Right Click on MyComputer icon and go to properties
Turn Off system restore
open IE and go to TOOLS OPTIONS delete temporary internet files and cookies
do a disk cleanup in your Start/accessories/system tools/ Menu
After the reboot
download
malwarebytes and install
run hijackthis and malwarebytes at the same time
select any files and or keys posted in hijackthis
but on both maiwarebytes and hijackthis click fix at the same time.
then reboot immediatly.if you forget to turn off system restore it will return no matter
reboot once complete, run hijack this and post your log here again
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: {b76c0542-a909-a8bb-aa64-4c876a3b31a2} - {2a13b3a6-78c4-46aa-bb8a-909a2450c67b} - C:\WINDOWS\system32\vcmroh.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O
O4 - HKLM\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s
O4 - HKLM\..\Run: [CPMffddc3ac] Rundll32.exe "c:\windows\system32\yuhisona.dll",a
O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKUS\S-1-5-19\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: avgrsstx.dll vcmroh.dll C:\WINDOWS\system32\nifudoju.dll c:\windows\system32\yuhisona.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O24 - Desktop Component 1: (no name) -
http://mail.google.com/mail/?tab=wm&shva=1#inbox