Hi,
Thanks again for responding.
My problem sounds pretty serious.
I downloaded and ran CounterSpy as you recommended. It found 11 threats including the ones you mentioned. CounterSpy removed some threats and Quarantined some others. Should I remove the quarantined threats?
Also "liveUpdate" is still not functioning, and I still can not connect to Symantecs website.
Here is the CounterSpy log:
Spyware Scan Details
Start Date: 10/9/2006 7:12:06 AM
End Date: 10/9/2006 8:12:19 AM
Total Time: 1 hrs 13 secs
Detected spyware
Messenger Plus! Adware Bundler more information...
Details: Messenger Plus! is a add-on for MSN Messenger. Messenger Plus! installs an OPTIONAL adware called C2Media which is also known as LOP.com.
Status: Ignored
Infected files detected
c:\documents and settings\carol and robert\my documents\my chat logs\jameslovaghy@msn.com.txt
eDonkey2000 P2P Program more information...
Details: eDonkey2000 is a peer-to-peer (P2P) application that allows its users to join together in a network via the Internet and share files from each other's hard drives.
Status: Ignored
Infected files detected
c:\documents and settings\carol and robert\my documents\edonkey2000 downloads\2_crack[1].cd-virtual_cover_creator_v2.1.zip
c:\documents and settings\carol and robert\my documents\edonkey2000 downloads\dvd region+css free 5.9.6.5 + serial-number.zip
c:\program files\edonkey2000\5.html
c:\program files\edonkey2000\78.html
c:\program files\edonkey2000\blacklist.txt
c:\program files\edonkey2000\contact.dat
c:\program files\edonkey2000\def.html
c:\program files\edonkey2000\edonkey2000.exe
c:\program files\edonkey2000\friend.met
c:\program files\edonkey2000\friend.met.bak
c:\program files\edonkey2000\keyring.dat
c:\program files\edonkey2000\keyring.dat.bak
c:\program files\edonkey2000\known.met
c:\program files\edonkey2000\known.met.bak
c:\program files\edonkey2000\layout.xml
c:\program files\edonkey2000\log.txt
c:\program files\edonkey2000\media.xml
c:\program files\edonkey2000\pref.xml
c:\program files\edonkey2000\reg.jpg
c:\program files\edonkey2000\server.met
c:\program files\edonkey2000\server.met.bak
c:\program files\edonkey2000\share.dat
c:\program files\edonkey2000\share.dat.bak
c:\program files\edonkey2000\svr-blacklist.txt
c:\program files\edonkey2000\uninstall_edonkey2000.exe
c:\program files\edonkey2000\uploadq.dat
c:\program files\edonkey2000\plugins\boost_thread-vc6-mt-1_31.dll
c:\program files\edonkey2000\plugins\btplugin.dll
c:\program files\edonkey2000\plugins\btplugin.ini
c:\program files\edonkey2000\plugins\easypreview.dll
c:\program files\edonkey2000\plugins\easypreview.txt
c:\program files\edonkey2000\plugins\ed2kie.dll
c:\program files\edonkey2000\plugins\httpprotocol.dll
c:\program files\edonkey2000\plugins\jpcplugin.ini
c:\program files\edonkey2000\plugins\jpcplugin5.dll
c:\program files\edonkey2000\plugins\launchmyapp.dll
c:\program files\edonkey2000\plugins\launchmyapp.ini
c:\program files\edonkey2000\plugins\leeme_esp.rtf
c:\program files\edonkey2000\plugins\lesemich_ger.rtf
c:\program files\edonkey2000\plugins\lma readme.txt
c:\program files\edonkey2000\plugins\readme_eng.rtf
c:\program files\edonkey2000\plugins\unrar.dll
c:\program files\edonkey2000\plugins\_libtorrent_bsd_licence. txt
c:\program files\edonkey2000\skins\default\add2keyring-dis.png
c:\program files\edonkey2000\skins\default\add2keyring-down.png
c:\program files\edonkey2000\skins\default\add2keyring-hover.png
c:\program files\edonkey2000\skins\default\add2keyring-up.png
c:\program files\edonkey2000\skins\default\arrow-down.png
c:\program files\edonkey2000\skins\default\arrow-up.png
c:\program files\edonkey2000\skins\default\background.png
c:\program files\edonkey2000\skins\default\console-big-down.png
c:\program files\edonkey2000\skins\default\console-big-hover.png
c:\program files\edonkey2000\skins\default\console-big-up.png
c:\program files\edonkey2000\skins\default\console-small-down.png
c:\program files\edonkey2000\skins\default\console-small-hover.png
c:\program files\edonkey2000\skins\default\console-small-up.png
c:\program files\edonkey2000\skins\default\download-dis.png
c:\program files\edonkey2000\skins\default\download-down.png
c:\program files\edonkey2000\skins\default\download-hover.png
c:\program files\edonkey2000\skins\default\download-up.png
c:\program files\edonkey2000\skins\default\ed2k-connect.png
c:\program files\edonkey2000\skins\default\ed2k-connected.png
c:\program files\edonkey2000\skins\default\ed2k-connecting.png
c:\program files\edonkey2000\skins\default\ed2k-disconnect.png
c:\program files\edonkey2000\skins\default\ed2k-disconnected.png
c:\program files\edonkey2000\skins\default\exclaim.png
c:\program files\edonkey2000\skins\default\folder-closed-both.png
c:\program files\edonkey2000\skins\default\folder-closed-childshared.png
c:\program files\edonkey2000\skins\default\folder-closed-shared.png
c:\program files\edonkey2000\skins\default\folder-closed-unshared.png
c:\program files\edonkey2000\skins\default\folder-go-up-level.png
c:\program files\edonkey2000\skins\default\folder-open-both.png
c:\program files\edonkey2000\skins\default\folder-open-childshared.png
c:\program files\edonkey2000\skins\default\folder-open-shared.png
c:\program files\edonkey2000\skins\default\folder-open-unshared.png
c:\program files\edonkey2000\skins\default\folder-refresh.png
c:\program files\edonkey2000\skins\default\generatecatalog-dis.png
c:\program files\edonkey2000\skins\default\generatecatalog-down.png
c:\program files\edonkey2000\skins\default\generatecatalog-hover.png
c:\program files\edonkey2000\skins\default\generatecatalog-up.png
c:\program files\edonkey2000\skins\default\launch-dis.png
c:\program files\edonkey2000\skins\default\launch-down.png
c:\program files\edonkey2000\skins\default\launch-hover.png
c:\program files\edonkey2000\skins\default\launch-up.png
c:\program files\edonkey2000\skins\default\little-back.png
c:\program files\edonkey2000\skins\default\main-help-down.png
c:\program files\edonkey2000\skins\default\main-help-hover.png
c:\program files\edonkey2000\skins\default\main-help-up.png
c:\program files\edonkey2000\skins\default\main-options-down.png
c:\program files\edonkey2000\skins\default\main-options-hover.png
c:\program files\edonkey2000\skins\default\main-options-up.png
c:\program files\edonkey2000\skins\default\main-register-down.png
c:\program files\edonkey2000\skins\default\main-register-hover.png
c:\program files\edonkey2000\skins\default\main-register-up.png
c:\program files\edonkey2000\skins\default\managekeyring-dis.png
c:\program files\edonkey2000\skins\default\managekeyring-down.png
c:\program files\edonkey2000\skins\default\managekeyring-hover.png
c:\program files\edonkey2000\skins\default\managekeyring-up.png
c:\program files\edonkey2000\skins\default\mediaplayer.png
c:\program files\edonkey2000\skins\default\moreres-dis.png
c:\program files\edonkey2000\skins\default\moreres-down.png
c:\program files\edonkey2000\skins\default\moreres-hover.png
c:\program files\edonkey2000\skins\default\moreres-up.png
c:\program files\edonkey2000\skins\default\on-connect.png
c:\program files\edonkey2000\skins\default\on-connected.png
c:\program files\edonkey2000\skins\default\on-connecting.mng
c:\program files\edonkey2000\skins\default\on-connecting.png
c:\program files\edonkey2000\skins\default\on-disconnect.png
c:\program files\edonkey2000\skins\default\on-disconnected.png
c:\program files\edonkey2000\skins\default\options-down.png
c:\program files\edonkey2000\skins\default\options-hover.png
c:\program files\edonkey2000\skins\default\options-up.png
c:\program files\edonkey2000\skins\default\preview.png
c:\program files\edonkey2000\skins\default\refresh-dis.png
c:\program files\edonkey2000\skins\default\refresh-down.png
c:\program files\edonkey2000\skins\default\refresh-hover.png
c:\program files\edonkey2000\skins\default\refresh-up.png
c:\program files\edonkey2000\skins\default\remove-dis.png
c:\program files\edonkey2000\skins\default\remove-down.png
c:\program files\edonkey2000\skins\default\remove-hover.png
c:\program files\edonkey2000\skins\default\remove-up.png
c:\program files\edonkey2000\skins\default\search-dis.png
c:\program files\edonkey2000\skins\default\search-down.png
c:\program files\edonkey2000\skins\default\search-hover.png
c:\program files\edonkey2000\skins\default\search-up.png
c:\program files\edonkey2000\skins\default\searching.mng
c:\program files\edonkey2000\skins\default\share-dis.png
c:\program files\edonkey2000\skins\default\share-down.png
c:\program files\edonkey2000\skins\default\share-hover.png
c:\program files\edonkey2000\skins\default\share-up.png
c:\program files\edonkey2000\skins\default\tab-catalogs-down.png
c:\program files\edonkey2000\skins\default\tab-catalogs-hover.png
c:\program files\edonkey2000\skins\default\tab-catalogs-up.png
c:\program files\edonkey2000\skins\default\tab-friends-down.png
c:\program files\edonkey2000\skins\default\tab-friends-hover.png
c:\program files\edonkey2000\skins\default\tab-friends-up.png
c:\program files\edonkey2000\skins\default\tab-home-down.png
c:\program files\edonkey2000\skins\default\tab-home-hover.png
c:\program files\edonkey2000\skins\default\tab-home-up.png
c:\program files\edonkey2000\skins\default\tab-media-down.png
c:\program files\edonkey2000\skins\default\tab-media-hover.png
c:\program files\edonkey2000\skins\default\tab-media-up.png
c:\program files\edonkey2000\skins\default\tab-search-down.png
c:\program files\edonkey2000\skins\default\tab-search-hover.png
c:\program files\edonkey2000\skins\default\tab-search-up.png
c:\program files\edonkey2000\skins\default\tab-servers-down.png
c:\program files\edonkey2000\skins\default\tab-servers-hover.png
c:\program files\edonkey2000\skins\default\tab-servers-up.png
c:\program files\edonkey2000\skins\default\tab-shared-down.png
c:\program files\edonkey2000\skins\default\tab-shared-hover.png
c:\program files\edonkey2000\skins\default\tab-shared-up.png
c:\program files\edonkey2000\skins\default\tab-stats-down.png
c:\program files\edonkey2000\skins\default\tab-stats-hover.png
c:\program files\edonkey2000\skins\default\tab-stats-up.png
c:\program files\edonkey2000\skins\default\tab-transfers-down.png
c:\program files\edonkey2000\skins\default\tab-transfers-hover.png
c:\program files\edonkey2000\skins\default\tab-transfers-up.png
c:\program files\edonkey2000\skins\default\ui.xml
c:\program files\edonkey2000\skins\default\unshare-dis.png
c:\program files\edonkey2000\skins\default\unshare-down.png
c:\program files\edonkey2000\skins\default\unshare-hover.png
c:\program files\edonkey2000\skins\default\unshare-up.png
c:\program files\edonkey2000\skins\default\x-down.png
c:\program files\edonkey2000\skins\default\x-hover.png
c:\program files\edonkey2000\skins\default\x-up.png
c:\program files\edonkey2000\temp\- guns n' roses - live and let die.mp3\1.part.met
c:\program files\edonkey2000\temp\- guns n' roses - live and let die.mp3\1.part.met.bak
c:\program files\edonkey2000\temp\01-everything zen.mp3\1.1.part
c:\program files\edonkey2000\temp\01-everything zen.mp3\1.part.met
c:\program files\edonkey2000\temp\01-everything zen.mp3\1.part.met.bak
c:\program files\edonkey2000\temp\bush-no sex in your violence.mp3\1.part.met
c:\program files\edonkey2000\temp\bush-no sex in your violence.mp3\1.part.met.bak
c:\program files\edonkey2000\temp\bush_everything zen.mp3\1.part.met
c:\program files\edonkey2000\temp\bush_everything zen.mp3\1.part.met.bak
c:\program files\edonkey2000\temp\don't mess with temp files!!!!!.txt
c:\program files\edonkey2000\temp\nothingface - make your own bones.mp3\1.part.met
c:\program files\edonkey2000\temp\nothingface - make your own bones.mp3\1.part.met.bak
c:\program files\edonkey2000\temp\ted nugent (as the amboy dukes) - journey to the center of the mind.mp3\1.part.met
c:\program files\edonkey2000\temp\ted nugent (as the amboy dukes) - journey to the center of the mind.mp3\1.part.met.bak
c:\program files\edonkey2000\temp\the logo creator v4.1 + all logos pack + all bonus logo + serials.zip\1.10.part
c:\program files\edonkey2000\temp\the logo creator v4.1 + all logos pack + all bonus logo + serials.zip\1.43.part
c:\program files\edonkey2000\temp\the logo creator v4.1 + all logos pack + all bonus logo + serials.zip\1.part.met
c:\program files\edonkey2000\temp\the logo creator v4.1 + all logos pack + all bonus logo + serials.zip\1.part.met.bak
Infected registry entries detected
HKEY_CLASSES_ROOT\CLSID\{320154BB-D666-48F6-990E-172B32954620}
HKEY_CLASSES_ROOT\CLSID\{320154BB-D666-48F6-990E-172B32954620}\InProcServer32 C:\Program Files\eDonkey2000\plugins\ed2kie.dll
HKEY_CLASSES_ROOT\CLSID\{320154BB-D666-48F6-990E-172B32954620}\InProcServer32 ThreadingModel Both
HKEY_CLASSES_ROOT\CLSID\{320154BB-D666-48F6-990E-172B32954620}\ProgID eD2KDownloadManager.object.1
HKEY_CLASSES_ROOT\CLSID\{320154BB-D666-48F6-990E-172B32954620}\TypeLib {379919F2-1612-45B7-B9F4-773F6D5214F5}
HKEY_CLASSES_ROOT\CLSID\{320154BB-D666-48F6-990E-172B32954620}\VersionIndependentProgID eD2KDownloadManager.object
HKEY_CLASSES_ROOT\CLSID\{320154BB-D666-48F6-990E-172B32954620} eD2K downloadManager object
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\eDonkey2000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\eDonkey2000 DisplayName eDonkey2000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\eDonkey2000 UninstallString "C:\Program Files\eDonkey2000\uninstall_eDonkey2000.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\eDonkey2000 DisplayIcon "C:\Program Files\eDonkey2000\eDonkey2000.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\eDonkey2000 NoModify 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\eDonkey2000 NoRepair 1
DesktopScam Trojan Downloader more information...
Details: DesktopScam is a trojan that is downloaded with rogue security applicatons in order to frighten the affected user into purchasing the rogue program.
Status: Quarantined
Infected files detected
c:\documents and settings\all users\start menu\security troubleshooting.url
c:\documents and settings\all users\start menu\online security guide.url
Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objecta\{686a161d-5bd1-4999-8832-6393f41e564c}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objecta\{686a161d-5bd1-4999-8832-6393f41e564c}
Haxdoor.Fam Backdoor more information...
Details: Haxdoor.Fam is a group of backdoor trojans that allow a remote attacker to gain access and control the computer. Haxdoor is also used to download additional malware.
Status: Quarantined
Infected files detected
c:\windows\system32\pasksa.dll
c:\windows\system32\p79bsksb.sys
Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pasksa
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pasksa DllName pasksa.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pasksa Startup pasksaope
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pasksa Impersonate 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pasksa Asynchronous 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pasksa MaxWait 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pasksa 2sksid D4B15D6451C7769164D4
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb\Security Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb\Enum 0 Root\LEGACY_P79BSKSB\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb\Enum Count 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb\Enum NextInstance 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb Type 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb Start 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb ErrorControl 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb ImagePath \??\C:\WINDOWS\System32\p79bsksb.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\p79bsksb DisplayName USB p79bsksb
Overnet Adware Bundler more information...
Details: Overnet/eDonkey is a file sharing application that bundles third party adware and spyware with the free version.
Status: Ignored
Infected files detected
C:\Program Files\eDonkey2000\Plugins\ed2kie.dll
Trojan-Downloader.BAT.Ftp.ab Trojan Downloader more information...
Status: Quarantined
Infected files detected
C:\Smitfraudfix\SmitfraudFix\Reboot.exe
SpywareQuake Rogue Security Program more information...
Details: SpywareQuake is a purported anti-spyware application to scan for and remove spyware from users' computers.
Status: Quarantined
Infected registry entries detected
HKEY_CLASSES_ROOT\TypeLib\{5CB9686D-CC21-4927-B904-D91D4479F4BD}
HKEY_CLASSES_ROOT\TypeLib\{5CB9686D-CC21-4927-B904-D91D4479F4BD}\1.0\0\win32 C:\Program Files\SpywareQuake.com\Spyware-Quake.exe
HKEY_CLASSES_ROOT\TypeLib\{5CB9686D-CC21-4927-B904-D91D4479F4BD}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{5CB9686D-CC21-4927-B904-D91D4479F4BD}\1.0\HELPDIR C:\Program Files\SpywareQuake.com\
HKEY_CLASSES_ROOT\TypeLib\{5CB9686D-CC21-4927-B904-D91D4479F4BD}\1.0 AVG 1.0 Type Library
Cookie: ATDMT.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted
Infected cookies detected
c:\documents and settings\carol and robert\cookies\carol and robert@atdmt[2].txt
Cookie: DoubleClick Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted
Infected cookies detected
c:\documents and settings\carol and robert\cookies\carol and robert@doubleclick[1].txt
Cookie: TribalFusion.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted
Infected cookies detected
c:\documents and settings\carol and robert\cookies\carol and robert@tribalfusion[1].txt
Cookie: Adserver.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted
Infected cookies detected
c:\documents and settings\carol and robert\cookies\carol and robert@z1.adserver[1].txt
Here is the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 8:54:42 AM, on 10/9/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.e xe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServer.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\CounterSpy.exe
C:\hijackthis\June 17 2006\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://msn.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP DVD\Umbrella\DVDTray.exe"
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV0 2.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {2A465934-E5F0-11D2-91B5-00104B9C4765} - C:\Program Files\Copernic 2001 Pro\Copernic.exe
O9 - Extra 'Tools' menuitem: Launch Copernic 2001 - {2A465934-E5F0-11D2-91B5-00104B9C4765} - C:\Program Files\Copernic 2001 Pro\Copernic.exe
O9 - Extra button: Copernic - {2A465936-E5F0-11D2-91B5-00104B9C4765} - C:\Program Files\Copernic 2001 Pro\Copernic.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Translate - {99EFB53C-C965-43CF-9F45-52242D134187} - file://C:\Program Files\Copernic 2001 Pro\Translate.htm
O9 - Extra 'Tools' menuitem: &Translate Using Gist-In-Time - {99EFB53C-C965-43CF-9F45-52242D134187} - file://C:\Program Files\Copernic 2001 Pro\Translate.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -
http://zone.msn.com/binFrameWork/v10...I.cab46479.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) -
http://zone.msn.com/BinFrameWork/v10...y.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -
http://zone.msn.com/binframework/v10...t.cab32846.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://cdn2.zone.msn.com/binFramewor...o.cab34246.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) -
http://zone.msn.com/bingame/zpagames...l.cab42858.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) -
http://zone.msn.com/binframework/v10...y.cab41227.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) -
http://209.226.48.74:81/activex/AMC.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} -
http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (ZPA_Backgammon Object) -
http://zone.msn.com/bingame/zpagames...n.cab40641.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: xartcd5 - C:\WINDOWS\SYSTEM32\xartcd5.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PowerPCB License Server - Unknown owner - C:\padspwr\Security\License_Management\lmgrd.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Thanks again for your help,
Poof