Boot in Safe Mode, see how here.
Run a HJT scan and (if still there) place a tick-mark in the little square before:
...................................................................................................
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.kwic.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = webproxy.queensu.ca:8080
R3 - URLSearchHook: (no name) - - (no file)
F1 - win.ini: run=hpfsched
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Fix ALL your O16 - DPF: entries
This is NOT your ISP: Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
So FIX this O17 as well
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 85.255.113.147,85.255.112.24
...................................................................................................
Now click on the
Fix Checked button in HJT. Exit HJT.
Rightclick IE on the desktop, select Properties, click on
Delete Cookies, and
Delete Files.
Delete ALL files and directories from: C:\WINDOWS\Temp (except files dated from TODAY).
Boot normal.