Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop (in a folder on the desktop is fine) & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=explorer.exe winlogin.exe
O4 - HKLM\..\Run: [NDplDeamon] winlogin.exe
O4 - HKLM\..\Run: [atlzx.exe] C:\WINDOWS\system32\atlzx.exe
O4 - HKLM\..\RunOnce: [ipst32.exe] C:\WINDOWS\system32\ipst32.exe
O4 - HKLM\..\RunOnce: [javavr.exe] C:\WINDOWS\system32\javavr.exe
O4 - HKLM\..\RunOnce: [atlyh32.exe] C:\WINDOWS\system32\atlyh32.exe
O4 - HKLM\..\RunOnce: [mslf.exe] C:\WINDOWS\system32\mslf.exe
O4 - HKLM\..\RunOnce: [apphz32.exe] C:\WINDOWS\apphz32.exe
O4 - HKLM\..\RunOnce: [d3ii.exe] C:\WINDOWS\d3ii.exe
O4 - HKLM\..\RunOnce: [appjh32.exe] C:\WINDOWS\appjh32.exe
O4 - HKLM\..\RunOnce: [apirr.exe] C:\WINDOWS\apirr.exe
O4 - HKLM\..\RunOnce: [netbo32.exe] C:\WINDOWS\system32\netbo32.exe
O4 - HKLM\..\RunOnce: [winlg32.exe] C:\WINDOWS\system32\winlg32.exe
O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe
O4 - HKLM\..\RunOnce: [addgd.exe] C:\WINDOWS\system32\addgd.exe
O4 - HKLM\..\RunOnce: [sdkrf.exe] C:\WINDOWS\sdkrf.exe
O4 - HKLM\..\RunOnce: [d3bs.exe] C:\WINDOWS\system32\d3bs.exe
O4 - HKLM\..\RunOnce: [appqn.exe] C:\WINDOWS\system32\appqn.exe
O4 - HKLM\..\RunOnce: [sdkuo32.exe] C:\WINDOWS\system32\sdkuo32.exe
O4 - HKLM\..\RunOnce: [d3kx32.exe] C:\WINDOWS\system32\d3kx32.exe
O4 - HKLM\..\RunOnce: [sdknt32.exe] C:\WINDOWS\sdknt32.exe
O4 - HKLM\..\RunOnce: [mszi.exe] C:\WINDOWS\mszi.exe
O4 - HKLM\..\RunOnce: [systd32.exe] C:\WINDOWS\systd32.exe
O4 - HKLM\..\RunOnce: [addpp32.exe] C:\WINDOWS\addpp32.exe
O4 - HKLM\..\RunOnce: [ieqs.exe] C:\WINDOWS\system32\ieqs.exe
O9 - Extra button: AOL Toolbar - {1AE2F26C-8E23-4930-A68D-9E681A764001} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {1AE2F26C-8E23-4930-A68D-9E681A764001} - (no file)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)
Run a search for winlogin.exe & delete it.
Download About:buster from http://malwarebytes.biz/AboutBuster.zip and unzip it to your desktop. Do not run yet
Download & instal Adaware from here
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.' Do not run yet
Click here for instructions on how to boot into safe mode.
Boot up in safe mode.
Run About:buster, click OK, Start, and OK again to start the scan. Let it scan and fix everything it finds.
Still in safe mode, do a full system scan with Adaware. When the scan is finished select *next* & place a check in the boxes to the left of what is found & click *next* again. Let it delete those entries.
Reboot your computer in normal mode.
Post a new log without removing anything from it :) .