Just ran Hijackthis. Can you help?

I think I have been hijacked. When I logged on Yahoo Mail the link read something like, "red.appclient.yahoo...". I ran Hijackthis and removed two programs. The "red.applic" message no longer appeared but re-appeared later. I got rid of it again with Hijackthis. Just to be on the safe side, can you tell me if you see any dangers in this log? Thanks.

Logfile of HijackThis v1.99.1 Scan saved at 10:07:02, on 05-05-20 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes: C:\\WINDOWS\\SYSTEM\\KERNEL32.DLL C:\\WINDOWS\\SYSTEM\\MSGSRV32.EXE C:\\WINDOWS\\SYSTEM\\MPREXE.EXE C:\\WINDOWS\\SYSTEM\\mmtask.tsk C:\\WINDOWS\\SYSTEM\\MSTASK.EXE C:\\PROGRAM FILES\\MCAFEE.COM\\VSO\\MCVSRTE.EXE C:\\WINDOWS\\EXPLORER.EXE C:\\WINDOWS\\TASKMON.EXE C:\\WINDOWS\\SYSTEM\\SYSTRAY.EXE C:\\PROGRAM FILES\\MCAFEE.COM\\VSO\\MCVSSHLD.EXE C:\\PROGRAM FILES\\MCAFEE.COM\\AGENT\\MCAGENT.EXE C:\\PROGRAM FILES\\MCAFEE.COM\\VSO\\MCVSESCN.EXE C:\\WINDOWS\\SYSTEM\\WMIEXE.EXE C:\\WINDOWS\\SYSTEM\\DDHELP.EXE C:\\PROGRAM FILES\\INTERNET EXPLORER\\IEXPLORE.EXE D:\\MY DOCUMENTS\\HIJACKTHIS.EXE

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =

formatting link
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Window Title = Microsoft Internet Explorer provided by Rogers Yahoo! R1 - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyOverride = 127.0.0.1 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\\WINDOWS\\SYSTEM\\MSDXM.OCX O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655}

- C:\\PROGRAM FILES\\MCAFEE.COM\\VSO\\MCVSSHL.DLL O4 - HKLM\\..\\Run: [TaskMonitor] C:\\WINDOWS\\taskmon.exe O4 - HKLM\\..\\Run: [SystemTray] SysTray.Exe O4 - HKLM\\..\\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\\..\\Run: [MCUpdateExe] C:\\PROGRA~1\\MCAFEE.COM\\AGENT\\MCUPDATE.EXE O4 - HKLM\\..\\Run: [VSOCheckTask] "C:\\PROGRA~1\\MCAFEE.COM\\VSO\\MCMNHDLR.EXE" /checktask O4 - HKLM\\..\\Run: [VirusScan Online] "C:\\PROGRA~1\\MCAFEE.COM\\VSO\\mcvsshld.exe" O4 - HKLM\\..\\Run: [MCAgentExe] C:\\PROGRA~1\\MCAFEE.COM\\AGENT\\mcagent.exe O4 - HKLM\\..\\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\\..\\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\\..\\RunServices: [McVsRte] C:\\PROGRA~1\\MCAFEE.COM\\VSO\\mcvsrte.exe /embedding O4 - Startup: Shortcut to Internet Explorer.lnk = ? O8 - Extra context menu item: Download by Net Transport - C:\\Program Files\\Xi\\NetTransport 2\\NTAddLink.html O8 - Extra context menu item: Download all by Net Transport - C:\\Program Files\\Xi\\NetTransport 2\\NTAddList.html O8 - Extra context menu item: &Yahoo! Search - file:///C:\\Program Files\\Yahoo!\\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\\Program Files\\Yahoo!\\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\\Program Files\\Yahoo!\\Common/ycdict.htm O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -

formatting link
- DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class)

-

formatting link

Reply to
mikesmith9999
Loading thread data ...

Now my Yahoo Mail link reads:

formatting link
Is this a problem? Thanks.

Reply to
mikesmith9999

In article , wrote: :Now my Yahoo Mail link reads:

:

formatting link
:Is this a problem?

I use yahoo from time to time, and I have seen very similar links. Yahoo spreads its load over multiple servers. The IP block registration for us.f514.mail.yahoo.com looks legitimate.

I have not figured out what the rand= portion of the URL is used for by Yahoo; I -usually- only see it when I am using an older browser and Yahoo has dropped back to an older interface version.

Reply to
Walter Roberson

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.