Laptop is running Windows 2000 and is probably not up-to-date on anything. It has one account only - administrator.
I wasn't doing anything particularly risky - I clicked on a link supposedly to amazon.co.uk through google shopping and a different website appeared. Then two black windows (command windows?) appeared with C:\WINNT\svchost.exe as the title (could have been scvhost.exe). I frantically tried to close everything but all hell had broken lose! I can't remember whether it was after I shut down and rebooted or as I was trying to shut down, but the laptop seemed to be doing a dump. When the laptop rebooted the two black windows appeared again and reappeared every time I closed them. After several reboot attempts it dawned on me that the laptop was still connected to the wireless network (no shared files fortunately) - once I took out the wireless card the black windows stopped appearing.
Most of windows itself still seems to be working fine - explorer, word, search etc all seem to work. Nothing else does though (malware programs, acrobat reader etc). Run doesn't work and neither do a number of options from the control panel such as adminstrator tools. Task manager is displaying processes, but it doesn't appear to be possible to stop any processes (though it's just possible that's because they are all genuine system processes that should be running).
Pressing F8 during the boot process brings up the menu but on selecting safe mode results in a blue screen - inaccessible boot device. Rebooting now brings up an error message that the system log is full (can't see it because admin tools are blocked).
Obviously I can't download and run the suggested programs in the 'malware post' - sorry.
We have a boot disk and were planning on trying that, but we realised that my daughter hadn't backed up any of her files recently. So we stupidly put in a memory stick to take the files off (and fortunately were not so stupid as to put it in somewhere else!). The following were added to the memory stick: 4 short cuts (Copy of shortcut to  to ), RECYCLER, BOOTEX and autorun, and these are constantly replaced if you attempt to remove them.
I hope that's enough information for someone to help. Please can anyone tell me what virus we have (or maybe more than one?), can I get rid of it and if so how, and how do I 'disinfect' the memory stick to save my daughter's stuff?
Thanks very much.
Edited by bubbshjs, 26 September 2011 - 07:35 AM.