the following is best done in safe mode O4 - HKCU\..\Run: [OLE] C:\WINDOWS\svchosts.exe that is not the legit windows file, svchost.exe, the S makes the differance. It is the Backdoor.Zinx Trojan. O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZRxdm075XXAU that is the mywebsearch adware, fix it, then delete its folder check out the prevention section of my Guide To Malware for tips, info, and links to freeware programs, that can help prevent the infection from happening again.