About:blank problem

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

bbmack

Thread Starter
Joined
Apr 17, 2007
Messages
27
It seems about:blank has made a most unwelcome appearance on my computer and has nocked the internet off on one of the comps accounts.

Had this prob about 3 yrs ago, after months of problems I came across a shreader that a uni student had created that got rid of the problem in seconds. Can't find that so was hoping one of you guys could help me again.


Here's the logfile:

Logfile of HijackThis v1.99.1
Scan saved at 00:38:35, on 01/01/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE
C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\ScanSoft\OmniPage15.0\Opware15.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IW Controlcenter] C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [Opware15] "C:\Program Files\ScanSoft\OmniPage15.0\Opware15.exe"
O4 - HKLM\..\Run: [PDF3 Registry Controller] "C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\\RegistryController.exe"
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\IEShellExt.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\tmwsock.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141203110187
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: Net MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
 
Joined
Sep 7, 2004
Messages
49,014
DownLoad http://www.cexx.org/lspfix.htm

Launch the LSP application, and click the "I know what I'm doing" checkbox.

Check all instances of tmwsock.dll (and nothing else), and move them to
the "Remove" pane.
Then click Finish.

Restart in safe mode

Now delete the C:\windows\system32\tmwsock.dll--> file
Reboot.
================

Download Superantispyware (SAS) free home version

http://www.superantispyware.com/superantispywarefreevspro.html

Install it and double-click the icon on your desktop to run it.
· It will ask if you want to update the program definitions, click Yes.
· Under Configuration and Preferences, click the Preferences button.
· Click the Scanning Control tab.
· Under Scanner Options make sure the following are checked:
o Close browsers before scanning
o Scan for tracking cookies
o Terminate memory threats before quarantining.
o Please leave the others unchecked.
o Click the Close button to leave the control center screen.
· On the main screen, under Scan for Harmful Software click Scan your computer.
· On the left check C:\Fixed Drive.
· On the right, under Complete Scan, choose Perform Complete Scan.
· Click Next to start the scan. Please be patient while it scans your computer.
· After the scan is complete a summary box will appear. Click OK.
· Make sure everything in the white box has a check next to it, then click Next.
· It will quarantine what it found and if it asks if you want to reboot, click Yes.
· To retrieve the removal information for me please do the following:
o After reboot, double-click the SUPERAntispyware icon on your desktop.
o Click Preferences. Click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o It will open in your default text editor (such as Notepad/Wordpad).
o Please highlight everything in the notepad, then right-click and choose copy.
· Click close and close again to exit the program.
· Please paste that information here for me with a new HijackThis log.

This will take some time!!!!!!!!
 

bbmack

Thread Starter
Joined
Apr 17, 2007
Messages
27
Wow that did take some time (y) Found about 7 Trojan Horse's too.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/01/2002 at 05:05 AM

Application Version : 3.9.1008

Core Rules Database Version : 3265
Trace Rules Database Version: 1276

Scan type : Complete Scan
Total Scan Time : 03:02:12

Memory items scanned : 469
Memory threats detected : 0
Registry items scanned : 7109
Registry threats detected : 0
File items scanned : 118314
File threats detected : 197

Adware.Tracking Cookie
C:\Documents and Settings\Julia\Cookies\[email protected][2].txt
C:\Documents and Settings\Julia\Cookies\[email protected][1].txt
C:\Documents and Settings\Julia\Cookies\[email protected][2].txt
C:\Documents and Settings\Julia\Cookies\[email protected][1].txt
C:\Documents and Settings\Julia\Cookies\[email protected][1].txt
C:\Documents and Settings\Julia\Cookies\[email protected][2].txt
C:\Documents and Settings\Julia\Cookies\[email protected][1].txt
C:\Documents and Settings\Julia\Cookies\[email protected][1].txt
C:\Documents and Settings\Julia\Cookies\[email protected][1].txt
C:\Documents and Settings\Julia\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][2].txt
C:\Documents and Settings\Natalie\Cookies\[email protected][1].txt

Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\LAURA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\UGPL7F3Z\ANTI4[1].EXE
C:\DOCUMENTS AND SETTINGS\LAURA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\VOLDFC4S\ANTZOM[1].EXE
C:\DOCUMENTS AND SETTINGS\NATALIE\LOCAL SETTINGS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\01EFST6F\XC60[1].EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1962E516-0B3A-4D57-AF31-7DD20206D70D}\RP246\A0109824.EXE

Malware.SpyVampire
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1962E516-0B3A-4D57-AF31-7DD20206D70D}\RP246\A0109820.EXE

Trojan.Downloader-Gen/SysFade
C:\WINDOWS\SYSFADE.EXE

Trojan.Downloader-FC
C:\WINDOWS\SYSTEM32\KERNELS32.EXE

Trojan.Downloader-Gen/RSVP
C:\WINDOWS\SYSTEM32\RSVP322.DLL
C:\WINDOWS\SYSTEM32\RSVP322.DLLYRT

Trace.Known Threat Sources
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\ZG1PL5V1\text[1].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\cmd[1].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\ZG1PL5V1\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\text[6].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\ZG1PL5V1\cmd[4].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\ZG1PL5V1\cmd[5].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\text[5].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[5].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[5].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\ZG1PL5V1\cmd[3].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[9].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[2].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[3].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[4].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[10].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\text[7].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[5].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\ZG1PL5V1\cmd[6].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[1].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[12].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[1].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[10].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\X9A3U2SO\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[6].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[2].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[2].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[6].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[4].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[11].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[6].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[7].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[3].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[9].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[5].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[1].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[4].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[8].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[10].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[13].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[1].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[10].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[9].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[7].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[13].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[5].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[8].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[14].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[10].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[10].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[7].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[9].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[12].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[5].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[7].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[14].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[6].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[11].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[13].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[11].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[13].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[15].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[13].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[7].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[18].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[11].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[14].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[16].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[14].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[14].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[15].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[15].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\cmd[2].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\cmd[12].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\cmd[12].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[13].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[17].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\E3QR0TWL\text[16].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[17].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[15].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[14].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[16].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\cmd[1].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[1].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\QTK7M18J\text[16].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\text[16].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\text[6].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[19].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\text[1].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\text[1].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[8].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\cmd[1].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[18].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[1].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\cmd[6].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\text[6].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\L1ZK64KW\cmd[12].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\KTOXEVSN\text[14].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[2].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[7].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\cmd[2].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\cmd[6].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[5].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\text[7].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\text[4].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\cmd[5].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[3].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[7].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\cmd[1].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[2].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[4].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[6].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[13].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\cmd[3].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[9].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[7].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\text[8].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[6].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VOLDFC4S\text[10].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\text[5].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\cmd[5].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[3].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\text[9].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[9].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[10].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\UGPL7F3Z\cmd[5].htm
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\MRKP254V\text[10].dat
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\VP0KWBVN\text[5].dat
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\5KBTZG2K\cmd[1].htm
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\01EFST6F\text[2].dat
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\O9EJG5I3\text[1].dat
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\01EFST6F\text[1].dat
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\8DMZ8DIN\text[1].dat
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\5KBTZG2K\cmd[2].htm
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\8DMZ8DIN\cmd[2].htm
C:\Documents and Settings\Natalie\Local Settings\Temp\Temporary Internet Files\Content.IE5\8DMZ8DIN\anti4[1].exe





Here is the hi-jack this logfile

Logfile of HijackThis v1.99.1
Scan saved at 13:07:06, on 01/01/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE
C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\ScanSoft\OmniPage15.0\Opware15.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IW Controlcenter] C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [Opware15] "C:\Program Files\ScanSoft\OmniPage15.0\Opware15.exe"
O4 - HKLM\..\Run: [PDF3 Registry Controller] "C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\\RegistryController.exe"
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\IEShellExt.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141203110187
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: Net MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\Net MD Simple Burner\NetMDSB.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

Thank you very much
 
Joined
Sep 7, 2004
Messages
49,014
DownLoad EasyCleaner http://www.majorgeeks.com/download414.html

Use the clear files and Unnecessary files buttons – I do not recommend
using the Duplicates files button
as many dupes are there on purpose.

Not all files will delete – that is normal.

In the unnecessary button I check the top 4 entries
=======================

Clean

If you feel its is fixed mark it solved via Thread Tools above

Turn off restore points, boot, turn them back on – here’s how

http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam

This clears infected restore points and sets a new, clean one.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top