Follow the default settings for installation. Please print these directions and then proceed with the following steps in order.Step #1Download CCleaner and install it but do not run it yet.Step #2Start in Safe Mode Using the F8 This will take multiple stages so please have patience.

Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1098853670873 O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class)

Logfile of HijackThis v1.97.7 Scan saved at 12:25:04 PM, on 11/24/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

AFter about 5 minutes of websearching and thinking everything was okay, i closed IE and all of that crap reinstalled itself on my computer. Check to see if salm.exe is in Processes and if it is, End Process it. I realized i had websearch toolbar, virtual bouncer, and adestroyer added to my start menu. The CPU still shoots up to 100% quite a bit, but I'm not too concerned about it anymore.

Scan with HJT and have it fix the following entries: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com R1

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Make sure these items have your preferred settings in them.: "Default homepage" "Default searchpage" Click "Tweak" on the left hand side to display the Tweak Settings box.

Also remove these folders in Program Files: 180solutions 180search assistant Fix this in HijackThis: C:\PROGRA~1\COMMON~1\tsa\tsl.exe Restart your computer in "Safe Mode". Nov 21, 2004 #11 gtrawlings TS Rookie begin2search hijacked Could someone look at this log. Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - (no file) O18 - Filter: text/plain - {B72F75B8-93F3-429D-B13E-660B206D897A} - (no file)

When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. STEP TWO Please follow these instructions to run Adware. To help keep your computer somewhat safer, you should get SpywareBlaster and/or SpywareGuard

Here is my HJT-log: Logfile of HijackThis v1.98.2 Scan saved at 08:50:52, on 13/11/2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: F:\WINNT\System32\smss.exe F:\WINNT\system32\winlogon.exe F:\WINNT\system32\services.exe Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quietO4 - HKCU\..\RunServices: [Compaq Print Fax] cpqa1000.exeO8 - Extra context menu item: Speak by TextToSpeechMP3 - C:\Program Files\TextToSpeechMP3\ttsttsmcom.htmO9 - Extra button: TextToSpeechMP3 - {03b5d444-9d5c-4361-aab5-f81f37f0f704} - C:\Program Files\TextToSpeechMP3\ttsttsmcomIE.htmO9 - I am not in safe mode with networking and I'm afraid to start in normal mode in fear that I will get all those spyware/adware programs.

I want to try to clean everything in here because I fear the malware pigeon-holing again in normal mode.