User account creation after virus with suspicous tracking parameters and not detectable by any norton products

I downloaded a  file that appeared to be installing a free program , but i clicked cancel at 25% (sony vegas) but after clicking cancel and opening up my browser there were many malware advertisements all over internet explorer and it was extremely slow

I ran full system scan , power eraser/file reputation scan even on the specific files and nothing showed up

So i assumed i could track where sony vegas was installed     C:\Users\kesug_000\AppData\Local\Microsoft\Windows\INetCache\IE\X2FA1DWM       This folder is invisible even with show hidden files enabled , i can only go to this folder by search or direct copy and pasting because in file browser the folder "INETCACHE" simply does not exist

contained in that folder was a supposed sony vegas installer and PNG images with jpg's (All the files modified on 9/23/2014) that i opened and noticed they were the same popups and advert spam i noticed in internet explorer

There were also 'script files' i tried to delete but could not because it belonged to a new user i never encountered before - after trying to modify the file to stop the popups another duplicate file immediately  appeared  with user permission changed to a user with this name so i knew this was a virus

S-1-5-21-8077971-2639352479-2834690060-1001

after many tries i managed to change the ownership of the files and delete them , after i deleted said files the popups stopped

 

next i tried deleting the account/changing ownership in safemode and after restarting my computer was seriously bugged -

black desktop background,extremely slow internet explorer that could not DOWNLOAD ANYTHING off the internet (i did not change any settings) but today i managed to change all of my security settings to maximum, disabled internet explorer,enabled UAC and changed default parent control of all files on C hardrive . after doing so my wallpaper spontaneous repaired and after installing firefox mozilla from a usb it   has not had any problems

[image] http://i60.tinypic.com/zsv8k8.png [/image]

but this user has stayed in my system with ownership on 'information' files specifically like the search utility , user app data folder and all my desktop items(public desktop folder included) , with low level permissions on desktop items which allows it to delete them but not full control and full control ownership on the search utility and app data folder

and if i do change ownership and delete this unknown account it reappears after i restart my computer! i think a script is involved but i have no clue where it is

This user also does not show up on 'net user' for command prompt or user accounts menu in control panel or when i go to the security tab on a file and go to 'add' , this lists many other groups like SYSTEM but not the unknown account

 

please someone help me!

how can i permanently remove this unknown user that i know came from a virus that was undetectable by any norton products?!