1. Please give us the exact name of the file that you see in Task Manager and any other specific information that you might have concerning the infection.
2. I'd suggest that you remove SpyFighter and use reputable programs like Ad Aware and SpyBot instead. SpyFighter's accuracy is questionable, and the company apparently has advertising partnerships with some of the adware distributors.
You can read a bit more about SpyFighter and other suspect (or outright bogus) "anti-spyware" programs here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
It's a good idea to consult the list at the link above before downloading/installing any spyware-related utilities.
3. Run HijackThis again and have it fix:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {44FA143F-05A1-A796-536B-363BB7DC977C} - C:\WINDOWS\netyq32.dll
- Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up)
- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".
- Locate and delete the C:\WINDOWS\netyq32.dll file.
- For every user account listed under C:\Documents and Settings, delete the entire contents of these folders (but not the folders themselves):
Important: One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if any data that you care about is living in those Temp folders, you need to move it to a safe location now, or it will be erased along with everything else!
1. Cookies
2. Local Settings\Temp
3. Local Settings\History
4. Local Settings\Temporary Internet Files
- Delete the entire content of your C:\Windows\Temp folder.
- Delete the entire content of your C:\Windows\Prefetch folder.
Note- If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed. Windows will allow you to delete the versions of those files which exist in sub-folders within the main Temp/Temorary folders, but might not let you delete the versions of those files that exist in the main Temp folders themselves; this is normal and OK.
- Empty your Recycle Bin.
- Reboot normally.
4. Run HJT again and post the new log it generates.