Thanks for the feedback, but you are not done yet
Re-open HJT and this time just do a Scan.
Locate the following and place a tick next to each one:
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O18 - Filter hijack: text/html - {0e6a2db2-3266-49b3-bfd4-928c631b61ea} - C:\WINDOWS\system32\msziptools.dll
Select
Fix to the above, then close HJT
Next, go to Control Panel > Programs Add or Remove and uninstall
MostFun If found.
Restart, and go to
Safe Mode
Safe Mode is accessed by repeatively pressing F8 function key just before Windows Startup. Then select Safe Mode. Log into an Administrator account (this may be your account)
Now, using Windows Explorer, navigate to C:\Program Files\
MostFun\ .... and delete this folder.
You might also do a search for this file:
c:\
softarea51\MostFun-MostFun.exe <--- if found, delete what I've
bolded
Also locate: C:\Program Files\
Vongo and delete the bolded folder there as well.
Next locate C:\WINDOWS\system32\
msziptools.dll and delete the bolded file stated
Restart normally back to Normal Mode
------------------
Once back in Normal Mode, please do the following:
Download Combofix
Lots of info on its use
h e r e
Direct download
h e r e
Locate the downloaded Combofix. Double click on it to run, answering any prompts along the way
Note: during Combofix scan (lasting up to 10mins) your Desktop and clock may reset (all normal)
ComboFix will also restart your computer (eventually) and then (eventually) create a log
Save this log file to be attached to a new reply
Restart back to Normal mode, and attach the Combofix log
Also do another scan with HJT (scan and log file) and attach this to a new reply as well