More research has lead me to do a sfc /scannow command, which didn't find any integrity violations, and throw malwarebytes on the case. a malwarebytes quick scan came up with this:
Malwarebytes' Anti-Malware 1.51.1.1800
Malwarebytes : Free anti-malware, anti-virus and spyware removal download
Database version: 7398
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
07/08/2011 13:01:04
mbam-log-2011-08-07 (13-00-44).txt
Scan type: Quick scan
Objects scanned: 188131
Time elapsed: 8 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\8DDYX0ZBPZ (Trojan.FakeAlert.SA) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\ZU6RKI1ONY (Trojan.FakeAlert.SA) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\VB AND VBA PROGRAM SETTINGS\Micronsoft (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSWUpdate (Trojan.Agent.Gen) -> Value: MSWUpdate -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSWUpdate (Trojan.Agent.Gen) -> Value: MSWUpdate -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell.Gen.A) -> Bad: (Explorer.exe "C:\Users\Dell\AppData\Roaming\services.exe") Good: (Explorer.exe) -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> No action taken.
c:\Windows\Tasks\{810401e2-dde0-454e-b0e2-aa89c9e5967c}.job (Trojan.FraudPack) -> No action taken.
Some of the things in there even to my untrained eye look pretty rubbish, would a full scan uncover more undesirable things? will removing the selected things just clean the nasties or will it delete the files completely that might be important? I'm not sure really how these programs work, it might sound like a stupid question, but I guess it would be stupider not to ask...
Another question, my sfc /scannow didnt return any violations, but its clear I'm being violated, why is it lying to my face? is it just not as powerful a tool as malware bytes? or is malwarebytes trying to sell itself to me? OR (because I ran them at the same time) is malware bytes fighting the good fight so sfc /scannow can chill? this is a very new world to me.
many thanks in advance.