First, right-click on an empty area of your desktop and select New, Folder; give the new folder a name (something like HJT or HijackThis), and then drag the hijackthis.exe icon that is on your desktop into the new folder.
Next, download, install, update, and run these utilities:
CWShredder -- http://www.intermute.com/spysubtract/cwshredder_download.html
about:Buster -- http://www.majorgeeks.com/download4289.html
HSRemove -- http://www.majorgeeks.com/download4286.html
PurityScan uninstaller -- http://www.purityscan.com/uninstall.html
CCleaner –- http://www.filehippo.com/download/Qi6RR0U86febzhqUrQQIBQ2/download.html (don't run this one yet)
Then, scan with HJT and have it fix the following entries:
O2 - BHO: (no name) - {06CBB302-3027-2876-B64E-B7FB3EDC4AF2} - (no file)
O2 - BHO: (no name) - {098B2816-B4D3-3673-D079-F2C9806EDCDE} - (no file)
O2 - BHO: (no name) - {530B7D08-CAE3-EA46-E81F-C9EE8580BEBD} - (no file)
O2 - BHO: (no name) - {570B7D7C-CAE3-9147-E86D-BFEE8B80BECE} - (no file)
O2 - BHO: (no name) - {B333FFD7-73DB-5379-54CF-1EF25F8EC6AF} - C:\WINDOWS\System32\yzsrqvtv.dll
O2 - BHO: (no name) - {BE709C45-AFC1-EC7A-3096-3BB6E6204E4F} - C:\WINDOWS\System32\atpcyyyk.dll
O2 - BHO: (no name) - {CAD9FD7F-C0C0-F76C-BF7B-0F88956FE05A} - (no file)
O4 - HKLM\..\Run: [Win32] C:\Win32\dll\Win32k.exe -starthide C:\Win32\dll\Win32.exe -local
O4 - HKLM\..\Run: [f405760d6a13] C:\WINDOWS\System32\basesrv2.exe
O4 - HKLM\..\Run: [ndupinwx] C:\WINDOWS\System32\ndupinwx.exe
O4 - HKLM\..\Run: [dkfqomrq] C:\WINDOWS\System32\dkfqomrq.exe
O4 - HKCU\..\Run: [Sjjd] C:\WINDOWS\System32\??chost.exe
O4 - HKCU\..\Run: [Notn] C:\Program Files\apsi\wtta.exe
If this IP address is not related to your ISP, have HJT fix this O15 entry as well --
O15 - Trusted IP range: http://66.206.11.125
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binar...StatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
Close any open windows, other then HijackThis, and hit Fix checked.
In order to view some of the files and folders here, you will need to set your system up accordingly. Open Windows Explorer, go to Tools, and in Folder Options, select Show hidden files and folders, and uncheck Hide protected operating system files.
Go to the following locations and delete the highlighted files:
C:\Win32\dll\Win32k.exe
C:\WINDOWS\System32\yzsrqvtv.dll
C:\WINDOWS\System32\atpcyyyk.dll
C:\WINDOWS\System32\basesrv2.exe
C:\WINDOWS\System32\ndupinwx.exe
C:\WINDOWS\System32\dkfqomrq.exe
C:\WINDOWS\System32\??chost.exe
C:\Program Files\apsi\wtta.exe
Do a search for these files and delete any instances found:
Dist006.exe
Setup1024.exe
Juocztuz.exe
Aclui874.exe
Basesrv2.exe
Regsync.exe
Installerv3.exe
If any of these files cannot be deleted, please reboot into Safe Mode and try again. Let us know which, if any, still could not be deleted.
Open Firefox and go to Tools, Options, and then click on Privacy (padlock icon on the left); click on the Clear All button.
Now run CCleaner.
Do you know what this file is? I suspect it's bad, but can't find any info on it. If you don't know what it is, please go to the file, right-click on it, select Properties, and give us whatever info you can on it (Company, version, etc.) --
C:\WINDOWS\System32\authz859.exe
Reboot, close any open browser windows, scan with HijackThis, and post a new log please.