First thing I found googling it:
Close all Internet Explorer windows and goto "Start"--> "Run" and type in :
taskmgr ,then click " OK".
Then highlight each file below and then click "End Process":
netia.exe
apiqw32.exe
Next
Goto "Start" --> "Run" and type in:
Services.msc ,then click " OK".
Scroll down and find the service called "Network Security Service".
Double-click on it.
In the next window that opens, click the Stop button, then change the Startup Type to Disabled.Click "Apply" and then "OK".
Let us know if "Network Security Service" is listed.
3.
Close ALL Internet Explorer Windows, only have HijackThis running.
In HiJackThis Check the boxes beside the below entries, then click on "Fix checked" .
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kbaqk.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://kbaqk.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://kbaqk.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\kbaqk.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://kbaqk.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\kbaqk.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {96DF800A-C660-BD6C-1D33-EC8F6FA48462} - C:\WINDOWS\mssd.dll
O4 - HKLM\..\Run: [netia.exe] C:\WINDOWS\system32\netia.exe
O4 - HKLM\..\RunOnce: [apiqw32.exe] C:\WINDOWS\apiqw32.exe
Reboot into Safe Mode.....( tap F8 key during reboot, until the boot menu appears...use the arrow keys to choose "Safe Mode" from the menu......,then press the "Enter" key)
Make sure you can see Hidden files and Folders, so you can remove them:
http://www.xtra.co.nz/help/0,,4155-1916458,00.htmlThen delete the below files and Folders:
C:\WINDOWS\system32\netia.exe <<
C:\WINDOWS\apiqw32.exe <<
Reboot computer and post back a new HJT log to this thread, plea