Heres a copy of the log if that helps ....Jim
Logfile of X-RayPc Build 38512 (Installed 1118874992)
Scan saved at 15/06/2005 22:39:41
Registry Settings:
IE Start Page (User) :
http://www.evertonfc.com/IE Start Page (Global) :
http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
IE Blank Page : C:\WINDOWS\system32\blank.htm
IE Default Page :
http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
IE Search Page (User) :
http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
IE Search Page (Global) :
http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
IE Default Search :
http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
IE Search Bar :
http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
HOSTS Directory : %SystemRoot%\System32\drivers\etc
Running processes:
C:\WINDOWS\system32\services.exe (108032 c6ce6eec82f187615d1002bb3bb50ed4)
C:\WINDOWS\system32\lsass.exe (13312 84885f9b82f4d55c6146ebf6065d75d2)
C:\WINDOWS\system32\svchost.exe (14336 8f078ae4ed187aaabc0a305146de6716)
C:\WINDOWS\System32\svchost.exe (14336 8f078ae4ed187aaabc0a305146de6716)
C:\WINDOWS\system32\spoolsv.exe (57856 7435b108b935e42ea92ca94f59c8e717)
C:\WINDOWS\System32\cisvc.exe (5632 3192bd04d032a9c4a85a3278c268a13a)
C:\Program Files\Norton GoBack\GBPoll.exe (512000 a2bb85da575874ca2a14f2db9e85f856)
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (131072 d40357f1ba41905355b599228357495d)
C:\WINDOWS\system32\pctspk.exe (86016 0275215d01c3985e682a661b8826f371)
C:\WINDOWS\System32\svchost.exe (14336 8f078ae4ed187aaabc0a305146de6716)
C:\WINDOWS\System32\Tablet.exe (450560 64f5255e28e86c8f91040f42a15e0511)
C:\WINDOWS\system32\ZONELABS\vsmon.exe (1210112 049eb3c18dd71b96075dd7da48043fdf)
C:\WINDOWS\System32\MsPMSPSv.exe (53248 668056d5c3c11ab7d266819a96b964e8)
c:\PROGRA~1\mcafee.com\vso\mcshield.exe (225401 269dfc7d130ad858f2a4b71319fdcfc5)
C:\Program Files\Common Files\Stardock\SDMCP.exe (241664 a6ea07a7d47c733d22b3f0dd6c393012)
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe (430592 becbb112151e0ed91740d918642ce4fe)
C:\Program Files\Stardock\Object Desktop\Component Tray\sdctray.exe (356352 dd14b4cc6e95c01a9fdc217d59c691a1)
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (935688 bac4e154f30aba45bb99c0bb9196a57e)
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe (196608 944982c9b57c8bcc58f4001a62cd503f)
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe (32881 d7b9be63c406103ee1405fe473ac0697)
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (866816 d40191aa225638ab20e59524cdd74030)
c:\program files\mcafee.com\agent\mcagent.exe (278528 c9a041d6e5211ca48aeba3ac1987d837)
c:\progra~1\mcafee.com\vso\mcvsescn.exe (471097 c9ae1c7570883eed7f6f81b7ac9ecff7)
C:\WINDOWS\system32\atiptaxx.exe (245760 7521596bfe009af58b616b3a4d96015e)
C:\WINDOWS\system32\ctfmon.exe (15360 24232996a38c0b0cf151c2140ae29fc8)
C:\Program Files\Muiltmedia keyboard utility\1.3\KbdAp32A.exe (375296 87fbed060896c6ff2c4e6cafa5437378)
C:\Program Files\Norton GoBack\GBTray.exe (524288 fe65ba6f268b84dfc140936b68d61cb7)
C:\WINDOWS\system32\cidaemon.exe (8192 582304f6f1946fa5068cf143d729d7ed)
C:\Program Files\Mozilla Firefox\firefox.exe (6631017 28bc6acf8851153633c9cd6ccd858c03)
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\WINZIP\winzip32.exe (2781184 01e7bf01e08bea9c03ecd0e71dd3f4d8)
C:\Documents and Settings\J.P. Carney\Local Settings\Temp\x-raypc.exe (334072 77e20d297f99fef15422286e56af8360)
O2 - BHO: (Yahoo! Companion BHO) - {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_6_0_0.dll (327246 374305b47a9de61b271d9bb293c06f51)
O2 - BHO: (AcroIEHlprObj Class) - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (63136 42729c3de75a7a51fc6f9ef6546c9199)
O2 - BHO: (no name) - {206e52e0-d52e-11d4-ad54-0000e86c26f6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll
O2 - BHO: (UberButton Class) - {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (181352 f5e62c5f6dae350140f821278060b8ea)
O2 - BHO: (YahooTaggedBM Class) - {65d886a2-7ca7-479b-bb95-14d1efb7946a} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll (115832 a7dfd7463c4ac34309d2304546d7a96a)
O2 - BHO: (ST) - {9394ede7-c8b5-483e-8773-474bf36af6e4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (155648 0da1349495955cb41a5899047c5a1267)
O2 - BHO: (MSNToolBandBHO) - {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (282624 0deb8b7cad01ee86d1c4062e1b587c5a)
O2 - BHO: (SidebarAutoLaunch Class) - {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (124032 0645dbcbdb3f4a69aee13f4b5f9c4291)
O3 - Toolbar: McAfee VirusScan {ba52b914-b692-46c4-b683-905236f6f655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll (135223 edb43b7360e94d294eed19da0eb3a467)
O3 - Toolbar: Yahoo! Companion {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_6_0_0.dll (327246 374305b47a9de61b271d9bb293c06f51)
O3 - Toolbar: MSN {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (282624 0deb8b7cad01ee86d1c4062e1b587c5a)
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (935688 bac4e154f30aba45bb99c0bb9196a57e)
O4 - HKLM\..\Run: [VSOCheckTask] c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe (143360 d527afe3bed159802f84fee4118b995a)
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe (196608 944982c9b57c8bcc58f4001a62cd503f)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe (32881 d7b9be63c406103ee1405fe473ac0697)
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (866816 d40191aa225638ab20e59524cdd74030)
O4 - HKLM\..\Run: [POINTER]
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe (180224 c7d0c96ad30cfafc37f621c75fad6252)
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe (278528 c9a041d6e5211ca48aeba3ac1987d837)
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.3\MMKEYBD.EXE (207360 2b0b3587e50be8c5d47fc2a2627005f3)
O4 - HKLM\..\Run: [AtiPTA] C:\WINDOWS\system32\atiptaxx.exe (245760 7521596bfe009af58b616b3a4d96015e)
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (15360 24232996a38c0b0cf151c2140ae29fc8)
O4 - HKLM\..\ShellServiceObjectDelayLoad: [0aMCPClient] C:\Program Files\Common Files\Stardock\mcpcore.dll (86016 e0475dbae1d9e5f229acb3e1dc1264c2)
O4 - HKLM\..\ShellServiceObjectDelayLoad: [PostBootReminder] C:\WINDOWS\system32\SHELL32.dll (8450048 9833f278924d028414d7f89bfd4fc46b)
O4 - HKLM\..\ShellServiceObjectDelayLoad: [CDBurn] C:\WINDOWS\system32\SHELL32.dll (8450048 9833f278924d028414d7f89bfd4fc46b)
O4 - HKLM\..\ShellServiceObjectDelayLoad: [WebCheck] C:\WINDOWS\System32\webcheck.dll (276480 6501db5182d5a8c0f1f1707286161d66)
O4 - HKLM\..\ShellServiceObjectDelayLoad: [SysTray] C:\WINDOWS\System32\stobject.dll (121856 297101a925ecffdcdf7f6341ffbb6c1a)
O16 - DPF: (Microsoft XML Parser for Java)- file://C:\WINDOWS\Java\classes\xmldso.cab - C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd (1162 0f7667aa2dfebb40816a75bfa972166d)
O16 - DPF: {166b1bca-3f9c-11cf-8075-444553540000} (Shockwave ActiveX Control)-
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab - C:\WINDOWS\Downloaded Program Files\erma.inf (1271 d5897197b02d5b52547c7f60cd8f7c28)
O16 - DPF: {1803b9ef-9905-4f34-afc4-05d1bab28801} (RegUserCfgUI Class)-
http://us.dl1.yimg.com/download.yahoo.com/dl/controls/yregucfg/2004_10_11_1/yregucfg.cab - C:\Program Files\Yahoo!\Common\yregucfg.dll (144448 dc3f07eaf0e7483885c3f3a9540e39b1)
O16 - DPF: {231b1c6e-f934-42a2-92b6-c2fefec24276} (yucsetreg Class)- C:\Program Files\Yahoo!\common\yucconfig.dll - C:\Program Files\Yahoo!\common\yucconfig.inf (317 2920f72762990fee1aa9df66e4ac77d3)
O16 - DPF: {2a32b14f-4d29-4ea3-ac54-e9b19f436ce7} (Scanner Class)-
http://www.windowsecurity.com/trojanscan/TDECntrl.CAB - C:\WINDOWS\Downloaded Program Files\TDECntrl.INF (814 da56a97e9e268fbc886fb45065f342fb)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class)- C:\Program Files\Yahoo!\common\yinsthelper.dll - C:\Program Files\Yahoo!\common\yinst.inf (1206 0b4916128b3b4d0e9268337ccd100321)
O16 - DPF: {71057c18-0507-4747-86bc-e11ce7512c5f} (mailhelper Class)-
http://register.btinternet.com/templates/btmailcontrol013.cab - C:\WINDOWS\Downloaded Program Files\btmailcontrol.inf (264 4b3118dd55638bca16ab6b5be9f114b4)
O16 - DPF: {8ad9c840-044e-11d1-b3e9-00805f499d93} (Java Plug-in 1.4.2_04)-
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll (65650 2bca54cb6a12a5efbf922c0c1856f30d)
O16 - DPF: {8b1bc605-c593-4865-8f5b-05517f0cd0bb} (MSSecurityAdvisorCD Class)- file://E:\Content\include\msSecUcd.cab - C:\WINDOWS\Downloaded Program Files\msSecucd.inf (677 2b7c2d4f5e21dcd85225cb1ca30a16c2)
O16 - DPF: {a17e30c4-a9ba-11d4-8673-60db54c10000} (YahooYMailTo Class)-
http://download.yahoo.com/dl/installs/ymail/ymmapi.dll - C:\Program Files\Yahoo!\Common\ymmapi.inf (905 13bf2f23877272e548285921a3268c47)
O16 - DPF: {b9191f79-5613-4c76-aa2a-398534bb8999} (YAddBook Class)-
http://download.yahoo.com/dl/installs/yab_af.cab - C:\PROGRA~1\YAHOO!\COMMON\yab_af.inf (793 673da1ceab630a51e8686169dbb56d09)
O16 - DPF: {bcc0ff27-31d9-4614-a68e-c18e1ada4389} (DwnldGroupMgr Class)-
http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cab - C:\WINDOWS\Downloaded Program Files\McGDMgr.inf (691 855e290960c11c16eb4603f2b4c7e3ab)
O16 - DPF: {c606ba60-ab76-48b6-96a7-2c4d5c386f70} (PreQualifier Class)-
http://downloads.broadbandassist.com/BTYahoo!Help//PreQual/files/MotivePreQual.cab - C:\WINDOWS\Downloaded Program Files\MotivePreQual.inf (911 724be015bf846f83c6eb1cc07098173a)
O16 - DPF: {cafeefac-0014-0002-0004-abcdeffedcba} (Java Plug-in 1.4.2_04)-
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll (65650 2bca54cb6a12a5efbf922c0c1856f30d)
O16 - DPF: {d27cdb6e-ae6d-11cf-96b8-444553540000} (Shockwave Flash Object)-
http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab - C:\WINDOWS\Downloaded Program Files\swflash.inf (3759 60b7c507c4804edf26cc2a3066899c29)
O16 - DPF: {ec5a4e7b-02eb-451d-b310-d5f2e0a4d8c3} (webhelper Class)-
http://register.btinternet.com/templates/btwebcontrol023.cab - C:\WINDOWS\Downloaded Program Files\btwebcontrol.inf (261 da27d6f51831bfe65e48fd4b48632d61)