Hi, please run HJT again, select Do system scan only and check the following.
O1 - Hosts: 134.96.33.102 crmud01
O1 - Hosts: 134.96.33.103 crmud02
O1 - Hosts: 134.96.33.105 crmud04
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\DOWNLO~1\CnsHook.dll
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\04 Other\qqlite_06rc\QQ.EXE
O9 - Extra 'Tools' menuitem: 腾讯QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\04 Other\qqlite_06rc\QQ.EXE
O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\04 Other\qqlite_06rc\QQIEHelper.dll
O9 - Extra 'Tools' menuitem: QQ炫彩工具设置 - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - D:\04 Other\qqlite_06rc\QQIEHelper.dll
O9 - Extra button: Instant Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - http://cn.zs.yahoo.com/cnsbutton.ht...ns&btn=yahoomsg (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.ht...=cns&btn=repair (file missing)
O9 - Extra 'Tools' menuitem: Repair Browser - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} - http://cn.zs.yahoo.com/cnsbutton.ht...=cns&btn=repair (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.ht...e=cns&btn=clean (file missing)
O9 - Extra 'Tools' menuitem: Clean Internet access record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} - http://cn.zs.yahoo.com/cnsbutton.ht...e=cns&btn=clean (file missing)
Close all browsers and click Fix Checked
------------------------------------------------------------------------
There are still more infections, but we are going to have the scanners knock them out for us.
Download the Free trial version of Spysweeper
http://www.webroot.com/consumer/pro...&rc=4129&ac=tsg
Update the defintions and run it, let it remove whatever it finds.
Then download ewido
www.ewido.net - Install. Update. Scan. Remove anything it finds.
-------------------------------------------------------------------------
Post new HJT log, and the ewido log