Originally Posted by CyFanate
Furthermore I know it's allowed to help. And if the information given by a non-sec member is correct and helpfull, what's the problem then? But okey, if it is a rule, I will stick to it.
Now that could have been in a nicer tone couldn't it? And no , it is not allowed for members to help in the malware section unless they have made clear that they know enough about the subject.
Originally Posted by CyFanate
First of all: The program you use is not my choice.
And are you talking about Ewido ?? One of the best out there..
Hya Sourlang.

Welcome to PCHF , and let's clean that up.
First uninstall these in add/remove programs if present:
YourSiteBar
Media Gateway
180search assistant
Intergrated Search Technologies
ISTBar
P2P Networking
The Best Offers Network
Then disable the wimdows messenger service:
Please download
Shoot The Messenger
Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state — running or disabled — that you desire.
If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.
After that boot in safemode (hit f8 when booting up) and then fix these with
hjt:
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - blank (file missing)
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\Program Files\
YourSiteBar\ysb.dll (file missing)
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\
Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [180sa] c:\program files\
180search assistant\180sa.exe
[b]O4 - HKLM\..\Run: [srevydsj] C:\WINDOWS\
srevydsj.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\
ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\
P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKCU\..\Run: [tbon] C:\PROGRA~1\
TBONBin\tbon.exe /r
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - blank (file missing)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} -
http://static.zangocash.com/cab/180s.../bridge-c9.cab
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - blank
And then manually delete the files in bold.
When done please post a new
hjt log to check.