Hi carly_sue, welcome to DaniWeb :)
To begin with, please do the following:
Download the (free) HijackThis utility:
http://www.stevewolfonline.com/Downloads/DMR/Spyware%20Tools/HJT/HijackThis.exe
Once downloaded, follow these instructions to install and run the program:
Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.
Run HijackThis, but do not have HJT fix anything yet; only have it scan your system! Once the scan is complete, the "Scan" button will turn into an option to "Save log...".
Save the log in the folder you created for HijackThis; the saved file will be named "hijackthis.log". Open the log file with Windows Notepad, and cut-n-paste the entire contents of the Notepad file here.
The log contents will tell us a lot about what "nasties" have crept into your system, and once we analyse the log we can tell you what to do from there.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
OK- your log indicates signs of at least one malicious infection, but there's something you need to take care of first:
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe
The log entry above indicates that you are running HJT from within a Temp/Temporary folder. Please do the following, as I instructed in my first post: Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.
One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if HijackThis (and other data that you care about) is living in those Temp folders, it will be erased along with everything else!
Temp/Temporary folders are just that- Temporary. They are not meant for permanent storage, as their contents are often delete in the course of troubleshooting, virus/spyware removal, running disk clean-up utilities, etc.
Please move HijackThis to a safe location and post another log after that. Once we're sure that HJT is no longer running from a Temp location we can begin removing the "nasties".
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
No problem; HijackThis is running from the right place now.
The "[winsync]" entry in the log is indicative of an infection that HijackThis alone can't thoroughly clean (and you may have leftovers from other infections as well), so let's run a couple of removal utilities and see what they can clean up:
You will be disconnected from the Internet for some of the following, so you'll need to print out these instructions, or save them into a text file with Notepad.
1. You already have MS Antispyware installed, so open the program and click on "Spyware Definitions" on the main page of the program to check for and install the most current spyware definitions database. Don't run a scan yet; just close the program when it finishes the update process.
2. Download and install ewido Security Suite . Run the program; you will receive a warning message saying "Database not found", just click "OK" for this. Next in the main screen, click "Update" and click "Start Update". Don't run a scan yet; just close the program when it finishes the update process.
3. Download and install CCleaner . As with the above two utilities, don't run the program yet.
4. Reboot the computer into Safe Mode. You get to the Safe Mode boot option by tapping the F8 key as your computer is starting up.
5. Once in Safe Mode, run full system scans with both MS Antispyware and ewido and have them fix all malicious/suspect entries they find. Also- when prompted, save the scan report log that ewido generates.
6. While still in Safe Mode, open CCleaner and click on the "Run Cleaner" button. Close CCleaner when it finishes its cleanup operation.
7. Reboot the computer normally, run HijackThis again, and post the new log. Also post the scan report log from ewido.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370