<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>hijack this log...Winfixer, cws.qttask, Vx2.Look2m in Security</title>
<link>http://www.dslreports.com/forum/r14391810</link>
<description></description>
<language>en</language>
<pubDate>Tue, 24 Nov 2009 09:01:31 EDT</pubDate>
<lastBuildDate>Tue, 24 Nov 2009 09:01:31 EDT</lastBuildDate>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14610723</link>
<description><![CDATA[<A HREF="/useremail/u/252964"><b>MrFixitSC</b></A> : thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14610723</guid>
<pubDate>Wed, 19 Oct 2005 09:22:36 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14610466</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : MrFixitCT, you really should start your own new topic instead piggybacking on this one.  But it is known that a Vundo infection interferes sometimes with getting the PC into safe mode and the author of the Vundofix tool has verfied that the tool should work in Normal Mode as well.  So try that.  But if you need help on the specific files ...please post a new topic and we'll glad to assist.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14610466</guid>
<pubDate>Wed, 19 Oct 2005 08:24:16 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14607459</link>
<description><![CDATA[<A HREF="/useremail/u/252964"><b>MrFixitSC</b></A> : I have a vundo related (possibly) when I try to boot in safe mode all I get is a black screen with "safemode" in the four corners so I cant proceed with the fix..??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14607459</guid>
<pubDate>Tue, 18 Oct 2005 19:59:56 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14398390</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : You're welcome eay, glad we could help!  Hope you have a great week, too :)<br><br>@Rusty Dusty:  Atribune just notified me that it was the f-lock key on his keyboard not being on so the F buttons didnt work.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14398390</guid>
<pubDate>Mon, 19 Sep 2005 16:36:06 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14398186</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Greetings Calamity Jane,<br><br>Thanks for the information.  I'm already using Clean up.  Great program and so easy to use.<br><br>I downloaded the MS Security stuff...... it's not able to locate my computer.  I guess I'm invisible these days. >  <br><br>The desktop is running smoothly but slow.  It's slow because of all the anti-spyware, anti-trojan, and anti-virus programs running in the background.  Yep, Color me paranoid.<br><br>Thanks again for all of your help.  I hope you have a great week.   ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14398186</guid>
<pubDate>Mon, 19 Sep 2005 16:10:40 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14397426</link>
<description><![CDATA[<A HREF="/useremail/u/726016"><b>Rusty Dusty</b></A> : <div class="bquote"><SMALL>said by  Atribune <A HREF="/useremail/u/1112532"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I sent you a messge hopefully you recieve it<br> </DIV>Well, this isn't so good.....!<br><br>It is great that "eay" problem(s) have been solved, but the resorting to an off-line fix session in the middle of a problem solving process that I was following leaves me wondering what the fix was so that I can learn and help myself or someone else in the future....<br><br>So what was the 'fix', please?<br><br>Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14397426</guid>
<pubDate>Mon, 19 Sep 2005 14:26:13 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14395374</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : looks like you got it to work  :)  Many thanks to Atribune for his efforts and help!!<br><br>The file that Panda found is in your cache (TIF) folder.  Go here and delete all the files in there:  C:\Documents and Settings\default\Local Settings\Temporary Internet Files.  <br><br>You can also run this little program to do that for you:<br>Download and install CleanUp!<br>&raquo;<A HREF="http://www.stevengould.org/downloads/cleanup/CleanUp40.exe" >www.stevengould.org/downloads/cl&middot;&middot;&middot;Up40.exe</A><br><br>Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).<br>Set the program up as follows:<br>Click "Options..."<br>Move the arrow down to "Custom CleanUp!"<br>Put a check next to the following (Make sure nothing else is checked!):<br><br>    * Empty Recycle Bins<br>    * Delete Cookies<br>    * Delete Prefetch files<br>    * Cleanup! All Users<br><br>Click OK<br>Press the CleanUp! button to start the program.<br><br>You can go ahead and delete the Vundofix folder now that we're done with that, should it be needed again, it's best to download a fresh copy as frequently changes are made to handle newer variants.<br><br>The HijackThis log looks good now :)<br>I think we can move forward to final cleanup and prevention steps now.<br><br>Now that your PC is clean, make sure all programs are running properly and then you'll need to reset your restore point in Windows XP.......why?<br><br>One of the best features of Windows ME or XP is the System Restore option, however if a malware infects a computer with this operating system it can be backed up in the System Restore folder.  Therefore, clearing the restore points is necessary after malware removal.<br><br>To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account. <br><br>(winXP)<br><br>1.  Turn off System Restore.<br>Go to Start > Run, click on *My Computer*.<br>Click Properties.<br>Click the System Restore tab.<br>Check Turn off System Restore.<br>Click Apply, and then click OK.<br><br>2.  Reboot.<br><br>3.  Turn ON System Restore.<br>Go to Start > Run, click on *My Computer*.<br>Click Properties.<br>Click the System Restore tab.<br>UN-Check *Turn off System Restore*.<br>Click Apply, and then click OK.<br><br>How to Turn On and Turn Off System Restore in Windows XP<br>&raquo;<A HREF="http://support.microsoft.com/default.aspx?scid=kb;en-us;310405" >support.microsoft.com/default.as&middot;&middot;&middot;s;310405</A><br><br>Next, I highly recommend you get some extra protection to prevent future infections.  Here are some things you can do and some free programs to help :).<br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/10002">How do I prevent browser hijacks and spyware?</A><br><br>I'm happy to see you have SP2 installed.  That will address numerous security issues in your Operating System and IE <br>Make sure that you keep your Operating System and IE updated with the latest Critical Security Updates from Microsoft...they usually come out once a month, on the 2nd Tuesday of each month.  This is the first step in malware prevention, as many nasties now take advantage of new exploits and if not patched, you are vulnerable!<br>Windows Update<br>&raquo;<A HREF="http://v4.windowsupdate.microsoft.com/en/default.asp" >v4.windowsupdate.microsoft.com/e&middot;&middot;&middot;ault.asp</A><br><br>And see this link for instructions on how to configure the enhanced security features in SP2:<br>&raquo;<A HREF="http://www.microsoft.com/technet/security/smallbusiness/prodtech/windowsxp/iesecxp.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;cxp.mspx</A><br><br>I also highly recommend to get the free tool, Microsoft Baseline Security Analyzer (MBSA) from Microsoft to analyze your PC security for prevention purposes. <br><br>MBSA Version 2.0  will scan for common system misconfigurations on Windows 2000, Windows XP, and Windows Server 2003 systems.  This program will identify the system security weaknesses in your browser and operating system and provides easy instructions to correct them.  This includes any missing critical Windows security updates, system vulnerabilities and your IE Browser security settings.  Get the download here:<br>Microsoft Baseline Security Analyzer <br>&raquo;<A HREF="http://www.microsoft.com/technet/security/tools/mbsahome.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;ome.mspx</A><br>Choose MBSAsetup-EN.msi = (English Version) or the language appropriate for you.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2005<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14395374</guid>
<pubDate>Mon, 19 Sep 2005 08:39:52 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14394004</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Atribune  and Calamity Jane,<br><br>Thank you.  You turned my bad experience into a wonderful one.  You've been very kind and I truly appreciate all of your help.<br><br>Here's the Panda and HJt logs.<br>-----------------------------------------------------------<br>ACTIVE SCAN:<br><br>Incident                      Status                        Location                                                                                                                                                                                                                                                        <br><br>Adware:adware/savenow      No  disinfected                <br>Windows registry                                                                                                                                                                                                                                               <br>Adware:Adware/CWS           <br>No disinfected                <br>C:\Documents and Settings\default\Local Settings\Temporary Internet Files\Content.IE5\8HMN81QF\menus[1].js                                                                                                                ------------------------------------------------------------                                      <br>HJT:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 10:37:40 PM, on 9/18/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Sygate\SPF\smc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe<br>C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\Program Files\ewido\security suite\ewidoctrl.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe<br>C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe<br>C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe<br>C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\system32\wdfmgr.exe<br>C:\WINDOWS\system32\wbem\wmiprvse.exe<br>C:\WINDOWS\System32\alg.exe<br>C:\Documents and Settings\default\Desktop\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumericon&c=2C01&lc=0409" >desktop.presario.net/scripts/red&middot;&middot;&middot;&lc=0409</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Insight Broadband<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe<br>O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe<br>O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray<br>O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"<br>O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html<br>O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html<br>O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\default\My Documents\filelib\aim.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: Yahoo! Euchre - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/et1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pote_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;te_x.cab</A><br>O16 - DPF: Yahoo! Pyramids - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pyt1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" >messenger.zone.msn.com/binary/ms&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - &raquo;<A HREF="http://housecall60.trendmicro.com/housecall/xscan60.cab" >housecall60.trendmicro.com/house&middot;&middot;&middot;an60.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Upwords.cab31267.cab" >messenger.zone.msn.com/binary/Up&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - &raquo;<A HREF="http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab" >h20270.www2.hp.com/ediags/gmn/in&middot;&middot;&middot;_gmn.cab</A><br>O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab" >messenger.zone.msn.com/binary/Mi&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://jcs.chat.dcn.yahoo.com/v45/yacscom.cab" >jcs.chat.dcn.yahoo.com/v45/yacscom.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe" >appldnld.m7z.net/qtinstall.info.&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://spaces.msn.com//PhotoUpload/MsnPUpld.cab" >spaces.msn.com//PhotoUpload/MsnPUpld.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1115410355375" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;10355375</A><br>O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/en/filesharingctrl.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;ctrl.cab</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;kMSN.cab</A><br>O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - &raquo;<A HREF="http://www.pcpitstop.com/mhLbl.cab" >www.pcpitstop.com/mhLbl.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZAxRcMgr.cab" >messenger.zone.msn.com/binary/ZAxRcMgr.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" >messenger.zone.msn.com/binary/ZI&middot;&middot;&middot;2846.cab</A><br>O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab" >messenger.zone.msn.com/binary/Ba&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {C852B12E-3F08-4099-AF8E-32FD327B88EA} (msnloader Class) - &raquo;<A HREF="http://rockstar.messenger.msn.com/rockstar.cab" >rockstar.messenger.msn.com/rockstar.cab</A><br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\default\Local Settings\Temporary Internet Files\Content.IE5\82VVYU4H\CWShredder[1].exe (file missing)<br>O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14394004</guid>
<pubDate>Sun, 18 Sep 2005 23:48:45 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14393446</link>
<description><![CDATA[<A HREF="/useremail/u/1112532"><b>Atribune</b></A> : Resent]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393446</guid>
<pubDate>Sun, 18 Sep 2005 22:05:33 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14393323</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Hmm....Would it be possible to re-send the message?  I forgot to update my profile when I changed ISP's.  My fault.<br><br>Thank you for your help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393323</guid>
<pubDate>Sun, 18 Sep 2005 21:44:34 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14393261</link>
<description><![CDATA[<A HREF="/useremail/u/1112532"><b>Atribune</b></A> : I sent you a messge hopefully you recieve it]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393261</guid>
<pubDate>Sun, 18 Sep 2005 21:34:14 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14393161</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Logfile of HijackThis v1.99.1<br>Scan saved at 8:18:18 PM, on 9/18/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\NOTEPAD.EXE<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Documents and Settings\default\Desktop\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumericon&c=2C01&lc=0409" >desktop.presario.net/scripts/red&middot;&middot;&middot;&lc=0409</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Insight Broadband<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\yabab.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe<br>O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe<br>O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray<br>O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"<br>O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html<br>O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html<br>O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\default\My Documents\filelib\aim.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: Yahoo! Euchre - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/et1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pote_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;te_x.cab</A><br>O16 - DPF: Yahoo! Pyramids - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pyt1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" >messenger.zone.msn.com/binary/ms&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - &raquo;<A HREF="http://housecall60.trendmicro.com/housecall/xscan60.cab" >housecall60.trendmicro.com/house&middot;&middot;&middot;an60.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Upwords.cab31267.cab" >messenger.zone.msn.com/binary/Up&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - &raquo;<A HREF="http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab" >h20270.www2.hp.com/ediags/gmn/in&middot;&middot;&middot;_gmn.cab</A><br>O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab" >messenger.zone.msn.com/binary/Mi&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://jcs.chat.dcn.yahoo.com/v45/yacscom.cab" >jcs.chat.dcn.yahoo.com/v45/yacscom.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe" >appldnld.m7z.net/qtinstall.info.&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://spaces.msn.com//PhotoUpload/MsnPUpld.cab" >spaces.msn.com//PhotoUpload/MsnPUpld.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1115410355375" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;10355375</A><br>O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/en/filesharingctrl.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;ctrl.cab</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;kMSN.cab</A><br>O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - &raquo;<A HREF="http://www.pcpitstop.com/mhLbl.cab" >www.pcpitstop.com/mhLbl.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZAxRcMgr.cab" >messenger.zone.msn.com/binary/ZAxRcMgr.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" >messenger.zone.msn.com/binary/ZI&middot;&middot;&middot;2846.cab</A><br>O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab" >messenger.zone.msn.com/binary/Ba&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {C852B12E-3F08-4099-AF8E-32FD327B88EA} (msnloader Class) - &raquo;<A HREF="http://rockstar.messenger.msn.com/rockstar.cab" >rockstar.messenger.msn.com/rockstar.cab</A><br>O20 - Winlogon Notify: yabab - C:\WINDOWS\system32\yabab.dll<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\default\Local Settings\Temporary Internet Files\Content.IE5\82VVYU4H\CWShredder[1].exe (file missing)<br>O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393161</guid>
<pubDate>Sun, 18 Sep 2005 21:19:21 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14393120</link>
<description><![CDATA[<A HREF="/useremail/u/1112532"><b>Atribune</b></A> : Can you post a new hijackthis log]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393120</guid>
<pubDate>Sun, 18 Sep 2005 21:14:16 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14393103</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : enter,  ctrl+z, enter......didn't work:(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393103</guid>
<pubDate>Sun, 18 Sep 2005 21:11:27 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14393092</link>
<description><![CDATA[<A HREF="/useremail/u/1112532"><b>Atribune</b></A> : You're welcome, but i wouldn't call it help yet.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393092</guid>
<pubDate>Sun, 18 Sep 2005 21:09:37 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14393072</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Will do.  Thanks for your help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393072</guid>
<pubDate>Sun, 18 Sep 2005 21:06:41 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14393064</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> :  Not a problem.  I was just thinking out loud:D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393064</guid>
<pubDate>Sun, 18 Sep 2005 21:05:38 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14393055</link>
<description><![CDATA[<A HREF="/useremail/u/1112532"><b>Atribune</b></A> : Can you try Calamity Janes instructions again but this time instead of enter f6 enter use enter ctrl+z enter and let me know how that goes.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393055</guid>
<pubDate>Sun, 18 Sep 2005 21:04:22 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14393042</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Hold on.  Atribune is looking at this thread.  He should post soon :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393042</guid>
<pubDate>Sun, 18 Sep 2005 21:03:09 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14393016</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : What would happen if I just renamed the file?  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14393016</guid>
<pubDate>Sun, 18 Sep 2005 20:59:26 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392933</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Oops. I forgot The other files are ......<br><br>Readme.txt<br>Vundo Registration Entries<br>srthjt]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392933</guid>
<pubDate>Sun, 18 Sep 2005 20:47:52 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392908</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : It has ..........<br><br>process<br>command line utitlity<br>www.beyondlogic.org<br><br>I have reinstalled this fix twice thinking that perhaps it was missing something. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392908</guid>
<pubDate>Sun, 18 Sep 2005 20:43:45 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392863</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ah, big cavalry.  The author of the program, suggests this:<br><br>Can you ask your user to open the vundofix folder and post a list of files that are in it.<br><br>If you dont see process.exe have him redownload the vundofix.exe.<br><br>&raquo;<A HREF="http://www.atribune.org/downloads/VundoFix.exe" >www.atribune.org/downloads/VundoFix.exe</A><br><br><B><SMALL>Note to Mods:  While the forum rules state not to use a link to an .exe file in a post to protect users from accidentally clicking on a malware file.  This fix uses a self-extracting archive in an .exe that is a fix tool only and is NOT malware.  No other mirrored download links are allowed by the author of the tool, therefore, you will see the link to Vundofix.exe in my post here is an exception to this forum rule.  Using that link for the tool ensures that the OP has the most current version of the tool maintained on the author's authorized website</B></SMALL><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2005<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392863</guid>
<pubDate>Sun, 18 Sep 2005 20:35:21 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392814</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : LOL...you're very quick!  Lemme call more cavalry ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392814</guid>
<pubDate>Sun, 18 Sep 2005 20:29:03 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392808</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok - we'll scratch MSAS didn't work?<br><br>Did you try typing in the file name?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392808</guid>
<pubDate>Sun, 18 Sep 2005 20:28:17 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392778</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : ""Try typing it in (be very careful)""<br><br>I did that too]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392778</guid>
<pubDate>Sun, 18 Sep 2005 20:23:54 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392768</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : I did that earlier today. I updated the definitions and ran the scan. The scan came out clean.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392768</guid>
<pubDate>Sun, 18 Sep 2005 20:22:21 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392766</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Try typing it in (be very careful)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392766</guid>
<pubDate>Sun, 18 Sep 2005 20:21:46 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392752</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Nope.....it still hangs on the first file path :huh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392752</guid>
<pubDate>Sun, 18 Sep 2005 20:19:53 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392740</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok, another suggestion from LoPhat...he reports seeing where someone had success using Microsoft Antispyware with the latest defs (#5757)<br><br>The download is here:<br>&raquo;<A HREF="http://www.microsoft.com/athome/security/spyware/software/default.mspx" >www.microsoft.com/athome/securit&middot;&middot;&middot;ult.mspx</A> <br><br>Be sure you update it first before scanning.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2005<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392740</guid>
<pubDate>Sun, 18 Sep 2005 20:17:35 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392699</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Let's see, one member of the calvary ( LoPhatPhuud <A HREF="/useremail/u/555588"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> - thank you Lo!) has spotted an error in the second file name....lemme revise instructions.  But I think the first file is where it is hanging??<br><br>Please follow these instructions:<br><br>1.  Make a copy of these instructions so you have them handy as the most steps need to be done in safe mode with IE closed.<br><br>2.  Please download the VundoFix tool<br>www.atribune.org/downloads/VundoFix.exe<br><br>3.  Double-click VundoFix.exe to extract the files<br><br>4.  This will create a folder named VundoFix on your desktop.<br><br>5.  After the files are extracted, please reboot your computer into <B>Safe Mode</B>.  <br>How to start the computer in Safe mode<br>&raquo;<A HREF="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam" >service1.symantec.com/SUPPORT/ts&middot;&middot;&middot;_doc_nam</A><br><br>6.  Once in safe mode open the VundoFix folder and doubleclick on <B>KillVundo.bat</B><br><br>You will first be presented with a message and a list of forums to seek help at (but you're already getting help now at this forum)<br><br>At this point press enter one time.<br><br>7.   Next you will see:<br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Type in the filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix<HR></BLOCKQUOTE><br><br>At this point please copy and paste the following file path (make sure to enter it exactly as below!):<br><br><B>C:\WINDOWS\system32\yabab.dll</B><br><br>Press *Enter*, then press the *F6* key, then press *Enter* one more time to continue with the fix.<br><br>8.  Next you will see:<br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Please type in the second filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.<HR></BLOCKQUOTE><br><br>At this point please copy and paste the following file path (make sure to enter it exactly as below!):<br><br><B> C:\WINDOWS\system32\babay.*</B><br><br>Press *Enter*, then press the *F6* key, then press *Enter* one more time to continue with the fix.<br><br>9.  The fix will run then HijackThis will open.<br><br>Using HijackThis, please place a check next to the following items and click the *FIX CHECKED* button:<br><br><B>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\yabab.dll<br><br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br><br>O20 - Winlogon Notify: yabab - C:\WINDOWS\system32\yabab.dll</B><br><br>10.  After you have fixed these items, close HijackThis and Press any key to force a reboot of your computer.<br><br>Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!<br><br>Once your machine reboots please continue with the instructions below.<br><br>11.  Then, please run this online virus scan to clean up any leftovers:  <br>&raquo;<A HREF="http://www.pandasoftware.com/products/activescan.htm" >www.pandasoftware.com/products/a&middot;&middot;&middot;scan.htm</A><br><br>Save the results of the Panda ActiveScan so you can post them for review back here.<br><br>12. Also please post  a new HijackThis log and the vundofix.txt file from the vundofix folder into this topic.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2005<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392699</guid>
<pubDate>Sun, 18 Sep 2005 20:12:04 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392677</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : ;)I started doing that about 20 minutes ago.  Still just sits there after I entered the file path and*enter,F6,Enter*.......Crazy.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392677</guid>
<pubDate>Sun, 18 Sep 2005 20:08:01 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392636</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : While waiting for the calvary to arrive, could you reboot into safe mode and give the tool a while longer to work? (More than several minutes).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392636</guid>
<pubDate>Sun, 18 Sep 2005 20:00:14 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392602</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Thanks for all of your help. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392602</guid>
<pubDate>Sun, 18 Sep 2005 19:53:10 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392562</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok, well, the file is definitely there.  I've called in some others to take a look and add suggestions.  This is the first time I've been stumped with it acting this way - in the many I've done.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392562</guid>
<pubDate>Sun, 18 Sep 2005 19:46:15 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392529</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : To answer your question on the Vundi Fix.......Each time I ran it I waited several minutes.  Nothing ever showed after the file path entry.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392529</guid>
<pubDate>Sun, 18 Sep 2005 19:39:02 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392515</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : <br>Here's the scoop from file finder............<br><br>Number of files found:1 Files found in 182 Directories<br>Size of files found under C:\WINDOWS\system32\ = 528,404 Bytes<br><br>Export.txt:<br><br>C:\WINDOWS\system32\yabab.dll - 528404 Bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392515</guid>
<pubDate>Sun, 18 Sep 2005 19:37:00 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392451</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok, I may need to call some Vundo experts in here.  I should see {file missing}on HJT if it had been deleted.  How much time are you giving it to search for the file?  Or does the program just close?<br><br>2.  download this tool called Filefind:<br>&raquo;<A HREF="http://www.atribune.org/downloads/FileFind.zip" >www.atribune.org/downloads/FileFind.zip</A><br><br>Unzip it and doubleclick on Filefind.exe to run it<br><br>Copy and paste into the *Directory* searchbox the following line:<br><B>C:\WINDOWS\system32</B><br><br>Then copy and paste into the *file* find search box:<br><B>yabab.dll</B><br><br>Then press the *find* button. Wait for it to scan. Copy and paste the results found back here please.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2005<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392451</guid>
<pubDate>Sun, 18 Sep 2005 19:26:46 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392395</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Logfile of HijackThis v1.99.1<br>Scan saved at 6:15:16 PM, on 9/18/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\csrss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Sygate\SPF\smc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br>C:\Program Files\ewido\security suite\ewidoctrl.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe<br>C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe<br>C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe<br>C:\WINDOWS\system32\wdfmgr.exe<br>C:\WINDOWS\System32\alg.exe<br>C:\WINDOWS\system32\wbem\wmiprvse.exe<br>C:\WINDOWS\system32\NOTEPAD.EXE<br>C:\Documents and Settings\default\Desktop\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumericon&c=2C01&lc=0409" >desktop.presario.net/scripts/red&middot;&middot;&middot;&lc=0409</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Insight Broadband<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\yabab.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe<br>O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe<br>O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray<br>O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui<br>O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"<br>O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html<br>O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html<br>O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\default\My Documents\filelib\aim.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: Yahoo! Euchre - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/et1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pote_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;te_x.cab</A><br>O16 - DPF: Yahoo! Pyramids - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pyt1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" >messenger.zone.msn.com/binary/ms&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - &raquo;<A HREF="http://housecall60.trendmicro.com/housecall/xscan60.cab" >housecall60.trendmicro.com/house&middot;&middot;&middot;an60.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Upwords.cab31267.cab" >messenger.zone.msn.com/binary/Up&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - &raquo;<A HREF="http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab" >h20270.www2.hp.com/ediags/gmn/in&middot;&middot;&middot;_gmn.cab</A><br>O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab" >messenger.zone.msn.com/binary/Mi&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://jcs.chat.dcn.yahoo.com/v45/yacscom.cab" >jcs.chat.dcn.yahoo.com/v45/yacscom.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe" >appldnld.m7z.net/qtinstall.info.&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://spaces.msn.com//PhotoUpload/MsnPUpld.cab" >spaces.msn.com//PhotoUpload/MsnPUpld.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1115410355375" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;10355375</A><br>O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/en/filesharingctrl.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;ctrl.cab</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;kMSN.cab</A><br>O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - &raquo;<A HREF="http://www.pcpitstop.com/mhLbl.cab" >www.pcpitstop.com/mhLbl.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZAxRcMgr.cab" >messenger.zone.msn.com/binary/ZAxRcMgr.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" >messenger.zone.msn.com/binary/ZI&middot;&middot;&middot;2846.cab</A><br>O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab" >messenger.zone.msn.com/binary/Ba&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {C852B12E-3F08-4099-AF8E-32FD327B88EA} (msnloader Class) - &raquo;<A HREF="http://rockstar.messenger.msn.com/rockstar.cab" >rockstar.messenger.msn.com/rockstar.cab</A><br>O20 - Winlogon Notify: yabab - C:\WINDOWS\system32\yabab.dll<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\default\Local Settings\Temporary Internet Files\Content.IE5\82VVYU4H\CWShredder[1].exe (file missing)<br>O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392395</guid>
<pubDate>Sun, 18 Sep 2005 19:16:58 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392385</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : all righty then.......that didn't work either ;-(<br>I "cut and paste" the file paths.  That didn't work.  Then I typed the file paths and that didn't work.<br><br>Sorry.  I'm clueless on why this isn't working. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392385</guid>
<pubDate>Sun, 18 Sep 2005 19:13:51 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392359</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : The program is set to exit if the file is not found.  So if it still does that as well in normal mode, scan with HijackThis and post a fresh HJT log please.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392359</guid>
<pubDate>Sun, 18 Sep 2005 19:09:46 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14392353</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : OK, I'll try that and post the results.<br><br>Thanks for your help on this.  I appreciate truly it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392353</guid>
<pubDate>Sun, 18 Sep 2005 19:08:32 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392319</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Hmmm, you're using this filename and path, right?:<br><br>C:\WINDOWS\system32\yabab.dll<br><br>Maybe try rebooting back into normal mode.  Then try running the tool.  I saw once instance where it wasn't working right in safe mode.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2005<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392319</guid>
<pubDate>Sun, 18 Sep 2005 19:01:20 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392297</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : It doesn't say anything........just the file path and then nothing.  My version of XP is an upgrade from WinME.  Would that make a difference?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392297</guid>
<pubDate>Sun, 18 Sep 2005 18:55:27 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392211</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Does Vundo fix say file not found?  If so, something else may have already taken care of it and we can do some fixing of entries in HijackThis.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392211</guid>
<pubDate>Sun, 18 Sep 2005 18:37:45 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14392120</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : Thank you Calamity Jane.<br><br>I did as you suggested but the Vundi Fix will not work.<br><br>After I *cut and paste* the file path and do the "*enter,F6,enter*" it does not proceed to the next step.<br>I do not see the ""Please type in the second filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.""<br><br>I am in safe mode.  I'm XP SP2.<br><br>Any suggestions?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14392120</guid>
<pubDate>Sun, 18 Sep 2005 18:19:20 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14391968</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : On this item noted by Trojan Hunter:<br>C:\WINDOWS\SYSTEM32\strings.exe (Suspicious: UPX-packed file in Windows System folder)<br><br>You can get a second (well actually 14) opinion here:<br>Jotti Malware Scan <br>&raquo;<A HREF="http://virusscan.jotti.org/" >virusscan.jotti.org/</A><br><br>Let Jotti scan the file (just browse to it and submit) and wait while it finishes scanning.  Copy the report when it's done and post the results back here :)<br><br>If Jotti's Malware scan is busy, you can also use this one<br><br>Virus Total<br>&raquo;<A HREF="http://www.virustotal.com/" >www.virustotal.com/</A><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2005<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14391968</guid>
<pubDate>Sun, 18 Sep 2005 17:50:40 EDT</pubDate>
</item>

<item>
<title>Re: hijack this log...Winfixer, cws.qttask, Vx2.Lo</title>
<link>http://www.dslreports.com/forum/remark,14391935</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : It's Vundo<br><br>Please follow these instructions:<br><br>1.  Make a copy of these instructions so you have them handy as the most steps need to be done in safe mode with IE closed.<br><br>2.  Please download the VundoFix tool<br>www.atribune.org/downloads/VundoFix.exe<br><br>3.  Double-click VundoFix.exe to extract the files<br><br>4.  This will create a folder named VundoFix on your desktop.<br><br>5.  After the files are extracted, please reboot your computer into <B>Safe Mode</B>.  <br>How to start the computer in Safe mode<br>&raquo;<A HREF="http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam" >service1.symantec.com/SUPPORT/ts&middot;&middot;&middot;_doc_nam</A><br><br>6.  Once in safe mode open the VundoFix folder and doubleclick on <B>KillVundo.bat</B><br><br>You will first be presented with a message and a list of forums to seek help at (but you're already getting help now at this forum)<br><br>At this point press enter one time.<br><br>7.   Next you will see:<br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Type in the filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix<HR></BLOCKQUOTE><br><br>At this point please copy and paste the following file path (make sure to enter it exactly as below!):<br><br><B>C:\WINDOWS\system32\yabab.dll</B><br><br>Press *Enter*, then press the *F6* key, then press *Enter* one more time to continue with the fix.<br><br>8.  Next you will see:<br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Please type in the second filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.<HR></BLOCKQUOTE><br><br>At this point please copy and paste the following file path (make sure to enter it exactly as below!):<br><br><B> C:\WINDOWS\system32\babay</B><br><br>Press *Enter*, then press the *F6* key, then press *Enter* one more time to continue with the fix.<br><br>9.  The fix will run then HijackThis will open.<br><br>Using HijackThis, please place a check next to the following items and click the *FIX CHECKED* button:<br><br><B>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\yabab.dll<br><br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br><br>O20 - Winlogon Notify: yabab - C:\WINDOWS\system32\yabab.dll</B><br><br>10.  After you have fixed these items, close HijackThis and Press any key to force a reboot of your computer.<br><br>Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!<br><br>Once your machine reboots please continue with the instructions below.<br><br>11.  Then, please run this online virus scan to clean up any leftovers:  <br>&raquo;<A HREF="http://www.pandasoftware.com/products/activescan.htm" >www.pandasoftware.com/products/a&middot;&middot;&middot;scan.htm</A><br><br>Save the results of the Panda ActiveScan so you can post them for review back here.<br><br>12. Also please post  a new HijackThis log and the vundofix.txt file from the vundofix folder into this topic.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><br>Microsoft MVP/Windows Security 2003-2005<br><br><BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14391935</guid>
<pubDate>Sun, 18 Sep 2005 17:45:58 EDT</pubDate>
</item>

<item>
<title>hijack this log...Winfixer, cws.qttask, Vx2.Look2m</title>
<link>http://www.dslreports.com/forum/remark,14391810</link>
<description><![CDATA[<A HREF="/useremail/u/443740"><b>eay9</b></A> : My browser was hijacked with Winfixer popups.  In the process of trying to remove that I found and hopefully, removed others.  <br><br>I ran every program I know of: CWShredder, AdAware, Spybot, Spware Sweeper, Counter Spy, Trojan Hunter, Trend micro, Ewido and any other program I could locate ;-)<br><br>CWshredder found:  VX2. Look2me<br>Counterspy Found: cws.qttask<br>Spybot: Winfixer<br>AdAware or maybe trend found and removed Vundi<br><br>Trojan Huner found a possible Trojan.  Here's the log:<br>###########################################################<br>Registry scan<br>No suspicious entries found<br>Inifile scan<br>No suspicious entries found<br>Port scan<br>No suspicious open ports found<br>Memory scan<br>No trojans found in memory<br>File scan<br>Found possible trojan file: C:\WINDOWS\SYSTEM32\strings.exe (Suspicious: UPX-packed file in Windows System folder)<br>1 possible trojan files found<br>#############################################################<br><br>My system is running better but I'm still getting an occasional pop up.  I would appreciate any help you can provide.  Thanks!<br>############################################################<br>Here's my hijack this log:<br>Logfile of HijackThis v1.99.1<br>Scan saved at 3:45:47 PM, on 9/18/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Documents and Settings\default\Desktop\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumericon&c=2C01&lc=0409" >desktop.presario.net/scripts/red&middot;&middot;&middot;&lc=0409</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.yahoo.com" >www.yahoo.com</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Insight Broadband<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\yabab.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)<br>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll<br>O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll<br>O4 - HKLM\..\Run: [SystemTray] SysTray.Exe<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe<br>O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe<br>O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe<br>O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray<br>O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 4.2\THGuard.exe<br>O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html<br>O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html<br>O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html<br>O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html<br>O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html<br>O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\default\My Documents\filelib\aim.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: Yahoo! Euchre - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/et1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: Yahoo! Pool 2 - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pote_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;te_x.cab</A><br>O16 - DPF: Yahoo! Pyramids - &raquo;<A HREF="http://download.games.yahoo.com/games/clients/y/pyt1_x.cab" >download.games.yahoo.com/games/c&middot;&middot;&middot;t1_x.cab</A><br>O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab" >messenger.zone.msn.com/binary/ms&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - &raquo;<A HREF="http://housecall60.trendmicro.com/housecall/xscan60.cab" >housecall60.trendmicro.com/house&middot;&middot;&middot;an60.cab</A><br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB" >www.pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Upwords.cab31267.cab" >messenger.zone.msn.com/binary/Up&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - &raquo;<A HREF="http://download.ewido.net/ewidoOnlineScan.cab" >download.ewido.net/ewidoOnlineScan.cab</A><br>O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - &raquo;<A HREF="http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab" >h20270.www2.hp.com/ediags/gmn/in&middot;&middot;&middot;_gmn.cab</A><br>O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab" >messenger.zone.msn.com/binary/Mi&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - &raquo;<A HREF="http://jcs.chat.dcn.yahoo.com/v45/yacscom.cab" >jcs.chat.dcn.yahoo.com/v45/yacscom.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe" >appldnld.m7z.net/qtinstall.info.&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - &raquo;<A HREF="http://spaces.msn.com//PhotoUpload/MsnPUpld.cab" >spaces.msn.com//PhotoUpload/MsnPUpld.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1115410355375" >v5.windowsupdate.microsoft.com/v&middot;&middot;&middot;10355375</A><br>O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/en/filesharingctrl.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;ctrl.cab</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - &raquo;<A HREF="http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab" >appdirectory.messenger.msn.com/A&middot;&middot;&middot;kMSN.cab</A><br>O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - &raquo;<A HREF="http://www.pcpitstop.com/mhLbl.cab" >www.pcpitstop.com/mhLbl.cab</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZAxRcMgr.cab" >messenger.zone.msn.com/binary/ZAxRcMgr.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" >messenger.zone.msn.com/binary/ZI&middot;&middot;&middot;2846.cab</A><br>O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab" >messenger.zone.msn.com/binary/Ba&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {C852B12E-3F08-4099-AF8E-32FD327B88EA} (msnloader Class) - &raquo;<A HREF="http://rockstar.messenger.msn.com/rockstar.cab" >rockstar.messenger.msn.com/rockstar.cab</A><br>O20 - Winlogon Notify: yabab - C:\WINDOWS\system32\yabab.dll<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\default\Local Settings\Temporary Internet Files\Content.IE5\82VVYU4H\CWShredder[1].exe (file missing)<br>O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14391810</guid>
<pubDate>Sun, 18 Sep 2005 17:22:58 EDT</pubDate>
</item>

</channel>
</rss>
