Download this tool
http://p-nand-q.com/download/pserv_cpl/pserv-2.3.exe and install it
Set your Explorer up using the info in this link so that hidden and System files are visible
Also Uncheck the "Hide extensions for known file types" box
Reboot to SAFE mode
How to start the computer in Safe mode
Rename the C:\WINNT\Regedit.exe file to oldreg.bin
It appears to be infected and you will have to replace it from CD
Start the program we installed (use Start > All Programs > pserv.cpl > Services and Devices)
(my spanish is awful)
When it opens find the Plug and Play svc service
Right click and choose Kill - then set it disabled (or even delete it)
Reboot and check -- did it come back ?
Fix the entries using HijackThis
extract a new regedit.exe file

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/biggrin.gif\' class=\'bbc_emoticon\' alt=\'

\' />