- Boot to safe mode without networking

- Delete all of your temporary files, temporary internet files C:\Documents and Settings\<user>\Local Settings\ temp folders, C:\Windows\Temp folders, etc

- Delete anything suspicious in C:\Windows and C:\Windows\System32 that was modified in the last month or so (after researching to find what's legitimate and not)

- Clean anything suspicious in the registry HKLM\Software\Microsoft\Windows\Current Version\Run and its corresponding HKCU entry, and find and delete any files they reference

- View the registry HKLM\Software\Microsoft\Windows\Current Version\Explorer\Browser Helper Objects, copying each key name and running a search on the reg for them, deleting both the CLSID entries, coresponding files, and BHO entries

- Delete anything suspicious in HKLM\Software and HKCU\Software in the registry

- Delete anything suspicious in C:\Program Files

- Delete anything hiding in the Startup folder of the start menu

- On a seperate machine, download Webroot's Spy Sweeper and install it on the infected machine

- Reboot to safe mode with networking, launch Spy Sweeper, get the latest updates, and run a full scan, quarantining then deleting anything that it finds

- Reboot your machine as normal, watching the Task Manager process list during as much of the boot process as you can, watching for anything suspicious

- Subscribe to Spy Sweeper updates for a year or more and activate them

- Download the MVPS Host List and apply that per its instructions

- Download Mozilla Fire Fox and register it as the default handler for web related files

- Download some alternative media player(s) and avoid Windows Media Player (which spyware constantly hijacks)


Anti-spyware is long since a 100% necessity just like than anti-virus. I'll take my own advice one of these days, but until I do, you should. Good luck.
_________________________
-
FireFox31
110gig MKIIa (30+80), Eutronix lights, 32 meg stacked RAM, Filener orange gel lens, Greenlights Lit Buttons green set