hi dear
follow the steps first of all go to %ytemroot%/system32.exe
copy cmd.exe and paste it in any other dive and rename it like cmdnew.exe etc
double click on it u will get cmd prompt
type tasklist which will list all the processes running currently
see for unusual processes like ssvchhostt.exe or smss.exe rememeber smss is a system dependent process but some virus do it to hide themselft something called cammoflaging
kill all those process by taskkill command at prompt use /f switch to kill by force
go to run type cmd if u identified the problem u will be recovered
go to regedit hklm/software/microsoft/windows/currentversion/run you will see a entry of same process,delete it repeat same for hkcu
go to startup folder and delete same process
go to system32 and delete the virus or process if required use attrib feature
you will be definately recovered
happy windowing
with regards gautam