Hi, please run HJT again, and check off the following items
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\SYSTEM32\Userinit.exe,winusmx.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O20 - Winlogon Notify: URL - C:\WINNT\system32\mdidlpm.dll (file missing)
O23 - Service: Microsoft Windows Driver Service (Windows Driver Service) - Unknown owner - C:\WINNT\devldr32.exe
**Read here about devldr32.exe. Because you said it seems to be the rpoblem, I tink it may be the virus form of it, though it can be a legit sound card driver.**
Click Fix Checked.
___________________________________________________
We need to remove a NT Service
Do the following:Start -> Run
*type services.msc
*click OK
The Services Management Console opens - do the following:Click the Extended tab.
*Scroll down until you find Microsoft Windows Driver Service (Windows Driver Service)
*Click on the service to highlight it.
*Click Stop
*Right-Click on Microsoft Windows Driver Service (Windows Driver Service) .
*Click on 'Properties'
*Select the 'General' tab
*Click the down-arrow on the right-hand side on the 'Start-up Type' box
*From the drop-down menu, select ' Disabled'
*Click the 'Apply' tab
*Click 'OK'
Now:[list=type]Open HJT
*Click on Config>>Misc Tools>>Delete an NT Service
*Type Microsoft Windows Driver Service (Windows Driver Service) in the space provided and click 'OK'.
*The program will ask you to REBOOT --- Accept
*Attach another HijackThis log[/ list]
___________________________________________________
Please download ewido anti-malware it is a free version of the program.Install ewido anti-malware
When installing, under "Additional Options" uncheck..Install background guard
Install scan via context menu
Launch ewido, there should be an icon on your desktop, double-click it.
The program will now open to the main screen.
When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
You will need to update ewido to the latest definition files.On the left hand side of the main screen click update.
Then click on Start Update.
The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful" )
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates
Once the updates are installed do the following:Open up Ewido
Click on scanner
Click on Complete System Scan and the scan will begin.
You will be prompted to clean the first infection.
Select "Perform action on all infections", then proceed.
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Click Save report.
Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.
Reboot.
____________________________________________________
Follow instructions here now. To remove Qoologic.
http://forums.majorgeeks.com/showthread.php?t=74268
_____________________________________________________
Post a new HJT log, and teh ewido log