
Boot in safemode again.
copy the text in the quote below, and paste it into a blank notepad window.
Save it as Qoologic.reg and in the "save as" type box choose "all files".
Code:
REGEDIT4
[-HKEY_CLASSES_ROOT\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}]
[-HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9E248641-0E24-4DDB-9A1F-705087832AD6}]
Then fix this entry with hjt:
O4 - HKCU\..\Run: [wjrsx] C:\WINDOWS\system32\bvgawr.exe reg_run
And reboot to normal mode.
Then again post a new hjt log and a new Findqoologic log.























Linear Mode

