Hi. First of all you need to update hijackthis to version 1.98.2. Run hijackthis & go to *Config\Misc Tools\Check for update on-line*. If the site is down, go here. Remove the old version by opening the program, going to config\misc tools, then uninstall & exit. You then have to delete the file manually. Unzip the new version into the hijackthis folder.
The following could be the problem file. It is a keylogger which logs every key stroke.
O4 - HKLM\..\RunServices: [WndMsg] C:\WINNT\kl4.cap
Do the following as you also have other pressing stuff such as an hijackrd browser.
Download About:buster from http://malwarebytes.biz/AboutBuster.zip and unzip it to your desktop.
Download & instal Adaware from here
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked':
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yosrx.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\system32\yosrx.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\system32\yosrx.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yosrx.dll/index.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {8EE36A68-FD0C-A0E3-6ED8-6C6AA78C8DF5} - C:\WINNT\ntfc32.dll
O4 - HKLM\..\Run: [ntwv.exe] C:\WINNT\system32\ntwv.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\RunServices: [WndMsg] C:\WINNT\kl4.cap
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocach...etup1.0.0.8.cab
Click here for instructions on how to boot into safe mode.
Boot up in safe mode & delete the following manually;
C:\Program Files\Common Files\CMEII-folder
C:\WINNT\kl4.cap-file
Run About:buster, click OK, Start, and OK again to start the scan. Let it scan and fix everything it finds.
Still in safe mode, do a full system scan with Adaware. When the scan is finished select *next* & place a check in the boxes to the left of what is found & click *next* again. Let it delete those entries.
Reboot your computer in normal mode. Rescan with hijackthis & post another log.
Also go here for Gator removal instructions; http://www.pchell.com/support/gator.shtml
Do you have a firewall? If not, download & install the one from the link in my signature. It's free :).