First of all move HJT to its own folder such as C:/HJT
Then run HJT and check the following
C:\WINDOWS\System32\users32.exe
C:\WINDOWS\System32\adobepnl.dll
O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\System32\runsrv32.exe
O4 - HKLM\..\Run: [Transponder] C:\WINDOWS\System32\susp.exe
R3 - Default URLSearchHook is missing
Also check the items that say BHO (no name)....(no file)
Close all other windows except HJT and click the fix checked button
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.
Open the SmitfraudFixfolder and double-click smitfraudfix.cmdSelect option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Ok now we need to delete some files. Plz delete the following
C:\WINDOWS\System32\susp.exe
C:\WINDOWS\System32\runsrv32.exe
C:\WINDOWS\System32\users32.exe
If you cant manually do this download pocket killbox from here
once you have it up and running select the box where it says Delete on reboot then click where it says all files. Now click on the folder icon and select those files. Click the kill button and the program should automatically restart your computer.
Reboot and post a new log. Also tell me how your computer is doing.
srry forgot to put the link to pocket killbox so here it is.