Concur with Dr Web but first run TDSSKiller to clear the rootkit
Please read carefully and follow these steps.
[*]Download TDSSKiller and save it to your Desktop.
[*]Extract its contents to your desktop.
[*]Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerMain.png
[*]If an infected file is detected, the default action will be Cure, click on Continue.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerMal-1.png
[*]If a suspicious file is detected, the default action will be Skip, click on Continue.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerSuspicious.png
[*]It may ask you to reboot the computer to complete the process. Click on Reboot Now.
http://i466.photobucket.com/albums/rr21/JSntgRvr/TDSSKillerCompleted.png
[*]If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
[*]If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of “TDSSKiller.[Version][Date][Time]_log.txt”. Please copy and paste the contents of that file here.
THEN
Download Dr.Web CureIt to the desktop.
[*]Doubleclick the drweb-cureit.exe file, then on Start and allow to run the express scan
[*]This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
[*]Once the short scan has finished, chose the Complete Scan.
[*]Select all drives. A red dot shows which drives have been chosen.
[*]Click the green arrow
http://perplexus.geekstogo.com/drweb_green_arrow.jpg
at the right, and the scan will start.
[*]Click ‘Yes to all’ if it asks if you want to cure/move the file.
[*]When the scan has finished, look and see if you can click the following icon next to the files found:
http://perplexus.geekstogo.com/drweb_check.gif
[*]If so, click it and then click the next icon right below and select Move incurable as you’ll see in next image:
http://perplexus.geekstogo.com/drweb_move.gif
[*]This will move it to the %userprofile%\DoctorWeb\quarantine-folder if it can’t be cured. (this in case if we need samples)
[*]After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
[*]Save the report to your desktop. The report will be called DrWeb.csv
[*]Close Dr.Web Cureit.
[*]Reboot your computer to allow files that were in use to be moved/deleted during reboot.
[*]After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new OTL log.
NOTE: During the scan, a pop-up window will open asking for full version purchase. Simply close the window by clicking on X in upper right corner.