When he reboots it will reinstall itself unless he removes it from the registry, which requires an antivirus.
Download a good antivirus like this one.
service win32 seems like a legit system process.tidserv is a backdoor rootkit.Read this: http://www.viruslist.com/en/brown townysis?pubid=168740859
System restore.
If he's rebooted since he's gotten the virus, his System Restore points have been corrupted or deleted.