Can you please download the latest version of HijackThis.
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exeInstall it, but do not run it.
[*]Download SDFix by AndyManchesta and save it to your desktop.
[*]Double click on SDFix.exe. By default, it will install to C:\.
[*]Click on Install.
Next, boot into Safe Mode.
[*]When you see BIOS screen, start pressing F8.
[*]A boot menu will appear shortly.
[*]Using the up down arrows, select Safe Mode and press the Enter key.
[*]Windows will now load.
[*]Log in to your usual account.
[*]Navigate to C:\SDfix (if you installed it to the default location, otherwise, locate where you installed it)
[*]Double click on RunThis.bat
[*]Type Y to begin the cleanup process.
[*]It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
[*]Press any key to reboot.
[*]When the PC restarts the tool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
[*]Once the desktop icons load, the SDFix report will open on screen. You can also find the report in SDFix folder, named Report.txt.
Upload these 2 files to
Virus Total or
Jotti for a scan.
1. C:\WINDOWS\system32\s2.exe
2. C:\WINDOWS\system32\systemw32.exe
Copy and paste the first file into the Browse box. After the first file is done with the scanning, save the results of the scan and repeat with the second file.
Post these 3 logs:
1. SDFix report
2. A new HijackThis log
3. The scan results of the 2 files