At the very least least, you are infected with a variant of the W32/Rbot worm.
Judging from the following information in your HijackThis log's header, you are also running very outdated versions of XP and Internet Explorer:
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Before doing anything else, download and install XP Service Pack 1a ; the Service Pack fixes many bugs and security loopholes that allow malicious programs to install and run on your system.
1. I don't see any signs of an active antivirus program in your HijackThis log. If you do have an AV program installed, the worm may have disabled it; we'll attempt to fix that shortly. If you don't have an AV program installed, please download and install the free AVG antivirus utility now.
2. Open Windows Notepad, cut-n-paste the entire contents of the Quote box below into the new Notepad document, and then click the "Save As..." option under the "File" menu. In the Save As window, name the file RbotFix.reg and save it to your desktop: Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]
"Start"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"EnableDCOM"="Y"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]
"Start"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"restrictanonymous"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"ms ownage"=-
3. Download and install the following utilities:CCleaner - www.ccleaner.com
Webroot Spy Sweeper (14 day free trial) - http://www.webroot.com/shoppingcart...4011&vcode=DT02
Microsoft Anti-Spyware beta - http://www.microsoft.com/downloads/...&displaylang=en
ewido Anti-malware - http://www.ewido.net/en/download/
- Open Spy Sweeper, click on "Options", and then click on "Update Definitions" under the Program Options tab. Do not run a scan yet; just close the program once the update completes.
- Open ewido. In the main screen, click "Update" and click "Start Update". After the update process completes, exit from Ewido.
- Open MS Antispyware beta. Make sure the "AntiSpyware Autoupdater" feature is enabled, and that it has downloaded the most current antispyware updates. Close the program after you've verified this.
- Open your antivirus program and use its online update function to make sure that it has the most current virus definitions installed. Again- don't scan yet, just close the program once it's updated.
4. Double-click on the RbotFix.reg file that you saved on your desktop and choose Yes when asked if you want to add the information to the Registry.
5. Run HijackTHis again, put a check mark next to the following entries, and then click the "Fix checked" button:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.go2realsearch.com/sp2.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.go2realsearch.com/sp2.php
F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\System\fcs.exe
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [ms ownage] winPE.exe
O4 - HKLM\..\Run: [symwsc.exe] C:\sddg.exe
O4 - HKLM\..\RunServices: [ms ownage] winPE.exe
6. Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up).
Open CCleaner.
- Go to Options-> Advanced: Uncheck "Only delete files in Windows Temp folders older than 48 hours"
- Go to Options>CustomFolders>Add Folder>Navigate to these folders (click on bold file once and hit OK) :
* C:\Windows\Temp
* C:\Windows\Prefetch
* C:\Documents and Settings\\Local Settings\Temporary Internet Files\ (This will delete all your cached internet content including cookies.)
* C:\Documents and Settings\\Local Settings\Temp
* C:\Documents and Settings\\Local Settings\Temporary Internet Files
* C:\Documents and Settings\\Local Settings\Temp
* C:\Documents and Settings\\Cookies
* C:\Documents and Settings\\Cookies
Hit OK
- In left pane, scroll down to "Advanced, Custom Folders", put a check in Custom Folders
- Click on Run CCleaner
It may take a while for the program to perform its cleaning, so be patient. Close the program when it has finished.
- Run your antivirus program, MS Antispyware, and ewido; have the programs fix all malicious items they find.
When ewido finds the first malicious object on your system, it will ask you if it should clean it. When it asks this, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK.
Save the log file that ewido will create after it finishes scanning; you'll be including that log in your next post here.
- Run Spy Sweeper.
* Under the Sweep Options tab, select ALL options under 'What to Sweep'.
* Click the "Sweep" icon and then "Start" to begin scanning.
*When the scan completes, click Next to automatically quarantine all detected items.
*Click the Results icon, select Session Log, and then click Save to File. Save the scan results to your desktop and close Spy Sweeper.
7. Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".
- Search for the following files and delete them if found:
C:\WINDOWS\System\fcs.exe
winPE.exe
C:\sddg.exe
8. Empty your Recycle Bin, reboot normally, run HijackThis again, and post the new log. Also post the logs that ewido and Spy Sweeper generated.