Download these tools:-
SpyBot SnD
TrojanHunter Trial
SpywareBlaster
Boot in safe mode. Run HijackThis, click "Do a system scan only", and put a checkmark against these entries:-
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favorites
O2 - BHO: (no name) - {3C4E691E-50E0-4163-8E94-37F72E994272} - (no file)
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://E:\content\include\XPPatchInstaller.CAB
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://E:\Content\include\msSecUcd.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - *security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - *www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - *www-secure.symantec.com/techsupp/activedata/ActiveData.cab
Then close all other open programs, and click "Fix Checked" in HijackThis.
Then exit from HijackThis, and delete these files:-
C:\WINDOWS\system32\winshost.exe
E:\content\include\XPPatchInstaller.CAB
E:\Content\include\msSecUcd.cab
Run these tools SpyBot SnD, TrojanHunter and perform a full system scan, and remove any malwares they may find. After this, run SpywareBlaster, and click "Enable All Protection" and close it.
Reboot to Normal Mode. You are using an older version of HijackThis. Get the latest version and post a new HijackThis log file.