As far as I can see the virus is the following file: C:\head891238.exe
Press CTRL+ALT+DEL to bring up the task manager. Find the process 'head891238.exe' and terminate it. Then open up HijackThis, have it scan, and remove the following items:
code:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F3 - REG:win.ini: load=C:\\yay.exe
O4 - HKLM\..\Run: [eTunnel] C:\head891238.exe
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler V1.39.13R] C:\head891238.exe
Make sure that the process is terminated before you remove it with HijackThis otherwise the startup entry will most likely be automatically restored.
Now you need to delete the file itself. Easiest way would be to go to C:\ and delete head891238.exe if you can see it. Problem is that its attributes are probably set to hidden. If that is the case, go to Start => Run and type 'cmd', then in the black window that appears type:
code:
del C:\head891238.exe
It should delete, and that should, in theory, be the end of your msn worm problems.
By the way, I can see you have MyWebSearch (adware) installed. You might want to remove that, either by checking whether it will let you do so in Add/Remove programs, or by using
Spybot S&D or
Ad-Aware.
EDIT: You might want to repeat the steps that you took to delete C:\head891238.exe, instead for the file C:\yay.exe (although it might not exist, in that case then it doesn't matter).