Time to get some free stuff.... but first, why not copy this into notepad?
I would like you to download CCleaner from http://www.majorgeeks.com/download4191.html and put it in a new folder.
Next go get Ewido 4.0 [free], install it alongside your other regular applications in Program Files, because you should keep it for scanning once a week or so - put an icon on your desktop.
So, Ewido:- start it; the main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Click on update tab and then Update Now. When it finishes click on scanner tab and then Settings:- How to act- click on recommended action and set Quarantine. For reports, set to generate after every scan and untick only if threats found. Finally down on the tray right click the Ewido icon and untick Start with windows, an then Exit it. Don't scan yet.
Ok, you're done with the net. Shut it down. Disconnect..... whatever...
Rclick your recycle bin and run CCleaner. [or go to its folder and dclick ccleaner.exe] You will lose a lot of handy stuff like histories etc... but there is a job to do...
Go into safe mode [Restart, key F8 immed after POST runs and select Safe Mode and Enter.... You'll get a dark desktop with icons etc...]
Start Ewido, do the full system scan. Click "Apply all actions" to place any infected files into Quarantine, and only then click on "Save Report" to view all completed scans; click on the scan you just performed and select "Save report."
Note: Close all open windows, programs, and DO NOT USE the computer while Ewido is scanning. If Explorer or other programs are open during the scan that means certain files will also be in use. Some malware will insert itself and hide in areas that are "protected" by Windows when the files are being used. This can hamper Ewido's ability to clean properly and may result in reinfection.
And now, still in Safe Mode and with NOTHING else open, run Hijack This, check the items i list below and Fix them. [if they still exist]
NOTE - the first two you do not need as auto-starts. They just hog resources, and their functions will still remain for manual initiation.
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
I'm not sure why this next one is on registry auto-load... have you had a bad crash lately?? Anyway, go ahead and fix it, cos your sys is obviously running now... :)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\Poker.exe (HKCU)
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll
We may have some fun with the last one...
Done? then back to normal mode, run HT again and please post it.