Intuition21
Welcome to TechSpot
Go here first and do exactly what it says:
https://www.techspot.com/vb/topic17297.html
Then reboot in Safe Mode and run HJT standalone and let it "fix":
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\rlriv.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\rlriv.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\rlriv.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\rlriv.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\rlriv.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\rlriv.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\rlriv.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {83EB6065-85E2-7595-DFD5-A093986B0410} - C:\WINNT\system32\sdkkb.dll
O4 - HKLM\..\Run: [DeskMateAutoUpdate] C:\PROGRA~1\DESKMA~1\DeskMateAutoUpdate.exe
O4 - HKLM\..\Run: [netcx.exe] C:\WINNT\system32\netcx.exe
O4 - HKLM\..\Run: [NwhA0O] C:\documents and settings\administrator.vewx2x0royk13en\local settings\temp\NwhA0O.exe
O4 - HKLM\..\Run: [NwhA0O.exe] C:\documents and settings\administrator.vewx2x0royk13en\local settings\temp\NwhA0O.exe
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: (HKLM)
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) -
http://www.errorguard.com/installation/Install.cab
O16 - DPF: {2456741B-1567-7682-A355-939856783603} - ms-its:mhtml:file://C:\foo.mht!
http://www.xpehbam.biz/be//T.CHM::/load.exe
O23 - Service: Remote Procedure Call (RPC) Helper - Unknown - C:\WINNT\addsj.exe (file missing)
When finished, still in Safe Mode, delete the following:
C:\WINNT\rlriv.dll
C:\WINNT\system32\sdkkb.dll
Everything in, including the directory itself: C:\PROGRA~1\DESKMA~1
C:\WINNT\system32\netcx.exe
Clean out everything in: C:\documents and settings\administrator.vewx2x0royk13en\local settings\temp
C:\WINNT\addsj.exe (if still around)
C:\foo.mht (or whatever it is called there)