Listen up kiddies, cause Im only going to write this once.
The really simple guide to getting rid of Spy|Ad|Mal|ware in Windows XP:
(you will need the Spybot S&D installer and HijackThis burned to a CD for this...)
1) Reboot into Safe mode, Command prompt only. This can be done by repeatedly tapping "F8" while booting.
2) Press Ctrl+Alt+Delete, click on "Proccess", check for anything funny. It should be clean, but just make sure.
3) Using the command prompt, run "regedit". This will load the Registry editor.
4) Navigate to "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version\Run". Any spyware on the system will have a reference in this list.
5) Run through the list one by one and check the executable name/path. If you recognize it as legit, skip it. If you dont recognize it, look up the executable name on Google. If you recognize it as spyware, move on to step 5a.
5a) If the item is spyware, jot down its path. If only the filename is in ithe path, its likely in "C:\windows".
5b) Using the command promt, CD into the path containing the spyware's executable. Run "dir FILENAME" and see if it is listed. If it is, run "delete FILENAME" to remove it. If it isnt, run "attrib -h -s -r FILENAME", then "dir "FILENAME" again. The file should then appear. If the executable is in its own folder in "\program files\", remove the entire folder with "delete *" then "cd ../" and "rmdir FOLDERNAME". If the folder contains subfolders, recursively remove their contents with "delete *", and then the folders themselves with "rmdir FOLDERNAME".
5c) Delete the item from the Registry.
6) In the Registry editor, check for other folders under "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version\" that start with "Run". Examples would include "RunOnce" and "RunServices". If such a folder exists, enter it and go back to step 5.
7) Exit the registry editor.
8) Using the command prompt, run "services.msc".
9) Go through the list one by one. Legit services will have realistic-sounding descriptions, illegit ones will either lack a description, or have somthing stupid. If you cant tell, look up the service name on Google.
9a) If you have identified a service as spyware, doubleclick on the entry to load the properties dialog. If the service is running, click on "Stop", then change the "startup type" from "automatic" to "disabled".
9b) Jot down the executable name and path of the service.
9c) Using the command prompt, navigate the path containing the service. Run "dir FILENAME" and see if it is listed. If it is, run "delete FILENAME" to remove it. If it isnt, run "attrib -h -s -r FILENAME", then "dir "FILENAME" again. The file should then appear. If the service is in its own folder in "\program files\", remove the entire folder with "delete *" then "cd ../" and "rmdir FOLDERNAME". If the folder contains subfolders, recursively remove their contents with "delete *", and then the folders themselves with "rmdir FOLDERNAME".
10) Close the Services editor window.
11) Reboot. Do this by pressing Ctrl+Alt+Del, clicking "Shut down", then "Restart". Windows needs to be shut down normally in order to preserve the changes to the registry youve made.
12) Use "F8" and boot back into Safe mode Command prompt only. Do NOT boot normally.
13) Put your Spybot/Hijackthis CD into the tray.
14) Using the command prompt, run "D:" to switch to the CD. If 'D' is not your CDrom, replace 'D' with the correct drive letter.
15) Run HijackThis.
15a) HT will report a number of false positives, but a clean system will have few or no BHOs, so assuming one is spyware is generally safe.
15b) Using the command prompt, navigate the folder containing the object. Run "delete OBJECTNAME" to remove the object.
16) Close HijackThis.
17) Run the Spybot S&D installer. Enable TeaTimer.
18) Run a spyware scan. Repair any results.
19) Reboot. Let windows boot normally.
20) Run Windows Explorer, then close it. Repeat this twice.
21) Run Internet Explorer, then close it. Repeat this twice.
22) Run Spybot S&D, then run a spyware scan. If there are any results, repair them.
23) STOP USING INTERNET EXPOLORER.
And when the moment is right, I'm gonna fly a kite.