Open Task Manager & end process on the following:
tapiap.exe
Go to C:\WINDOWS\Help and delete the file manually.
Your system is infected with the Virtumundo malware.
Download the Pocket KillBox
Unzip the file to your desktop.
Boot into Safe Mode:
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu will come up where you can choose to enter Safe Mode.
To get back to normal mode just restart the computer as you normally would.
Run KillBox.exe.
Paste each of these lines into the box, select delete on reboot, on all the dll files tick unregister dll before deleting and end explorer shell before deleting must be ticked at all times , then press the red X button, when it says reboot now, say no and continue to paste the lines in in turn and follow the above procedure every time, after the last line has been pasted let it reboot.
C:\DOCUME~1\SUSANM~1\LOCALS~1\Temp\paipat.dat
C:\WINDOWS\Fonts\mcac.exe
C:\WINDOWS\qhijkfmj.exe
C:\WINDOWS\AppPatch\msreg.exe
C:\WINDOWS\system32\hostx.exe
In the Full Path of File to Delete field paste this path and click the red circle with the white X in it(when it asks you to reboot, click YES.):
C:\WINDOWS\system32\bkinst.exe
Your computer will restart and check if the file was deleted.
Rescan with HijackThis and fix these entries:
O2 - BHO: CATLEvents Object - {02F96FB7-8AF6-439B-B7BA-2F952F9E4800} - C:\DOCUME~1\SUSANM~1\LOCALS~1\Temp\paipat.dat
O4 - HKLM\..\Run: [*mcac] C:\WINDOWS\Fonts\mcac.exe
O4 - HKLM\..\Run: [qhijkfmj] C:\WINDOWS\qhijkfmj.exe
O4 - HKLM\..\RunOnce: [*tapiap] C:\WINDOWS\Help\tapiap.exe rerun
Do a search for mcac,qhijkfmj,tapiap, gersm, msreg, bkinst,hostx and tsnikb and delete any files that you find.
Empty your Recycle Bin.
Restart your computer.
Post a fresh HijackThis log.