Ok, You should print out the following instructions, as we will be working in safe mode. Reconfigure Windows XP to show hidden files: Click Start. Open My Computer. Select the Tools menu and click Folder Options. Select the View Tab. Under the Hidden files and folders heading select "Show hidden files and folders". Uncheck the "Hide protected operating system files (recommended)" option. Uncheck the "Hide file extensions for known file types" option. Click Yes to confirm. Click OK. Download Winsockxpfix but do not run it yet. I suggest you remove NewDotNet unless you deliberately installed it. It is extremely dubious and commercially sponsored: First, please open Add/Remove programs and uninstall New.Net or NewDotNet from there if listed. If it is not listed, follow these instructions: ̢̮â¬Å¡Ãâ÷ From a computer that has Internet access, click on the following link: ]http://www.new.net/support/uninstall6_76[Caution: ExecutableFile]. ̢̮â¬Å¡Ãâ÷ Download and save uninstall6_76[Caution: ExecutableFile] to Local Disc C ̢̮â¬Å¡Ãâ÷ Click on Start. ̢̮â¬Å¡Ãâ÷ Click on Run. ̢̮â¬Å¡Ãâ÷ In the Open window type, C:\uninstall6_76[Caution: ExecutableFile]. ̢̮â¬Å¡Ãâ÷ Click on the OK button. ̢̮â¬Å¡Ãâ÷ After removal, you may be prompted to reboot. Please reboot if not prompted. In case your internet connection breaks, run the winsock fix. Open Hijackthis, and select "Scan only" and place a checkmark in the following boxes: R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.e3e (CAUTION - executable file) O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_90.dll O4 - HKLM\..\Run: [wpib] C:\WINDOWS\wpib.e3e (CAUTION - executable file) O4 - HKLM\..\Run: [Warning] cfpsys.e3e (CAUTION - executable file) O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.e3e (CAUTION - executable file) /auto O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/26fee675102 ... xIE601.cab Then close all other windows and select "Fix Checked". Boot into safe mode by restarting your computer and continuously tapping F8 and selecting "Safe Mode". Click "Start > Control panel > add/remove programs and look for the following and remove them (if present): winupdates netster Then browse for the following and delete them: C:\WINDOWS\system32\Userinit[Caution: ExecutableFile] <- File C:\Program Files\NewDotNet <- Folder C:\WINDOWS\wpib[Caution: ExecutableFile] <- File C:\Program Files\winupdates <- Folder Click start > search and search for the following and delete it: cfpsys[Caution: ExecutableFile] <- File Now reboot normally and post a fresh Hijackthis log please. How is your computer running now!