Hi,
Open NotePad, and copy the contents of the below "Quode" box:-
cd %windir%
attrib -s -r -h NMSOCKNT.DLL
del NMSOCKNT.DLL
cd system32
attrib -s -r -h zbqmifab.exe
del zbqmifab.exe
attrib -s -r -h ngsh33.dll
del ngsh33.dll
attrib -s -r -h ngpw36.exe
del ngpw36.exe
attrib -s -r -h adprot.exe
del adprot.exe
attrib -s -r -h svcnet.exe
del svcnet.exe
Go to File Menu >Save As, and save the file with the name Test.bat and exit from NotePad.
Download Ewido and install it. Then run it, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido.
Download CCleaner and install it. Do not run it now.
Reboot in Safe Mode:-
Restart (or switch ON) the PC.
Then, keep tapping the F8 Key.
From the menu that will be displayed, out of which choose Safe Mode and press Enter.
Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-
R3 - Default URLSearchHook is missing
O2 - BHO: ngsh33.clsIS - {941CA48C-3984-4E7D-AAF8-8755ED76EB50} - C:\WINDOWS\system32\ngsh33.dll
O4 - HKLM\..\Run: [Shellapi32] svcnet.exe
O4 - HKLM\..\Run: [Aapp] C:\windows\system32\adprot
O4 - HKLM\..\Run: [zbqmifab] c:\windows\system32\zbqmifab.exe
O4 - HKCU\..\Run: [Shellapi32] svcnet.exe
O4 - HKCU\..\Run: [ngpw36] C:\windows\system32\ngpw36.exe
O4 - HKCU\..\Run: [adprot] C:\windows\system32\adprot.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} (CInstall Class) - http://www.wildtangent.com/webdrivers/webinstall/shockwave/Install.cab
O20 - AppInit_DLLs: C:\WINDOWS\NMSOCKNT.DLL C:\WINDOWS\NMSOCKNT.DLL
Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.
Double-Click on the file Test.bat, a small DOS type window should open and close immediately.
Run CCleaner, click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options.
Finally click "Run Cleaner" and click "OK" to continue cleaning.
Run Ewido, click on the "Scanner" button in the left menu, then click on the "Start" button.
If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
When the scan finishes, click on "Save Report". This will create a text file.
Reboot to normal mode, run HijackThis again, and post a fresh log along with Ewido log.