Exit the Services utility. Restart to safe mode. Please change your explorer settings as shown here to make sure, that you can see all files and folders.

Go to: http://www.spywareinfo.com/~merijn/winfiles.html and download SDHelper.dll. Beside "Startup Type" in the dropdown menu select "Disabled".

Logfile of HijackThis v1.98.2 Scan saved at 9:52:44 PM, on 12/2/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE

http://www.f-secure.com/en_EMEA/secu...nline-scanner/ Report the results and new HJT log. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types".

Also, why are you only running SP1?

O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: &Yahoo! Press enter to start HijackThis. I ran adaware, rebooted and ran HJT.

Anti-Spyware Programs ComparedWant to know just how effective your anti-spyware program is?

'Invalid Syntax Error' in IE 6 - please review HijackThis log

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to

I just checked it and it had 4% CPU and 1.43G memory.

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406 Perform the following steps in safe mode: Double click on the cwsserviceemove.reg file you downloaded at the beginning to enter into the registry. I really think you need to look at hardware. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: SSVHelper

Open the Temp folder and go to Edit - Select All then Edit - Delete to delete the entire contents of the Temp folder.

Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html

Visit Windows Update:Make sure that you have all the Critical Updates recommended for your operating system and Internet Explorer.

Find shell.dll and right click on it. Reset System RestoreIf you are using Windows ME or Windows XP, please reset your System Restore.

Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: CNavExtBho