Please open Notepad, and copy/paste the code in the box below into a new text file. Save it as KillQoo.reg (set Filetype to "All Files") and save it on your Desktop.
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\fyysfffx]
Open Pocket Killbox and Copy & Paste the entries below into the "Full Path of File to Delete"
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\naau.exe
C:\Documents and Settings\Spencer\Start Menu\Programs\Startup\naau.exe
C:\WINDOWS\system32\conres.cpl
C:\WINDOWS\SYSTEM32\datadx.dll
C:\WINDOWS\SYSTEM32\jaarj.dll
C:\WINDOWS\SYSTEM32\sssfsss.dll
C:\WINDOWS\system32\lppxll.exe
As you Paste each entry into Killbox,place a tick by any of these Selections available
"Delete on Reboot"
"Unregister .dll before Deleting"
Click the Red Circle with the White X in the Middle to Delete!
Restart in Safe Mode and Run those files through Killbox once more to be sure nothing survived.
This time place a tick by any of these selections available
"Standard File Kill"
"End Explorer Shell while Killing File"
"Unregister .dll before Deleting"
Now Locate and DoubleClick KillQoo.reg-> Allow it to merge into the Registry!
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lppxll.exe reg_run
Now close all windows other than HiJackThis, then click Fix Checked.
Restart back in Normal Mode and Post a fresh HijackThis log!