxc.dll
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from " Safe Mode ".
===============
Run the PurityScan uninstaller.
Post back a new log, and let me know how everything goes.