After sweeping a lot of ad-ware and trojans and stuff out (Ad-aware, Spybot, AVG, CWS-removers), I still think there is something nasty inside, so could someone please check the HJT log?
O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{41D8192F-1D85-4103-8264-2CB870CD03D1}: NameServer = 212.59.0.1<Only fix this, if it doesn`t belong to your ISP.
Click on the fix checked button.
Close HJT.
Locate and delete the following bold files and/or directories(if there).
IExplore327.exe This file is probably located in the C:\windows\system32 folder.
Reboot into normal mode and turn system restore back on.