Thanks very much for your help Liam. The pc is up and running again just fine. The ad-aware found just over 100 problems and spybot about 20, and there I was thinking things were fine using McAfee Internet security suite!
Thanks once again for your help. I've done another hjt scan and posted the log.
Cheers, LPS.
Logfile of HijackThis v1.98.2
Scan saved at 11:33:21, on 02/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C: \WINDOWS\System32\smss.exe
C: \WINDOWS\system32\winlogon.exe
C: \WINDOWS\system32\services.exe
C: \WINDOWS\system32\lsass.exe
C: \WINDOWS\system32\svchost.exe
C: \WINDOWS\System32\svchost.exe
C: \WINDOWS\system32\spoolsv.exe
C: \Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C: \Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
c: \PROGRA~1\mcafee.com\vso\mcvsrte.exe
C: \Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C: \PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C: \WINDOWS\System32\svchost.exe
c: \PROGRA~1\mcafee.com\vso\mcshield.exe
C: \PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C: \WINDOWS\Explorer.EXE
C: \Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C: \WINDOWS\Dit.exe
C: \WINDOWS\mHotkey.exe
C: \WINDOWS\System32\RunDll32.exe
C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
C: \Program Files\Logitech\Video\LogiTray.exe
C: \PROGRA~1\mcafee.com\agent\mcagent.exe
C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C: \WINDOWS\DitExp.exe
C: \PROGRA~1\mcafee.com\vso\mcvsshld.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C: \Program Files\iTunes\iTunesHelper.exe
C: \Program Files\QuickTime\qttask.exe
C: \Program Files\Logitech\MouseWare\system\em_exec.exe
C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
C: \Program Files\iPod\bin\iPodService.exe
C: \WINDOWS\System32\ctfmon.exe
c: \progra~1\mcafee.com\vso\mcvsescn.exe
C: \Program Files\Star Alliance Timetable\StarUpdater.exe
C: \WINDOWS\System32\LVComS.exe
C: \Program Files\BTopenworld NetHelp\bin\mpbtn.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C: \Program Files\Logitech\Video\LowLight.exe
C: \PROGRA~1\Yahoo!\browser\ycommon.exe
c: \progra~1\mcafee.com\vso\mcvsftsn.exe
C: \Program Files\Yahoo!\browser\ybrwicon.exe
C: \Program Files\Messenger\msmsgs.exe
C: \PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C: \Program Files\Yahoo!\browser\ybrowser.exe
C: \HJT\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://uk.red.clientapps.yahoo.com/c..._side.html</a> R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.2.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C: \Program Files\Yahoo!\Messenger\ycomp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C: \PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c: \progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c: \program files\google\googletoolbar1.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C: \Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \Program Files\Yahoo!\Messenger\ycomp.dll
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C: \WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCMService] "C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C: \Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C: \Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c: \PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C: \PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c: \PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [VirusScan Online] "c: \PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C: \PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] C: \Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C: \Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C: \WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C: \WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C: \WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C: \Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [EPSON Stylus C66 Series] C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /M "Stylus C66" /EF "HKCU"
O4 - Startup: Registration-InstantCopy.lnk = C: \Program Files\Pinnacle\Shared Files\InstantCDDVD\Pixie\RegTool.exe
O4 - Startup: StarUpdater.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C: \Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C: \Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetHelp.lnk = C: \Program Files\BTopenworld NetHelp\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://C: \Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C: \Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C: \Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C: \Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C: \PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C: \Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C: \Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C: \Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C: \Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: BT Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra 'Tools' menuitem: BT &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C: \Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C: \Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C: \Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.com/download.yaho...tocomplete.cab