xojie
First thing, MOVE HJT into its OWN directory, NOT in your Desktop.
Reboot in Safe Mode
Kill these running processes first with Task Manager, if you can:
C:\WINDOWS\winhh32.exe
C:\WINDOWS\system32\javala.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\7.tmp.exe
With NO other programs open, run HJT and let it FIX:
C:\WINDOWS\winhh32.exe
C:\WINDOWS\system32\javala.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us4nb.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cwsel.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\cwsel.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\cwsel.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cwsel.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\cwsel.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://srch-us4nb.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {E6729088-50CA-1D40-3B9D-AA2D52D24BF7} - C:\WINDOWS\system32\ipyn32.dll
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [javala.exe] C:\WINDOWS\system32\javala.exe
O4 - HKLM\..\Run: [7.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\7.tmp.exe 0 10001
O4 - HKLM\..\Run: [7.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\7.tmp.exe 0 10001
O4 - Global Startup: Windows Timer.hta
O16 - DPF: ChatSpace Full Java Client 3.1.0.235N -
http://205.177.13.50/Java/cfsn31235.cab
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) -
http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CF2D61ED-985C-4DC8-910C-B635E43CB1B5} (FTCChat Control) -
http://funteenchat.com/FTCChat.cab
O23 - Service: Network Security Service (NSS) - Unknown - C:\WINDOWS\winhh32.exe
When done, delete the crap, whatever is left:
C:\WINDOWS\winhh32.exe
C:\WINDOWS\system32\javala.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp (anything in this directory!)
C:\WINDOWS\system32\cwsel.dll
C:\WINDOWS\system32\ipyn32.dll
C:\Program Files\WildTangent (anything in this DIR including the DIR itself)
Timer.hta (wherever that is)