Run hijackthis again and put a checkmark against these entries....double check
in case you miss anything....
.....then,close all browser and outlook windows and "fix checked"
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about :blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {B549456D-F5D0-4641-BCED-8648A0C13D83} - C:\WINDOWS\BrowserHelper.dll
O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-A0E4-EA6FA787AD2D} - C:\PROGRA~1\POWERS~1\TOOLBAR\PWRSCUZ2.DLL
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
Re-boot and delete:
C:\PROGRAM FILES\MYWEBSEARCH [FOLDER]
Now Ctrl-Alt-Delete and end task on: WBLCG0L5.EXE
[end its process as many times as it takes till its gone]
Re-run HijackThis and "fix" all these entries:
O4 - HKLM\..\Run: [WBLCG0L5.EXE] C:\WINDOWS\WBLCG0L5.EXE /dk
O4 - HKCU\..\Run: [WBLCG0L5.EXE] C:\WINDOWS\WBLCG0L5.EXE /dk
O4 - Startup: MORZE5.lnk = C:\WINDOWS\morze5.exe
O4 - Startup: YTEJ0D4O.lnk = C:\WINDOWS\ytej0d4o.exe
O4 - Startup: A56LPGI0.lnk = C:\WINDOWS\a56lpgi0.exe
O4 - Startup: 89KZ6A6H.lnk = C:\WINDOWS\89kz6a6h.exe
O4 - Startup: RX22PUNR.lnk = C:\WINDOWS\rx22punr.exe
O4 - Startup: OKIW1Q96.lnk = C:\WINDOWS\okiw1q96.exe
O4 - Startup: 69EDPU44.lnk = C:\WINDOWS\69edpu44.exe
O4 - Startup: NQ94817E.lnk = C:\WINDOWS\nq94817e.exe
O4 - Startup: U8BVU0ZI.lnk = C:\WINDOWS\u8bvu0zi.exe
O4 - Startup: 50R350W2.lnk = C:\WINDOWS\50r350w2.exe
O4 - Startup: O6L6A5KK.lnk = C:\WINDOWS\o6l6a5kk.exe
O4 - Startup: ZM40H23N.lnk = C:\WINDOWS\zm40h23n.exe
O4 - Startup: UV1WQL95.lnk = C:\WINDOWS\uv1wql95.exe
O4 - Startup: ZDWZBB0P.lnk = C:\WINDOWS\zdwzbb0p.exe
O4 - Startup: VU5F2DG8.lnk = C:\WINDOWS\vu5f2dg8.exe
O4 - Startup: KJ053GFM.lnk = C:\WINDOWS\kj053gfm.exe
O4 - Startup: M7R61LDR.lnk = C:\WINDOWS\m7r61ldr.exe
O4 - Startup: 00FWKFRZ.lnk = C:\WINDOWS\00fwkfrz.exe
O4 - Startup: O66BP1WP.lnk = C:\WINDOWS\o66bp1wp.exe
O4 - Startup: 67TJEBUM.lnk = C:\WINDOWS\67tjebum.exe
O4 - Startup: MXFV6LF1.lnk = C:\WINDOWS\mxfv6lf1.exe
O4 - Startup: NXI65K20.lnk = C:\WINDOWS\nxi65k20.exe
O4 - Startup: L07881TL.lnk = C:\WINDOWS\l07881tl.exe
O4 - Startup: 00UD5LUN.lnk = C:\WINDOWS\00ud5lun.exe
O4 - Startup: EPBFN492.lnk = C:\WINDOWS\epbfn492.exe
O4 - Startup: 24811TTQ.lnk = C:\WINDOWS\24811ttq.exe
O4 - Startup: VONB17ZH.lnk = C:\WINDOWS\vonb17zh.exe
O4 - Startup: BHYQC0QJ.lnk = C:\WINDOWS\bhyqc0qj.exe
O4 - Startup: L5WU0HDQ.lnk = C:\WINDOWS\l5wu0hdq.exe
O4 - Startup: CL59OOWD.lnk = C:\WINDOWS\cl59oowd.exe
O4 - Startup: YYE44QWZ.lnk = C:\WINDOWS\yye44qwz.exe
O4 - Startup: 4L3T26H7.lnk = C:\WINDOWS\4l3t26h7.exe
O4 - Startup: ON2YB1AJ.lnk = C:\WINDOWS\on2yb1aj.exe
O4 - Startup: DHOBPG09.lnk = C:\WINDOWS\dhobpg09.exe
O4 - Startup: MWIWCGTQ.lnk = C:\WINDOWS\mwiwcgtq.exe
O4 - Startup: POZCOHE0.lnk = C:\WINDOWS\pozcohe0.exe
O4 - Startup: 8EP74B0A.lnk = C:\WINDOWS\8ep74b0a.exe
O4 - Startup: GDZLOVIJ.lnk = C:\WINDOWS\gdzlovij.exe
O4 - Startup: EO5NN8YO.lnk = C:\WINDOWS\eo5nn8yo.exe
O4 - Startup: 8E1V0ERW.lnk = C:\WINDOWS\8e1v0erw.exe
O4 - Startup: B0Z3JNCY.lnk = C:\WINDOWS\b0z3jncy.exe
O4 - Startup: B773K0CX.lnk = C:\WINDOWS\b773k0cx.exe
O4 - Startup: 0X37CUXI.lnk = C:\WINDOWS\0x37cuxi.exe
O4 - Startup: W2U3DKP6.lnk = C:\WINDOWS\w2u3dkp6.exe
O4 - Startup: TF0T7Q8R.lnk = C:\WINDOWS\tf0t7q8r.exe
O4 - Startup: 2AM2UER1.lnk = C:\WINDOWS\2am2uer1.exe
O4 - Startup: 4Z4ULQLY.lnk = C:\WINDOWS\4z4ulqly.exe
O4 - Startup: VFQH1P96.lnk = C:\WINDOWS\vfqh1p96.exe
O4 - Startup: 0QKT2D8R.lnk = C:\WINDOWS\0qkt2d8r.exe
O4 - Startup: 932E0HMU.lnk = C:\WINDOWS\932e0hmu.exe
O4 - Startup: Q5R3H8WA.lnk = C:\WINDOWS\q5r3h8wa.exe
O4 - Startup: 006CMV5B.lnk = C:\WINDOWS\006cmv5b.exe
O4 - Startup: CQ40J681.lnk = C:\WINDOWS\cq40j681.exe
O4 - Startup: ODAN0Z6P.lnk = C:\WINDOWS\odan0z6p.exe
O4 - Startup: VRYHE9O4.lnk = C:\WINDOWS\vryhe9o4.exe
O4 - Startup: Z55FQNM0.lnk = C:\WINDOWS\z55fqnm0.exe
O4 - Startup: 1YTEONDA.lnk = C:\WINDOWS\1yteonda.exe
O4 - Startup: LHHVJ9ZQ.lnk = C:\WINDOWS\lhhvj9zq.exe
O4 - Startup: 4WERVRG9.lnk = C:\WINDOWS\4wervrg9.exe
O4 - Startup: 952CWW1T.lnk = C:\WINDOWS\952cww1t.exe
O4 - Startup: CTEGR1K3.lnk = C:\WINDOWS\ctegr1k3.exe
O4 - Startup: UTL36T0R.lnk = C:\WINDOWS\utl36t0r.exe
O4 - Startup: CLRO9KQ1.lnk = C:\WINDOWS\clro9kq1.exe
O4 - Startup: X9RQI8PZ.lnk = C:\WINDOWS\x9rqi8pz.exe
O4 - Startup: WBLCG0L5.lnk = C:\WINDOWS\wblcg0l5.exe
O4 - Global Startup: MORZE5.lnk = C:\WINDOWS\morze5.exe
O4 - Global Startup: YTEJ0D4O.lnk = C:\WINDOWS\ytej0d4o.exe
O4 - Global Startup: A56LPGI0.lnk = C:\WINDOWS\a56lpgi0.exe
O4 - Global Startup: 89KZ6A6H.lnk = C:\WINDOWS\89kz6a6h.exe
O4 - Global Startup: RX22PUNR.lnk = C:\WINDOWS\rx22punr.exe
O4 - Global Startup: OKIW1Q96.lnk = C:\WINDOWS\okiw1q96.exe
O4 - Global Startup: 69EDPU44.lnk = C:\WINDOWS\69edpu44.exe
O4 - Global Startup: NQ94817E.lnk = C:\WINDOWS\nq94817e.exe
O4 - Global Startup: U8BVU0ZI.lnk = C:\WINDOWS\u8bvu0zi.exe
O4 - Global Startup: 50R350W2.lnk = C:\WINDOWS\50r350w2.exe
O4 - Global Startup: O6L6A5KK.lnk = C:\WINDOWS\o6l6a5kk.exe
O4 - Global Startup: ZM40H23N.lnk = C:\WINDOWS\zm40h23n.exe
O4 - Global Startup: UV1WQL95.lnk = C:\WINDOWS\uv1wql95.exe
O4 - Global Startup: ZDWZBB0P.lnk = C:\WINDOWS\zdwzbb0p.exe
O4 - Global Startup: VU5F2DG8.lnk = C:\WINDOWS\vu5f2dg8.exe
O4 - Global Startup: KJ053GFM.lnk = C:\WINDOWS\kj053gfm.exe
O4 - Global Startup: M7R61LDR.lnk = C:\WINDOWS\m7r61ldr.exe
O4 - Global Startup: 00FWKFRZ.lnk = C:\WINDOWS\00fwkfrz.exe
O4 - Global Startup: O66BP1WP.lnk = C:\WINDOWS\o66bp1wp.exe
O4 - Global Startup: 67TJEBUM.lnk = C:\WINDOWS\67tjebum.exe
O4 - Global Startup: MXFV6LF1.lnk = C:\WINDOWS\mxfv6lf1.exe
O4 - Global Startup: NXI65K20.lnk = C:\WINDOWS\nxi65k20.exe
O4 - Global Startup: L07881TL.lnk = C:\WINDOWS\l07881tl.exe
O4 - Global Startup: 00UD5LUN.lnk = C:\WINDOWS\00ud5lun.exe
O4 - Global Startup: EPBFN492.lnk = C:\WINDOWS\epbfn492.exe
O4 - Global Startup: 24811TTQ.lnk = C:\WINDOWS\24811ttq.exe
O4 - Global Startup: VONB17ZH.lnk = C:\WINDOWS\vonb17zh.exe
O4 - Global Startup: BHYQC0QJ.lnk = C:\WINDOWS\bhyqc0qj.exe
O4 - Global Startup: L5WU0HDQ.lnk = C:\WINDOWS\l5wu0hdq.exe
O4 - Global Startup: CL59OOWD.lnk = C:\WINDOWS\cl59oowd.exe
O4 - Global Startup: YYE44QWZ.lnk = C:\WINDOWS\yye44qwz.exe
O4 - Global Startup: 4L3T26H7.lnk = C:\WINDOWS\4l3t26h7.exe
O4 - Global Startup: ON2YB1AJ.lnk = C:\WINDOWS\on2yb1aj.exe
O4 - Global Startup: DHOBPG09.lnk = C:\WINDOWS\dhobpg09.exe
O4 - Global Startup: MWIWCGTQ.lnk = C:\WINDOWS\mwiwcgtq.exe
O4 - Global Startup: POZCOHE0.lnk = C:\WINDOWS\pozcohe0.exe
O4 - Global Startup: 8EP74B0A.lnk = C:\WINDOWS\8ep74b0a.exe
O4 - Global Startup: EO5NN8YO.lnk = C:\WINDOWS\eo5nn8yo.exe
O4 - Global Startup: GDZLOVIJ.lnk = C:\WINDOWS\gdzlovij.exe
O4 - Global Startup: 8E1V0ERW.lnk = C:\WINDOWS\8e1v0erw.exe
O4 - Global Startup: B0Z3JNCY.lnk = C:\WINDOWS\b0z3jncy.exe
O4 - Global Startup: B773K0CX.lnk = C:\WINDOWS\b773k0cx.exe
O4 - Global Startup: 0X37CUXI.lnk = C:\WINDOWS\0x37cuxi.exe
O4 - Global Startup: W2U3DKP6.lnk = C:\WINDOWS\w2u3dkp6.exe
O4 - Global Startup: TF0T7Q8R.lnk = C:\WINDOWS\tf0t7q8r.exe
O4 - Global Startup: 2AM2UER1.lnk = C:\WINDOWS\2am2uer1.exe
O4 - Global Startup: 4Z4ULQLY.lnk = C:\WINDOWS\4z4ulqly.exe
O4 - Global Startup: VFQH1P96.lnk = C:\WINDOWS\vfqh1p96.exe
O4 - Global Startup: 0QKT2D8R.lnk = C:\WINDOWS\0qkt2d8r.exe
O4 - Global Startup: 932E0HMU.lnk = C:\WINDOWS\932e0hmu.exe
O4 - Global Startup: Q5R3H8WA.lnk = C:\WINDOWS\q5r3h8wa.exe
O4 - Global Startup: 006CMV5B.lnk = C:\WINDOWS\006cmv5b.exe
O4 - Global Startup: CQ40J681.lnk = C:\WINDOWS\cq40j681.exe
O4 - Global Startup: ODAN0Z6P.lnk = C:\WINDOWS\odan0z6p.exe
O4 - Global Startup: VRYHE9O4.lnk = C:\WINDOWS\vryhe9o4.exe
O4 - Global Startup: Z55FQNM0.lnk = C:\WINDOWS\z55fqnm0.exe
O4 - Global Startup: 1YTEONDA.lnk = C:\WINDOWS\1yteonda.exe
O4 - Global Startup: LHHVJ9ZQ.lnk = C:\WINDOWS\lhhvj9zq.exe
O4 - Global Startup: 4WERVRG9.lnk = C:\WINDOWS\4wervrg9.exe
O4 - Global Startup: 952CWW1T.lnk = C:\WINDOWS\952cww1t.exe
O4 - Global Startup: CTEGR1K3.lnk = C:\WINDOWS\ctegr1k3.exe
O4 - Global Startup: UTL36T0R.lnk = C:\WINDOWS\utl36t0r.exe
O4 - Global Startup: CLRO9KQ1.lnk = C:\WINDOWS\clro9kq1.exe
O4 - Global Startup: X9RQI8PZ.lnk = C:\WINDOWS\x9rqi8pz.exe
O4 - Global Startup: WBLCG0L5.lnk = C:\WINDOWS\wblcg0l5.exe
Thats ALL the o4 Global startups except SpywareGuard Kodak and MemTurbo
Reboot into safe mode by following instructions here: http://helpdesk.its.bethel.edu/resnet/Documents/Antivirus/Safemode.html
then as some of the files or folders you need to delete may be hidden do this:
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
Locate and delete:
C:\WINDOWS\WBLCG0L5.EXE
Do a "start/find" and delete any and all references to
BrowserHelper.dll [FILE]
Re-boot once more and post another HijackThis log.

in case you miss anything....
.....then,close all browser and outlook windows and "fix checked"
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about :blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {B549456D-F5D0-4641-BCED-8648A0C13D83} - C:\WINDOWS\BrowserHelper.dll
O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-A0E4-EA6FA787AD2D} - C:\PROGRA~1\POWERS~1\TOOLBAR\PWRSCUZ2.DLL
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\1.BIN\MWSOEMON.EXE
Re-boot and delete:
C:\PROGRAM FILES\MYWEBSEARCH [FOLDER]
Now Ctrl-Alt-Delete and end task on: WBLCG0L5.EXE
[end its process as many times as it takes till its gone]
Re-run HijackThis and "fix" all these entries:
O4 - HKLM\..\Run: [WBLCG0L5.EXE] C:\WINDOWS\WBLCG0L5.EXE /dk
O4 - HKCU\..\Run: [WBLCG0L5.EXE] C:\WINDOWS\WBLCG0L5.EXE /dk
O4 - Startup: MORZE5.lnk = C:\WINDOWS\morze5.exe
O4 - Startup: YTEJ0D4O.lnk = C:\WINDOWS\ytej0d4o.exe
O4 - Startup: A56LPGI0.lnk = C:\WINDOWS\a56lpgi0.exe
O4 - Startup: 89KZ6A6H.lnk = C:\WINDOWS\89kz6a6h.exe
O4 - Startup: RX22PUNR.lnk = C:\WINDOWS\rx22punr.exe
O4 - Startup: OKIW1Q96.lnk = C:\WINDOWS\okiw1q96.exe
O4 - Startup: 69EDPU44.lnk = C:\WINDOWS\69edpu44.exe
O4 - Startup: NQ94817E.lnk = C:\WINDOWS\nq94817e.exe
O4 - Startup: U8BVU0ZI.lnk = C:\WINDOWS\u8bvu0zi.exe
O4 - Startup: 50R350W2.lnk = C:\WINDOWS\50r350w2.exe
O4 - Startup: O6L6A5KK.lnk = C:\WINDOWS\o6l6a5kk.exe
O4 - Startup: ZM40H23N.lnk = C:\WINDOWS\zm40h23n.exe
O4 - Startup: UV1WQL95.lnk = C:\WINDOWS\uv1wql95.exe
O4 - Startup: ZDWZBB0P.lnk = C:\WINDOWS\zdwzbb0p.exe
O4 - Startup: VU5F2DG8.lnk = C:\WINDOWS\vu5f2dg8.exe
O4 - Startup: KJ053GFM.lnk = C:\WINDOWS\kj053gfm.exe
O4 - Startup: M7R61LDR.lnk = C:\WINDOWS\m7r61ldr.exe
O4 - Startup: 00FWKFRZ.lnk = C:\WINDOWS\00fwkfrz.exe
O4 - Startup: O66BP1WP.lnk = C:\WINDOWS\o66bp1wp.exe
O4 - Startup: 67TJEBUM.lnk = C:\WINDOWS\67tjebum.exe
O4 - Startup: MXFV6LF1.lnk = C:\WINDOWS\mxfv6lf1.exe
O4 - Startup: NXI65K20.lnk = C:\WINDOWS\nxi65k20.exe
O4 - Startup: L07881TL.lnk = C:\WINDOWS\l07881tl.exe
O4 - Startup: 00UD5LUN.lnk = C:\WINDOWS\00ud5lun.exe
O4 - Startup: EPBFN492.lnk = C:\WINDOWS\epbfn492.exe
O4 - Startup: 24811TTQ.lnk = C:\WINDOWS\24811ttq.exe
O4 - Startup: VONB17ZH.lnk = C:\WINDOWS\vonb17zh.exe
O4 - Startup: BHYQC0QJ.lnk = C:\WINDOWS\bhyqc0qj.exe
O4 - Startup: L5WU0HDQ.lnk = C:\WINDOWS\l5wu0hdq.exe
O4 - Startup: CL59OOWD.lnk = C:\WINDOWS\cl59oowd.exe
O4 - Startup: YYE44QWZ.lnk = C:\WINDOWS\yye44qwz.exe
O4 - Startup: 4L3T26H7.lnk = C:\WINDOWS\4l3t26h7.exe
O4 - Startup: ON2YB1AJ.lnk = C:\WINDOWS\on2yb1aj.exe
O4 - Startup: DHOBPG09.lnk = C:\WINDOWS\dhobpg09.exe
O4 - Startup: MWIWCGTQ.lnk = C:\WINDOWS\mwiwcgtq.exe
O4 - Startup: POZCOHE0.lnk = C:\WINDOWS\pozcohe0.exe
O4 - Startup: 8EP74B0A.lnk = C:\WINDOWS\8ep74b0a.exe
O4 - Startup: GDZLOVIJ.lnk = C:\WINDOWS\gdzlovij.exe
O4 - Startup: EO5NN8YO.lnk = C:\WINDOWS\eo5nn8yo.exe
O4 - Startup: 8E1V0ERW.lnk = C:\WINDOWS\8e1v0erw.exe
O4 - Startup: B0Z3JNCY.lnk = C:\WINDOWS\b0z3jncy.exe
O4 - Startup: B773K0CX.lnk = C:\WINDOWS\b773k0cx.exe
O4 - Startup: 0X37CUXI.lnk = C:\WINDOWS\0x37cuxi.exe
O4 - Startup: W2U3DKP6.lnk = C:\WINDOWS\w2u3dkp6.exe
O4 - Startup: TF0T7Q8R.lnk = C:\WINDOWS\tf0t7q8r.exe
O4 - Startup: 2AM2UER1.lnk = C:\WINDOWS\2am2uer1.exe
O4 - Startup: 4Z4ULQLY.lnk = C:\WINDOWS\4z4ulqly.exe
O4 - Startup: VFQH1P96.lnk = C:\WINDOWS\vfqh1p96.exe
O4 - Startup: 0QKT2D8R.lnk = C:\WINDOWS\0qkt2d8r.exe
O4 - Startup: 932E0HMU.lnk = C:\WINDOWS\932e0hmu.exe
O4 - Startup: Q5R3H8WA.lnk = C:\WINDOWS\q5r3h8wa.exe
O4 - Startup: 006CMV5B.lnk = C:\WINDOWS\006cmv5b.exe
O4 - Startup: CQ40J681.lnk = C:\WINDOWS\cq40j681.exe
O4 - Startup: ODAN0Z6P.lnk = C:\WINDOWS\odan0z6p.exe
O4 - Startup: VRYHE9O4.lnk = C:\WINDOWS\vryhe9o4.exe
O4 - Startup: Z55FQNM0.lnk = C:\WINDOWS\z55fqnm0.exe
O4 - Startup: 1YTEONDA.lnk = C:\WINDOWS\1yteonda.exe
O4 - Startup: LHHVJ9ZQ.lnk = C:\WINDOWS\lhhvj9zq.exe
O4 - Startup: 4WERVRG9.lnk = C:\WINDOWS\4wervrg9.exe
O4 - Startup: 952CWW1T.lnk = C:\WINDOWS\952cww1t.exe
O4 - Startup: CTEGR1K3.lnk = C:\WINDOWS\ctegr1k3.exe
O4 - Startup: UTL36T0R.lnk = C:\WINDOWS\utl36t0r.exe
O4 - Startup: CLRO9KQ1.lnk = C:\WINDOWS\clro9kq1.exe
O4 - Startup: X9RQI8PZ.lnk = C:\WINDOWS\x9rqi8pz.exe
O4 - Startup: WBLCG0L5.lnk = C:\WINDOWS\wblcg0l5.exe
O4 - Global Startup: MORZE5.lnk = C:\WINDOWS\morze5.exe
O4 - Global Startup: YTEJ0D4O.lnk = C:\WINDOWS\ytej0d4o.exe
O4 - Global Startup: A56LPGI0.lnk = C:\WINDOWS\a56lpgi0.exe
O4 - Global Startup: 89KZ6A6H.lnk = C:\WINDOWS\89kz6a6h.exe
O4 - Global Startup: RX22PUNR.lnk = C:\WINDOWS\rx22punr.exe
O4 - Global Startup: OKIW1Q96.lnk = C:\WINDOWS\okiw1q96.exe
O4 - Global Startup: 69EDPU44.lnk = C:\WINDOWS\69edpu44.exe
O4 - Global Startup: NQ94817E.lnk = C:\WINDOWS\nq94817e.exe
O4 - Global Startup: U8BVU0ZI.lnk = C:\WINDOWS\u8bvu0zi.exe
O4 - Global Startup: 50R350W2.lnk = C:\WINDOWS\50r350w2.exe
O4 - Global Startup: O6L6A5KK.lnk = C:\WINDOWS\o6l6a5kk.exe
O4 - Global Startup: ZM40H23N.lnk = C:\WINDOWS\zm40h23n.exe
O4 - Global Startup: UV1WQL95.lnk = C:\WINDOWS\uv1wql95.exe
O4 - Global Startup: ZDWZBB0P.lnk = C:\WINDOWS\zdwzbb0p.exe
O4 - Global Startup: VU5F2DG8.lnk = C:\WINDOWS\vu5f2dg8.exe
O4 - Global Startup: KJ053GFM.lnk = C:\WINDOWS\kj053gfm.exe
O4 - Global Startup: M7R61LDR.lnk = C:\WINDOWS\m7r61ldr.exe
O4 - Global Startup: 00FWKFRZ.lnk = C:\WINDOWS\00fwkfrz.exe
O4 - Global Startup: O66BP1WP.lnk = C:\WINDOWS\o66bp1wp.exe
O4 - Global Startup: 67TJEBUM.lnk = C:\WINDOWS\67tjebum.exe
O4 - Global Startup: MXFV6LF1.lnk = C:\WINDOWS\mxfv6lf1.exe
O4 - Global Startup: NXI65K20.lnk = C:\WINDOWS\nxi65k20.exe
O4 - Global Startup: L07881TL.lnk = C:\WINDOWS\l07881tl.exe
O4 - Global Startup: 00UD5LUN.lnk = C:\WINDOWS\00ud5lun.exe
O4 - Global Startup: EPBFN492.lnk = C:\WINDOWS\epbfn492.exe
O4 - Global Startup: 24811TTQ.lnk = C:\WINDOWS\24811ttq.exe
O4 - Global Startup: VONB17ZH.lnk = C:\WINDOWS\vonb17zh.exe
O4 - Global Startup: BHYQC0QJ.lnk = C:\WINDOWS\bhyqc0qj.exe
O4 - Global Startup: L5WU0HDQ.lnk = C:\WINDOWS\l5wu0hdq.exe
O4 - Global Startup: CL59OOWD.lnk = C:\WINDOWS\cl59oowd.exe
O4 - Global Startup: YYE44QWZ.lnk = C:\WINDOWS\yye44qwz.exe
O4 - Global Startup: 4L3T26H7.lnk = C:\WINDOWS\4l3t26h7.exe
O4 - Global Startup: ON2YB1AJ.lnk = C:\WINDOWS\on2yb1aj.exe
O4 - Global Startup: DHOBPG09.lnk = C:\WINDOWS\dhobpg09.exe
O4 - Global Startup: MWIWCGTQ.lnk = C:\WINDOWS\mwiwcgtq.exe
O4 - Global Startup: POZCOHE0.lnk = C:\WINDOWS\pozcohe0.exe
O4 - Global Startup: 8EP74B0A.lnk = C:\WINDOWS\8ep74b0a.exe
O4 - Global Startup: EO5NN8YO.lnk = C:\WINDOWS\eo5nn8yo.exe
O4 - Global Startup: GDZLOVIJ.lnk = C:\WINDOWS\gdzlovij.exe
O4 - Global Startup: 8E1V0ERW.lnk = C:\WINDOWS\8e1v0erw.exe
O4 - Global Startup: B0Z3JNCY.lnk = C:\WINDOWS\b0z3jncy.exe
O4 - Global Startup: B773K0CX.lnk = C:\WINDOWS\b773k0cx.exe
O4 - Global Startup: 0X37CUXI.lnk = C:\WINDOWS\0x37cuxi.exe
O4 - Global Startup: W2U3DKP6.lnk = C:\WINDOWS\w2u3dkp6.exe
O4 - Global Startup: TF0T7Q8R.lnk = C:\WINDOWS\tf0t7q8r.exe
O4 - Global Startup: 2AM2UER1.lnk = C:\WINDOWS\2am2uer1.exe
O4 - Global Startup: 4Z4ULQLY.lnk = C:\WINDOWS\4z4ulqly.exe
O4 - Global Startup: VFQH1P96.lnk = C:\WINDOWS\vfqh1p96.exe
O4 - Global Startup: 0QKT2D8R.lnk = C:\WINDOWS\0qkt2d8r.exe
O4 - Global Startup: 932E0HMU.lnk = C:\WINDOWS\932e0hmu.exe
O4 - Global Startup: Q5R3H8WA.lnk = C:\WINDOWS\q5r3h8wa.exe
O4 - Global Startup: 006CMV5B.lnk = C:\WINDOWS\006cmv5b.exe
O4 - Global Startup: CQ40J681.lnk = C:\WINDOWS\cq40j681.exe
O4 - Global Startup: ODAN0Z6P.lnk = C:\WINDOWS\odan0z6p.exe
O4 - Global Startup: VRYHE9O4.lnk = C:\WINDOWS\vryhe9o4.exe
O4 - Global Startup: Z55FQNM0.lnk = C:\WINDOWS\z55fqnm0.exe
O4 - Global Startup: 1YTEONDA.lnk = C:\WINDOWS\1yteonda.exe
O4 - Global Startup: LHHVJ9ZQ.lnk = C:\WINDOWS\lhhvj9zq.exe
O4 - Global Startup: 4WERVRG9.lnk = C:\WINDOWS\4wervrg9.exe
O4 - Global Startup: 952CWW1T.lnk = C:\WINDOWS\952cww1t.exe
O4 - Global Startup: CTEGR1K3.lnk = C:\WINDOWS\ctegr1k3.exe
O4 - Global Startup: UTL36T0R.lnk = C:\WINDOWS\utl36t0r.exe
O4 - Global Startup: CLRO9KQ1.lnk = C:\WINDOWS\clro9kq1.exe
O4 - Global Startup: X9RQI8PZ.lnk = C:\WINDOWS\x9rqi8pz.exe
O4 - Global Startup: WBLCG0L5.lnk = C:\WINDOWS\wblcg0l5.exe
Thats ALL the o4 Global startups except SpywareGuard Kodak and MemTurbo
Reboot into safe mode by following instructions here: http://helpdesk.its.bethel.edu/resnet/Documents/Antivirus/Safemode.html
then as some of the files or folders you need to delete may be hidden do this:
Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
Locate and delete:
C:\WINDOWS\WBLCG0L5.EXE
Do a "start/find" and delete any and all references to
BrowserHelper.dll [FILE]
Re-boot once more and post another HijackThis log.