Logfile of HijackThis v1.99.0
Scan saved at 16:42:08, on 1/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
E:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
E:\Program Files\McAfee\McAfee Firewall\CPD.EXE
E:\WINDOWS\Explorer.EXE
E:\Program Files\McAfee\McAfee Firewall\CPD.EXE
E:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
E:\Program Files\Java\jre1.5.0\bin\jusched.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
E:\WINDOWS\System32\w?wexec.exe
E:\Documents and Settings\thomas\Application Data\herc.exe
e:\windows\system32\taskmgn.exe
E:\Winamp\winamp.exe
E:\Football Manager 2005\fm2005.exe
E:\DOCUME~1\thomas\LOCALS~1\Temp\~e5.0001
E:\Program Files\Outlook Express\msimn.exe
E:\PROGRA~1\MOZILL~1\firefox.exe
E:\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.beR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.beR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.google.be/R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - E:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: (no name) - {766F4A98-F55B-AFFB-0843-F7CABEA2C99B} - E:\WINDOWS\System32\rtjnkv.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - E:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Games toolbar - {02ffc86e-283e-4faa-95d6-addca024f30a} - E:\Program Files\Games\tbGame.dll
O3 - Toolbar: Searchfst Class - {000277A3-7D84-406a-9799-D12A81594693} - E:\WINDOWS\srchfst.dll
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - E:\Program Files\YourSiteBar\ysb.dll (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [System Toolkit] F:\McAfee Anti virus v7.00.EXE
O4 - HKLM\..\Run: [McAfee Guardian] "E:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Task Manager] e:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [Games toolbar] rundll32.exe "E:\PROGRA~1\Games\tbGame.dll" DllShowTB
O4 - HKLM\..\Run: [SurfSideKick 2] E:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKLM\..\Run: [TV Media] E:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "E:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [SurfSideKick 2] E:\Program Files\SurfSideKick 2\Ssk.exe
O4 - HKCU\..\Run: [Yahoo! Pager] E:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Ruk] E:\WINDOWS\System32\w?wexec.exe
O4 - HKCU\..\Run: [Nsbo] E:\Documents and Settings\thomas\Application Data\herc.exe
O4 - HKCU\..\Run: [TV Media] E:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///E:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///E:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cabO16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!
http://www.free32.com/POP.CHM::/sp.exeO16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cabO16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) -
http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cabO16 - DPF: {970BF476-3CF2-4572-9EF9-4479E1591DB8} (VacPro.belgio_ver3) -
http://ocx1.advnt01.com/dialer/belgio_ver3.CABO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabO23 - Service: AVSync Manager - Network Associates, Inc. - E:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: McAfee Firewall - Network Associates, Inc. - E:\Program Files\McAfee\McAfee Firewall\CPD.EXE
O23 - Service: McShield - Unknown - E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
I already tried fixing it yesterday, hope this still helps.
Tom.