Run HijackThis, close any open windows and browsers, and fix the following (by placing a check next to them and at the end hitting "Fix Checked")
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll
O2 - BHO: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
O4 - HKLM\..\Run: [sysser] C:\WINDOWS\System32\svchsot.exe
O4 - HKLM\..\Run: [5k0+¿ÔÇè]Iú" ‹üžigÅC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\hsjma.exe
O4 - HKLM\..\Run: [end of da road] C:\WINDOWS\System32\end of da road.exe
O4 - HKLM\..\Run: [5k09¿(+ú]Ù8øaîžigÝC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\hsjma.exe
O4 - HKLM\..\Run: [BtÇÏóËsã&}yÁèxHó'EC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\hsjma.exe
O4 - HKLM\..\Run: [Trickler] "c:\windows\igator\trickler3103_pic_fs_dmpt_3103.exe"
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [5k09¿(+ú8øaîžigÝY] C:\WINDOWS\hsjma.exe
O4 - HKLM\..\Run: [farstone] NULL
O16 - DPF: ChatSpace Full Java Client 3.1.0.235 -
http://207.150.169.9...va/cfs31235.cabO16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\Recycled\1.exe
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!
http://iframedollars....chm::/load.exeO16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\ied_s7.cab
O16 - DPF: {11111111-1111-1111-1111-511111193457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111193458} - file://c:\x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windup...e/bridge-c8.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.co...up1.0.0.8-2.cabO16 - DPF: {23232323-2323-2323-2323-232323291122} - file://c:\x.cab
O16 - DPF: {2DB91F50-1692-4E25-CB34-42A41D1CEB5A} -
http://213.159.117.150/1/gdnIL10.exeO16 - DPF: {35A86F4D-A233-4A4D-93CA-0A78B82B9788} (Regarabnation.UserControl1) -
http://www.hearyou.c...egistration.CABO16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
http://www.xxxtoolba...006_regular.cabO16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
http://65.254.32.42:1995/talk.cabO16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -
http://static.topcon...vex/loader2.ocxO16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) -
http://www.globalpho...ionale_ver4.CABO16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) -
http://www.mt-downlo....cab?refid=2732O23 - Service: ISEXEng - Unknown - C:\WINDOWS\System32\angelex.exe
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe
Boot into safe mode:Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.
Show hidden files/folders:Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.
Find and delete the following files/folders:
C:\Program Files\QuickSearch
C:\WINDOWS\System32\svchsot.exe
C:\Program Files\ISTsvc
C:\WINDOWS\hsjma.exe
C:\WINDOWS\zeta.exe
C:\WINDOWS\System32\angelex.exe
c:\x.cab
C:\WINDOWS\System32\end of da road.exe
Reboot into normal mode.
In "Add/Remove Programs" in the Control Panel uninstall New.Net or NewDotNet.
Reboot and post a new HJT log.