Hi Neal,
First will I say thanks for your help!
I have done as you have said - I have deleted Virusblast, found no uninstall file so I did it the hard way and deleted the folder. Internet seems to be starting a lot quicker.
Here are my two log files, the first on is ewido and the second is Hjackthis...
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 22

17, 2006-06-16
+ Report-Checksum: 2188CEB0
+ Scan result:
HKLM\SYSTEM\CurrentControlSet\Services\Sniffer\\Ta g -> Adware.BrowserAid : Ignored
C:\Program\Media-Codec -> Trojan.Small : Ignored
HKU\S-1-5-21-1663572197-1333480407-49557600-14936\Software\Microsoft\Windows\CurrentVersion\Ex t\Stats\{F79FD28E-36EE-4989-AA61-9DD8E30A82FA} -> Trojan.Small : Cleaned with backup
C:\Documents and Settings\Administratör\Cookies\banadmin@com[1].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\rumewe01\Cookies\rumewe01@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup
C:\Documents and Settings\rumewe01\Cookies\rumewe01@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\rumewe01\Cookies\rumewe01@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\rumewe01\Cookies\rumewe01@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\rumewe01\Cookies\rumewe01@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\1024\ld536C.tmp -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\1024\ldBF66.tmp -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\1024\ldF1A3.tmp -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\ld101.tmp -> Downloader.Zlob.pu : Cleaned with backup
::Report End
Hijackthis....
Logfile of HijackThis v1.99.1
Scan saved at 22:26:56, on 2006-06-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\UMCSTUB.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program\Compaq\Compaq Management Agents\cpqalert.exe
C:\Program\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
C:\Program\CA\SharedComponents\DesktopCommonServic es\DMPrimer\dmprimer.exe
C:\Program\Compaq\COMPAQ~2\hibserv.exe
C:\Program\Network Associates\Common Framework\FrameworkService.exe
c:\Program\Network Associates\VirusScan\mcshield.exe
c:\Program\Network Associates\VirusScan\vstskmgr.exe
C:\Program\Delade filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\PGPsdkServ.exe
C:\Program\CA\Unicenter Remote Control\rcHost.exe
C:\BVADMIN\SDO\BIN\SDSERV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\BVADMIN\SDO\BIN\TRIGGAG.EXE
C:\Program\Compaq\COMPAQ~1\cpqdmi.exe
C:\SxpInst\sxplog32.exe
C:\WINDOWS\Explorer.EXE
C:\BVADMIN\SDO\BIN\triggusr.exe
C:\Program\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program\Compaq\EAB\EABSERVR.EXE
C:\Program\Compaq\Hotkey Software\hkss.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\WINDOWS\system32\ltmsg.exe
C:\Program\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\Program\Real\RealPlayer\RealPlay.exe
C:\Program\Philips ToUcam Camera\VProperty.exe
C:\Program\QuickTime\qttask.exe
C:\Program\Network Associates\VirusScan\SHSTAT.EXE
C:\Program\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\MSN Messenger\MsnMsgr.Exe
C:\Program\Skype\Phone\Skype.exe
C:\Program\PGP Corporation\PGP for Windows XP\PGPtray.exe
C:\Program\ewido anti-malware\ewidoctrl.exe
C:\Program\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\rumewe01\Skrivbord\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.aftonbladet.se/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
F2 - REG:system.ini: UserInit=userinit,C:\SxpInst\sxplog32.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IEExtension Class - {1F6FE2C2-6040-4645-9053-7F689AFFE176} - C:\Program\VirusBlast\BlastIEmonitor.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\Program\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program\Compaq\EAB\EABSERVR.EXE /Start
O4 - HKLM\..\Run: [hkss] C:\Program\Compaq\Hotkey Software\hkss.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [RealTray] C:\Program\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program\Philips ToUcam Camera\VProperty.exe
O4 - HKLM\..\Run: [2FFBk5wc] C:\WINDOWS\wtihof.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "c:\Program\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PGPtray.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program\MultiPoker\MultiPoker.exe
O9 - Extra 'Tools' menuitem: MultiPoker - {641F4F4E-6C91-4159-869E-9F5CE6F0F64E} - C:\Program\MultiPoker\MultiPoker.exe
O9 - Extra button: @C:\Program\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://knuten
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary...r.cab28578.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsof...?1150059672787
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1150059656824
O16 - DPF: {83873F92-B99B-400A-9E36-52B5F4970FB7} -
http://appdirectory.messenger.msn.co...haringctrl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.comp...io5_3_16_0.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary...n.cab28578.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: RCEnumDD.dll
O23 - Service: McAfee Alert Manager (AlertManager) - McAfee Division of Network Associates, Inc. - c:\Program\Network Associates\Alert Manager\amgrsrvc.exe
O23 - Service: Asset Management Agent (AmoAgent) - Computer Associates International, Inc. - C:\WINDOWS\UMCSTUB.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\Program\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Remote Diagnostics Enabling Agent (DfwWebAgent) - Hewlett-Packard - C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
O23 - Service: DM Primer (DMPrimer) - Unknown owner - C:\Program\CA\SharedComponents\DesktopCommonServic es\DMPrimer\dmprimer.exe" -DMPRIMER_SERVICE_: (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program\ewido anti-malware\ewidoctrl.exe
O23 - Service: Hibernation - Unknown owner - C:\Program\Compaq\COMPAQ~2\hibserv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - c:\Program\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - c:\Program\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: PGPsdkService (PGPsdkServ) - PGP Corporation - C:\WINDOWS\System32\PGPsdkServ.exe
O23 - Service: Unicenter Remote Control Host (rcHost) - Computer Associates International, Inc. - C:\Program\CA\Unicenter Remote Control\rcHost.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Accociates, Intl Inc. - C:\BVADMIN\SDO\BIN\SDSERV.EXE
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
Uninstall_log...
Ad-Aware SE Personal
Adobe Reader 6.0 - Svenska
Agresso HKBRAD
America's Army
AmericasArmy
ArcSoft Camera Suite
ATI Display Driver
BV Meny
CA Unicenter Remote Control 6.0 ENU
Canon Camera Window for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon IXY 320, PowerShot S230, IXUS v3 WIA Driver
Canon PhotoRecord
Canon Utilities File Viewer Utility 1.2
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
Cisco Systems VPN Client 4.0.2 (A)
Compaq Easy Access Buttons 3.00 D2
Compaq HotKey Support Software
Compaq Power Management
Compaq Security Management
Diagnostics for Windows
DivX
DivX Player
ewido anti-malware
Excursion
GameSpy Arcade
HijackThis 1.99.1
Hyena
Insight Management Agents
Intel(R) PRO Ethernet Adapter and Software
InterVideo WinDVD
Java 2 Runtime Environment Standard Edition v1.3.1
Java 2 Runtime Environment, SE v1.4.2_04
Lucent Win Modem
Macromedia Flash Player
Macromedia Flash Player 8
McAfee Alert Manager
McAfee VirusScan Enterprise
Microsoft .NET Framework (English)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Swedish Language Pack
Microsoft .NET Klientpolicy Knuten III
Microsoft Visio Professional
MSN Messenger 6.2
MSN Messenger 7.5
MSXML 4.0 SP2 Parser and SDK
MultiPoker
NETGEAR 108 Mbps Wireless PC Card WG511T
Network Stumbler 0.4.0 (remove only)
Nokia Connectivity Cable Driver
Nordsjö-Sadolin Vision 1.0
OFFICE XP
ORiNOCO OR Manager
PGP 8.0.2
Philips ToUcam Fun Camera
QuickTime
RealPlayer Basic
Remote Diagnostics Enabling Agent
SeeMePlayMe Client
SeeMePlayMe Client
Shockwave Player
Skype 2.0
Sniffer Basic 4.5
Spybot - Search & Destroy 1.4
Säkerhetsuppdatering för Windows XP (KB883939)
Säkerhetsuppdatering för Windows XP (KB896422)
Unicenter Service Desk
Unicenter Software Delivery
Windows Media Format Runtime
Windows Media Player 10
Windows Media-kodaren 9 Series
Windows Media-kodaren 9 Series
Windows Messenger 5.0
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB893066
WinRAR archiver
Winzip
Yahoo! Toolbar