<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: HJT  Log - Winfixer 2005 will not stay away in Security</title>
<link>http://www.dslreports.com/forum/r14418905</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 00:05:42 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 00:05:42 EDT</lastBuildDate>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14662484</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : jimh, in addition, you need to start your own topic if you still need help after that.<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14662484</guid>
<pubDate>Wed, 26 Oct 2005 13:07:56 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14660570</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : This works for most people.<br><br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/13331">How Do I Remove Trojan Vundo/Winfixer/Virtumonde?</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14660570</guid>
<pubDate>Wed, 26 Oct 2005 07:01:01 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14660494</link>
<description><![CDATA[<A HREF="/useremail/u/1281661"><b>jimh6</b></A> : Hello to anyone that can help,<br><br>I have been searching google for an answer to the same problem DJCFP had, but I am unable to remove my hard drive to another computer to delete the files that are infected, and continue on with the repair. How do you delete the file (mine is C:\windows\system32\gebcy.dll.<br><br>I have tried everything mention by Joker (I think), and i ended up just like DJCFP, but I can go no further without deleting that file (I assume). Here is my HJT file:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 5:22:34 AM, on 10/26/2005<br>Platform: Windows XP SP1 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe<br>C:\Program Files\Microsoft AntiSpyware\gcasServ.exe<br>C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>C:\WINDOWS\System32\CTsvcCDA.exe<br>C:\Program Files\ewido\security suite\ewidoctrl.exe<br>C:\Program Files\ewido\security suite\ewidoguard.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Spyware Doctor\sdhelp.exe<br>C:\WINDOWS\System32\tcpsvcs.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\WINDOWS\system32\ntvdm.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE<br>C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE<br>C:\Program Files\hijackthis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://goggle.com" >goggle.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://goggle.com" >goggle.com</A><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = <br>O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll<br>O2 - BHO: MSEvents Object - {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - C:\WINDOWS\System32\gebcy.dll<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe<br>O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"<br>O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll<br>O9 - Extra button: @C:\Program Files\Messenger2\im2_ie_plugin.dll,-4 - {410C30C7-098A-4090-928E-F1D356D34C7F} - C:\Program Files\Messenger2\im2_ie_plugin.dll<br>O9 - Extra 'Tools' menuitem: Run IM2 Messenger - {410C30C7-098A-4090-928E-F1D356D34C7F} - C:\Program Files\Messenger2\im2_ie_plugin.dll<br>O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE<br>O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE<br>O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - &raquo;<A HREF="http://pcpitstop.com/pcpitstop/PCPitStop.CAB" >pcpitstop.com/pcpitstop/PCPitStop.CAB</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - &raquo;<A HREF="http://www.snapfish.com/SnapfishActivia.cab" >www.snapfish.com/SnapfishActivia.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120079588218" >update.microsoft.com/windowsupda&middot;&middot;&middot;79588218</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://acs.pandasoftware.com/activescan/as5free/asinst.cab" >acs.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - &raquo;<A HREF="http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab" >photo.walmart.com/photo/uploads/&middot;&middot;&middot;ient.cab</A><br>O20 - Winlogon Notify: gebcy - C:\WINDOWS\System32\gebcy.dll<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<br>O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe<br>O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe<br>O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe<br>O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe<br>O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe<br>O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe<br><br>Thank you in advance for your help.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14660494</guid>
<pubDate>Wed, 26 Oct 2005 06:25:31 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14430191</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I recommend clearing all your TEMP files and Recycle Bin now:<br>Click on Start > Run<br>In the Run command line, type CLEANMGR<br>In the windows that opens, you can select a drive (C: is the default), Click OK<br>On the Disk Cleanup tab, check:<br>Make sure the following are checked:<br>   Downloaded Program Files<br>   Temporary Internet Files and<br>   Recycle Bin<br>   Temporary Files<br>Click OK > Yes<br><br>Now let's turn off and then restart System Restore. <B>This will delete all your restore points</B>, but it will also prevent you from inadvertently restoring any of the fixes you have just implemented.  When you enable the System Restore feature again, the System Restore feature will create a new restore point and then resume monitoring your computer.<br><br>To disable and re-enable System Restore:<br><br>Go to Start --> Settings --> Control Panel --> System --> System Restore, and check <B><I>Turn off System Restore on all drives</I></B>, and select <B>Apply</B>.  Now uncheck <B><I>Turn off System Restore on all drives</I></B>, select <B>OK</B>, and restart your system.<br><br>Now you need to hide the files you un-hid earlier:<br><br>Click Start. Open My Computer.<br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading unselect "Show hidden files and folders". <br>Check the "Hide protected operating system files (recommended)" option. <br>Click Yes to confirm. Click OK.<br><br><B>You need a software firewall</B>. Unless one of those McAfee lines in your log is for a McAfee firewall, I didn't see one in your HijackThis log. Two free firewalls are Zone Alarm from zonelabs.com &raquo;<A HREF="http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp" >www.zonelabs.com/store/content/c&middot;&middot;&middot;load.jsp</A> or Kerio Personal Firewall available from &raquo;<A HREF="http://www.kerio.com/us/kpf_home.html" >www.kerio.com/us/kpf_home.html</A>. There is a tutorial on understanding firewalls at &raquo;<A HREF="http://www.bleepingcomputer.com/forums/tutorial60.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;l60.html</A>. <br><br>There are several free utilities you can use to help keep malware off your system: <br><br>A HOSTS file will prevent Internet Explorer from communicating with sites associated with adware or spyware. A good regularly updated HOST file is MVPS HOSTS File, available at &raquo;<A HREF="http://www.mvps.org/winhelp2002/hosts.htm" >www.mvps.org/winhelp2002/hosts.htm</A>. <br><br>IE/SPYAD adds sites associated with ads and spyware to your Internet Restricted Zone and you can download that at &raquo;<small>https</small>://<A HREF="https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD">netfiles.uiuc.edu/ehowes/www/res&middot;&middot;&middot;#IESPYAD</A>.<br><br>A free non-resident utility to prevent the installation of ActiveX-based malware is JavaCool's SpywareBlaster. For real-time protection, there is SpywareGuard. Both are available at &raquo;<A HREF="http://www.javacoolsoftware.com/products.html" >www.javacoolsoftware.com/products.html</A>. <br><br>I recommend reading Tony Klein's article <I>How did I get Infected?</I> at &raquo;<A HREF="http://www.computercops.biz/postlite7736-.html" >www.computercops.biz/postlite7736-.html</A><br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14430191</guid>
<pubDate>Fri, 23 Sep 2005 20:19:07 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14428642</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Joker,<br><br>I merged the file vundo.reg to my registry and performed Activescan. It appears as if I am good to go. I want to thank you so much for all of your help. I am not used to being on the receiving end of computer tech support, but I had no choice this time as it was so stubborn. This forum and it's members are the best! My hat is off to you Joker!<br><br>Here are the results of my Activescan:<br><br>Incident&#9;Status&#9;Location<br>Virus:Eicar.Mod&#9;No disinfected&#9;C:\Program Files\PestPatrol\Help.chm[HowCanITestDetection.html]]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14428642</guid>
<pubDate>Fri, 23 Sep 2005 16:20:09 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14427817</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : That got the file, and you also have successfully "fixed" the two lines in HijachThis. :)<br><br>Now you need to locate the vundo.reg file that you previously saved to your Desktop, <B>double click</B> it and <B>allow</B> it to merge with the registry. <br><br>I will be looking for the scan results. Good job.<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14427817</guid>
<pubDate>Fri, 23 Sep 2005 14:06:40 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14427668</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Joker,<br><br>Thank you again for all of this help. I had already done the search when you posted this last post. I had also tryed many things to try to get rid of that file (ddcax.dll) to no avail. So with that in mind, this what I did. I once again removed this HDD from the affected machine and installed it in another XP machine as a slave drive. I then searched for ddcax & xacdd and found the following: D:\WINDOWS\SYSTEM32\ddcax.dll & D:\WINDOWS\SYSTEM32\xacdd.ini (which would have been C:\WINDOWS\SYSTEM32\ddcax.dll & C:\WINDOWS\SYSTEM32\xacdd.ini had the drive been in the affected machine as the primary drive)<br><br>I then deleted those files (I was able to do this because there was no process trying to use them) Then I reinstalled the HDD in it's machine, booted in the safe mode and ran HJT and checked and fixed the following entries:<br><br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll (file missing)<br><br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll (file missing)<br><br>I then rebooted the machine and ran HJT. I am currently running activescan and will send you the results after it is through. Here is is the latest HJT log.<br><br>HJT Log:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 10:24:48 AM, on 9/23/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>c:\program files\mcafee.com\agent\mcdetect.exe<br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>C:\Program Files\Common Files\Microsoft <br><br>Shared\VS7Debug\mdm.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EX<br><br>E<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\HJT\HijackThis.exe<br><br>O2 - BHO: (no name) - <br><br>{53707962-6F74-2D53-2644-206D7942484F} - <br><br>C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: McAfee VirusScan - <br><br>{BA52B914-B692-46c4-B683-905236F6F655} - <br><br>c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS <br><br>Software\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SideWinderTrayV4] <br><br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>O4 - HKLM\..\Run: [HP Lamp] <br><br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>O4 - HKLM\..\Run: [EM_EXEC] <br><br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EX<br><br>E<br>O4 - HKLM\..\Run: [PinnacleDriverCheck] <br><br>C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg<br>O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program <br><br>Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE <br><br>C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [MCUpdateExe] <br><br>C:\PROGRA~1\mcafee.com\agent\mcupdate.exe<br>O4 - HKLM\..\Run: [MCAgentExe] <br><br>c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] <br><br>"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] C:\Program <br><br>Files\McAfee.com\VSO\mcvsshld.exe<br>O4 - HKLM\..\Run: [OASClnt] C:\Program <br><br>Files\McAfee.com\VSO\oasclnt.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] <br><br>C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: Keyboard Express 3.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - <br><br>res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - <br><br>{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: (no name) - <br><br>{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - <br><br>{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: Research - <br><br>{92780B25-18CC-41C8-B9BE-3C9C571A8263} - <br><br>C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} <br><br>(Microsoft ProgressBar Control, version 5.0 (SP2)) - <br><br>&raquo;<A HREF="http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComC" >bin.mcafee.com/molbin/Shared/Com&middot;&middot;&middot;,22/ComC</A><br><br>tl32.cab<br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} <br><br>(BrowseFolderPopup Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - <br><br>&raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.appl" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;nfo.appl</A><br><br>e.com/samantha/us/win/QuickTimeInstaller.exe<br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} <br><br>(McAfee.com Operating System Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/m" >download.mcafee.com/molbin/share&middot;&middot;&middot;0,0,99/m</A><br><br>cinsctl.cab<br>O16 - DPF: {53F63B36-5DB3-4C19-A8AB-2CB9AE7D57F7} <br><br>(CFM_AXFTP_MOD.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB" >www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} <br><br>(WUWebControl Class) - <br><br>&raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x8" >update.microsoft.com/windowsupda&middot;&middot;&middot;ls/en/x8</A><br><br>6/client/wuweb_site.cab?1120431258104<br>O16 - DPF: {6EA0A4DB-0B94-40E1-9165-54F5694C19EC} <br><br>(CFM2004noruna.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB" >www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB</A><br>O16 - DPF: {73989DDC-D9DE-47F7-B262-6FE39DC70BC2} <br><br>(CFM2004Turbo.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB" >www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB</A><br>O16 - DPF: {797FA1DD-30E7-4093-A892-E8C2A556A583} <br><br>(CFM2005TurboDMCrs.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMCrs.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;MCrs.CAB</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} <br><br>(ActiveScan Installer Class) - <br><br>&raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {A49DFBB5-A3BB-45FE-BA2F-34890123C47F} <br><br>(CFM2005TurboDMC.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMC.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;oDMC.CAB</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} <br><br>(DwnldGroupMgr Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/m" >download.mcafee.com/molbin/share&middot;&middot;&middot;0,0,26/m</A><br><br>cgdmgr.cab<br>O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} <br><br>(Java Runtime Environment 1.4.0) - <br>O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} <br><br>(Java Runtime Environment 1.4.1) - <br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} <br><br>(PhotosCtrl Class) - <br><br>&raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {DB1C1859-F90A-47DE-8934-FB8CECE8E6F3} <br><br>(CFM_AXFTP_MOD.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmodnorun.CAB" >www.racelm.com/rlm/cfmaxftp/cfmp&middot;&middot;&middot;orun.CAB</A><br>O16 - DPF: {DDC38B48-52B8-4FD6-BBB3-2FC2C136FD0D} <br><br>(CFM2004a.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004a.CAB" >www.racelm.com/rlm/cfm2004/cfm2004a.CAB</A><br>O16 - DPF: {F461205D-ABDC-42FE-B2E2-AFD4600B905E} <br><br>(MASHControl Class) - <br><br>&raquo;<A HREF="http://www.amiuptodate.com/vsc/mvt/bin/1,0,0,7/mash.cab" >www.amiuptodate.com/vsc/mvt/bin/&middot;&middot;&middot;mash.cab</A><br>O17 - <br><br>HKLM\System\CCS\Services\Tcpip\..\{6A551B11-F6EE-4A28-8<br><br>E26-0BAB4D056B63}: NameServer = <br><br>64.166.172.8,206.13.29.12<br>O23 - Service: Adobe LM Service - Unknown owner - C:\Program <br><br>Files\Common Files\Adobe Systems <br><br>Shared\Service\Adobelmsvc.exe<br>O23 - Service: C-DillaCdaC11BA - Macrovision - <br><br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>O23 - Service: Crypkey License - Kenonic Controls Ltd. - <br><br>C:\WINDOWS\SYSTEM32\crypserv.exe<br>O23 - Service: GEARSecurity_BackUp - Unknown owner - <br><br>C:\WINDOWS\SYSTEM32\GEARSEC.EXE (file missing)<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. <br><br>- C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner <br><br>- C:\Program Files\Common Files\Macromedia <br><br>Shared\Service\Macromedia Licensing.exe<br>O23 - Service: McAfee WSC Integration (McDetect.exe) - <br><br>McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br>O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - <br><br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee Task Scheduler (McTskshd.exe) - <br><br>McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>O23 - Service: McAfee SecurityCenter Update Manager <br><br>(mcupdmgr.exe) - McAfee, Inc - <br><br>C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA <br><br>Corporation - C:\WINDOWS\system32\nvsvc32.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14427668</guid>
<pubDate>Fri, 23 Sep 2005 13:45:34 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14426805</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : This one is being stubborn.<br><br>Using Windows Search (Start > Search > For Files or Folders), please search for and locate all instances of the following files:<br><br><B>ddcax<br>xacdd</B><br><br>Don't use a file extension. This will also find any other files of the same name but with any file extension.<br><br>Please post the full file name (with extension) and path of any files found along with a new HijackThis log. <br><br>Please locate your original XP install CD and have it handy. If you computer's BIOS is not set to allow booting from the CD, do you know how to change that? We will try removing the file from the recovery console. Once the file is gone, we should be able to proceed.<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14426805</guid>
<pubDate>Fri, 23 Sep 2005 11:30:25 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14423522</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Joker,<br><br>I followed those instructions and found only ddcax.dll threads in explorer.exe only (none in winlogon.exe) Also, I found no backwards or other iterrations of that file name.<br><br>I got an interesting message from Killbox when performing the delete on reboot operation, it said:<br><br>PendingFileRenameOperations Registry Data has been Removed by External Process!<br><br>HJT Log:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 6:08:01 PM, on 9/22/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>c:\program files\mcafee.com\agent\mcdetect.exe<br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Common Files\Microsoft <br><br>Shared\VS7Debug\mdm.exe<br>c:\PROGRA~1\mcafee.com\vso\OasClnt.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>c:\program files\mcafee.com\agent\mcagent.exe<br>c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EX<br><br>E<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\HJT\HijackThis.exe<br><br>O2 - BHO: MSEvents Object - <br><br>{52B1DFC7-AAFC-4362-B103-868B0683C697} - <br><br>C:\WINDOWS\system32\ddcax.dll<br>O2 - BHO: (no name) - <br><br>{53707962-6F74-2D53-2644-206D7942484F} - <br><br>C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: McAfee VirusScan - <br><br>{BA52B914-B692-46c4-B683-905236F6F655} - <br><br>c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS <br><br>Software\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SideWinderTrayV4] <br><br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>O4 - HKLM\..\Run: [HP Lamp] <br><br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>O4 - HKLM\..\Run: [EM_EXEC] <br><br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EX<br><br>E<br>O4 - HKLM\..\Run: [PinnacleDriverCheck] <br><br>C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg<br>O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program <br><br>Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE <br><br>C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [MCUpdateExe] <br><br>C:\PROGRA~1\mcafee.com\agent\mcupdate.exe<br>O4 - HKLM\..\Run: [MCAgentExe] <br><br>c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] <br><br>"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] C:\Program <br><br>Files\McAfee.com\VSO\mcvsshld.exe<br>O4 - HKLM\..\Run: [OASClnt] C:\Program <br><br>Files\McAfee.com\VSO\oasclnt.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] <br><br>C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: Keyboard Express 3.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - <br><br>res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - <br><br>{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: (no name) - <br><br>{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - <br><br>{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: Research - <br><br>{92780B25-18CC-41C8-B9BE-3C9C571A8263} - <br><br>C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} <br><br>(Microsoft ProgressBar Control, version 5.0 (SP2)) - <br><br>&raquo;<A HREF="http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComC" >bin.mcafee.com/molbin/Shared/Com&middot;&middot;&middot;,22/ComC</A><br><br>tl32.cab<br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} <br><br>(BrowseFolderPopup Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - <br><br>&raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.appl" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;nfo.appl</A><br><br>e.com/samantha/us/win/QuickTimeInstaller.exe<br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} <br><br>(McAfee.com Operating System Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/m" >download.mcafee.com/molbin/share&middot;&middot;&middot;0,0,99/m</A><br><br>cinsctl.cab<br>O16 - DPF: {53F63B36-5DB3-4C19-A8AB-2CB9AE7D57F7} <br><br>(CFM_AXFTP_MOD.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB" >www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} <br><br>(WUWebControl Class) - <br><br>&raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x8" >update.microsoft.com/windowsupda&middot;&middot;&middot;ls/en/x8</A><br><br>6/client/wuweb_site.cab?1120431258104<br>O16 - DPF: {6EA0A4DB-0B94-40E1-9165-54F5694C19EC} <br><br>(CFM2004noruna.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB" >www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB</A><br>O16 - DPF: {73989DDC-D9DE-47F7-B262-6FE39DC70BC2} <br><br>(CFM2004Turbo.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB" >www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB</A><br>O16 - DPF: {797FA1DD-30E7-4093-A892-E8C2A556A583} <br><br>(CFM2005TurboDMCrs.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMCrs.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;MCrs.CAB</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} <br><br>(ActiveScan Installer Class) - <br><br>&raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {A49DFBB5-A3BB-45FE-BA2F-34890123C47F} <br><br>(CFM2005TurboDMC.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMC.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;oDMC.CAB</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} <br><br>(DwnldGroupMgr Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/m" >download.mcafee.com/molbin/share&middot;&middot;&middot;0,0,26/m</A><br><br>cgdmgr.cab<br>O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} <br><br>(Java Runtime Environment 1.4.0) - <br>O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} <br><br>(Java Runtime Environment 1.4.1) - <br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} <br><br>(PhotosCtrl Class) - <br><br>&raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {DB1C1859-F90A-47DE-8934-FB8CECE8E6F3} <br><br>(CFM_AXFTP_MOD.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmodnorun.CAB" >www.racelm.com/rlm/cfmaxftp/cfmp&middot;&middot;&middot;orun.CAB</A><br>O16 - DPF: {DDC38B48-52B8-4FD6-BBB3-2FC2C136FD0D} <br><br>(CFM2004a.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004a.CAB" >www.racelm.com/rlm/cfm2004/cfm2004a.CAB</A><br>O16 - DPF: {F461205D-ABDC-42FE-B2E2-AFD4600B905E} <br><br>(MASHControl Class) - <br><br>&raquo;<A HREF="http://www.amiuptodate.com/vsc/mvt/bin/1,0,0,7/mash.cab" >www.amiuptodate.com/vsc/mvt/bin/&middot;&middot;&middot;mash.cab</A><br>O17 - <br><br>HKLM\System\CCS\Services\Tcpip\..\{6A551B11-F6EE-4A28-8<br><br>E26-0BAB4D056B63}: NameServer = <br><br>64.166.172.8,206.13.29.12<br>O20 - Winlogon Notify: ddcax - <br><br>C:\WINDOWS\system32\ddcax.dll<br>O23 - Service: Adobe LM Service - Unknown owner - C:\Program <br><br>Files\Common Files\Adobe Systems <br><br>Shared\Service\Adobelmsvc.exe<br>O23 - Service: C-DillaCdaC11BA - Macrovision - <br><br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>O23 - Service: Crypkey License - Kenonic Controls Ltd. - <br><br>C:\WINDOWS\SYSTEM32\crypserv.exe<br>O23 - Service: GEARSecurity_BackUp - Unknown owner - <br><br>C:\WINDOWS\SYSTEM32\GEARSEC.EXE (file missing)<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. <br><br>- C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner <br><br>- C:\Program Files\Common Files\Macromedia <br><br>Shared\Service\Macromedia Licensing.exe<br>O23 - Service: McAfee WSC Integration (McDetect.exe) - <br><br>McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br>O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - <br><br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee Task Scheduler (McTskshd.exe) - <br><br>McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>O23 - Service: McAfee SecurityCenter Update Manager <br><br>(mcupdmgr.exe) - McAfee, Inc - <br><br>C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA <br><br>Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - <br><br>Webroot Software, Inc. - C:\Program Files\Webroot\Spy <br><br>Sweeper\WRSSSDK.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14423522</guid>
<pubDate>Thu, 22 Sep 2005 21:15:07 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14423168</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Oh man, and I was doing so good at following your instructions to this point, I read on in your last post, and it addressed me looking for it in explorer.exe, sorry, I am continuing on.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14423168</guid>
<pubDate>Thu, 22 Sep 2005 20:21:09 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14423115</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Joker,<br><br>I am in process explorer in the safe mode on the affected machine. When following your instructions by double clicking on winlogin.exe, then selecting the threads tab, there are no instances of ddcax.dll at all, for that matter, all of the threads in winlogin.exe are somewhat generic in nature. A few examples are: 0x103d353, !CreateThread+0x27, etc......... However, I took it upon myself to use the find function in the main menu of process explorer to find ddcax.dll and found it in threads of explorer.exe. Some examples of those threads are: ddcax.dll+0x233ad, ddcax.dll+0x2047c, etc...<br><br>I have not got any further than simply finding those threads, so please advise.<br><br>Thank you Joker]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14423115</guid>
<pubDate>Thu, 22 Sep 2005 20:10:53 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14422748</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Ok, since the automated method isn't working, lets try an older manual method.<br><br>Please download Process Explorer by Systernals from <A HREF="http://www.sysinternals.com/files/procexpnt.zip"> HERE</A> <br><br>Also download KillBox by Option^Explicit from www.thespykiller.co.uk/files/killbox.exe<br><br><B>Then boot up in</B> <A HREF="http://www.bleepingcomputer.com/forums/index.php?showtutorial=61"> SAFE MODE</A> <br><br><B>the rest of this fix must be done in safe mode.</B> <br><br>Unzip Process Explorer and double click on <B>procexp.exe</B> <br><br>In the top section of the Process Explorer screen double click on <B>winlogon.exe</B> to bring up the winlogon.exe properties screen. Click on the <B>Threads tab</B> at the top. <br><br>Once you see this screen click on each instance of <B>ddcax.dll</B> once and then click the <B>kill</B> button. <br><br>After you have killed all of the <B>ddcax.dll</B>'s under winlogon click <B>OK</B>. <br><br>also look for any .ini or bak files or other dll's with either the same name or the file name in reverse & kill them as well <br><br>Example: <br><br>ddcax.bak<br>ddcax.ini<br>ddcax.reg etc<br><br>or<br><br>xacdd.dll<br>xacdd.bak<br>xacdd.ini etc<br><br>Next double click on <B>explorer.exe</B> and again click once on each instance of <B>ddcax.dll</B> then click the <B>kill</B> button. <br><br>also look for any .ini or bak files or reverse named dll's with either the same name or the file name in reverse & kill them as well.  See above for examples, and <B>write down the names and full path of files you find, you will need those file paths for Killbox</B>.<br><br>Click on the <B>Threads</B> tab at the top. <br><br>Once you have done that click <B>OK</B> again. <br><br>Next run HijackThis and place a check beside each of the following. <br><br><B> O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll<br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll</B><br><br>Now click <B>fix checked</B> and close HijackThis. <br><br>Please copy the text in the box below, and paste it into a blank notepad window. <br>Save it as <B>vundo.reg</B> and in the save as type box choose <B>all files</B>. <br><br>Once you have saved it <B>double click</B> it and <B>allow</B> it to merge with the registry. <br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>REGEDIT4 <br><br>[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}] <br><br>[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] <br><br>[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}] <br><br>[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}] <br><br>[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] <br><br>[-HKEY_CLASSES_ROOT\MSEvents.MSEvents] <br><br>[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1] <br><br>[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents] <br><br>[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]<HR></BLOCKQUOTE> <br><br>Now run killbox and paste The line below in bold into the box, select delete on reboot then press the red X button, say <B>yes</B> to the prompt but <B>no</B> to reboot now <br><br>Then continue to paste the lines in turn and follow the above procedure every time, If it says file is missing, or if it says unable to delete then make a note of the file name and let us know when you reply <br><br><B>C:\WINDOWS\system32\ddcax.dll</B><br><br>Then repeat by typing in the full name of any of the reverse named .bak or .ini or other files that you discovered in step 1 if there were any.<br><br>When you enter the last file, select <B>yes</B> to Reboot now. If you system does not restart, reboot it manually<br><br>After your computer has rebooted please run Hijackthis again and post a new HijackThis log.<br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14422748</guid>
<pubDate>Thu, 22 Sep 2005 19:17:00 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14422329</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Okay, I followed the steps in your last reply and here are the results of the scans:<br><br>Activescan:<br><br>Incident&#9;Status&#9;Location<br>Spyware:Spyware/Virtumonde&#9;No disinfected&#9;C:\HJT\backups\backup-20050922-134457-263.dll<br>Virus:Eicar.Mod&#9;No disinfected&#9;C:\Program Files\PestPatrol\Help.chm[HowCanITestDetection.html]<br>Spyware:Spyware/Virtumonde&#9;No disinfected&#9;C:\WINDOWS\system32\ddcax.dll<br><br>HJT:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 3:03:41 PM, on 9/22/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>c:\program files\mcafee.com\agent\mcdetect.exe<br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>C:\Program Files\Common Files\Microsoft <br><br>Shared\VS7Debug\mdm.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EX<br><br>E<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\system32\NOTEPAD.EXE<br>C:\HJT\HijackThis.exe<br><br>O2 - BHO: MSEvents Object - <br><br>{52B1DFC7-AAFC-4362-B103-868B0683C697} - <br><br>C:\WINDOWS\system32\ddcax.dll<br>O2 - BHO: (no name) - <br><br>{53707962-6F74-2D53-2644-206D7942484F} - <br><br>C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: McAfee VirusScan - <br><br>{BA52B914-B692-46c4-B683-905236F6F655} - <br><br>c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS <br><br>Software\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SideWinderTrayV4] <br><br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>O4 - HKLM\..\Run: [HP Lamp] <br><br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>O4 - HKLM\..\Run: [EM_EXEC] <br><br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EX<br><br>E<br>O4 - HKLM\..\Run: [PinnacleDriverCheck] <br><br>C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg<br>O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program <br><br>Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE <br><br>C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [MCUpdateExe] <br><br>C:\PROGRA~1\mcafee.com\agent\McUpdate.exe<br>O4 - HKLM\..\Run: [MCAgentExe] <br><br>c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] <br><br>"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] C:\Program <br><br>Files\McAfee.com\VSO\mcvsshld.exe<br>O4 - HKLM\..\Run: [OASClnt] C:\Program <br><br>Files\McAfee.com\VSO\oasclnt.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] <br><br>C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: Keyboard Express 3.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - <br><br>res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - <br><br>{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: (no name) - <br><br>{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - <br><br>{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program <br><br>Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: Research - <br><br>{92780B25-18CC-41C8-B9BE-3C9C571A8263} - <br><br>C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} <br><br>(Microsoft ProgressBar Control, version 5.0 (SP2)) - <br><br>&raquo;<A HREF="http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComC" >bin.mcafee.com/molbin/Shared/Com&middot;&middot;&middot;,22/ComC</A><br><br>tl32.cab<br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} <br><br>(BrowseFolderPopup Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - <br><br>&raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.appl" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;nfo.appl</A><br><br>e.com/samantha/us/win/QuickTimeInstaller.exe<br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} <br><br>(McAfee.com Operating System Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/m" >download.mcafee.com/molbin/share&middot;&middot;&middot;0,0,99/m</A><br><br>cinsctl.cab<br>O16 - DPF: {53F63B36-5DB3-4C19-A8AB-2CB9AE7D57F7} <br><br>(CFM_AXFTP_MOD.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB" >www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} <br><br>(WUWebControl Class) - <br><br>&raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x8" >update.microsoft.com/windowsupda&middot;&middot;&middot;ls/en/x8</A><br><br>6/client/wuweb_site.cab?1120431258104<br>O16 - DPF: {6EA0A4DB-0B94-40E1-9165-54F5694C19EC} <br><br>(CFM2004noruna.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB" >www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB</A><br>O16 - DPF: {73989DDC-D9DE-47F7-B262-6FE39DC70BC2} <br><br>(CFM2004Turbo.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB" >www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB</A><br>O16 - DPF: {797FA1DD-30E7-4093-A892-E8C2A556A583} <br><br>(CFM2005TurboDMCrs.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMCrs.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;MCrs.CAB</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} <br><br>(ActiveScan Installer Class) - <br><br>&raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {A49DFBB5-A3BB-45FE-BA2F-34890123C47F} <br><br>(CFM2005TurboDMC.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMC.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;oDMC.CAB</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} <br><br>(DwnldGroupMgr Class) - <br><br>&raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/m" >download.mcafee.com/molbin/share&middot;&middot;&middot;0,0,26/m</A><br><br>cgdmgr.cab<br>O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} <br><br>(Java Runtime Environment 1.4.0) - <br>O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} <br><br>(Java Runtime Environment 1.4.1) - <br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} <br><br>(PhotosCtrl Class) - <br><br>&raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {DB1C1859-F90A-47DE-8934-FB8CECE8E6F3} <br><br>(CFM_AXFTP_MOD.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmodnorun.CAB" >www.racelm.com/rlm/cfmaxftp/cfmp&middot;&middot;&middot;orun.CAB</A><br>O16 - DPF: {DDC38B48-52B8-4FD6-BBB3-2FC2C136FD0D} <br><br>(CFM2004a.UserControl1) - <br><br>&raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004a.CAB" >www.racelm.com/rlm/cfm2004/cfm2004a.CAB</A><br>O16 - DPF: {F461205D-ABDC-42FE-B2E2-AFD4600B905E} <br><br>(MASHControl Class) - <br><br>&raquo;<A HREF="http://www.amiuptodate.com/vsc/mvt/bin/1,0,0,7/mash.cab" >www.amiuptodate.com/vsc/mvt/bin/&middot;&middot;&middot;mash.cab</A><br>O17 - <br><br>HKLM\System\CCS\Services\Tcpip\..\{6A551B11-F6EE-4A28-8<br><br>E26-0BAB4D056B63}: NameServer = <br><br>64.166.172.8,206.13.29.12<br>O20 - Winlogon Notify: ddcax - <br><br>C:\WINDOWS\system32\ddcax.dll<br>O23 - Service: Adobe LM Service - Unknown owner - C:\Program <br><br>Files\Common Files\Adobe Systems <br><br>Shared\Service\Adobelmsvc.exe<br>O23 - Service: C-DillaCdaC11BA - Macrovision - <br><br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>O23 - Service: Crypkey License - Kenonic Controls Ltd. - <br><br>C:\WINDOWS\SYSTEM32\crypserv.exe<br>O23 - Service: GEARSecurity_BackUp - Unknown owner - <br><br>C:\WINDOWS\SYSTEM32\GEARSEC.EXE (file missing)<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. <br><br>- C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner <br><br>- C:\Program Files\Common Files\Macromedia <br><br>Shared\Service\Macromedia Licensing.exe<br>O23 - Service: McAfee WSC Integration (McDetect.exe) - <br><br>McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br>O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - <br><br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee Task Scheduler (McTskshd.exe) - <br><br>McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>O23 - Service: McAfee SecurityCenter Update Manager <br><br>(mcupdmgr.exe) - McAfee, Inc - <br><br>C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA <br><br>Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - <br><br>Webroot Software, Inc. - C:\Program Files\Webroot\Spy <br><br>Sweeper\WRSSSDK.exe<br><br>Vundofix:<br><br>Could not delete file.<br>Files Deleted sucessfully.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14422329</guid>
<pubDate>Thu, 22 Sep 2005 18:08:35 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14421075</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Lets try one more time. If it doesn&#146;t work, we'll try another method. Now that there is only one set of entries for Vundo, it may work better.<br><br>Please reboot your computer into <B>Safe Mode</B>.  You can do this by restarting your computer and continually tapping the F8 key until a menu appears.  Use your up arrow key to highlight Safe Mode then hit enter.<br><br>[*]Once in Safe mode, Using Windows Explorer, locate and delete the following Files:<br><br>C:\HJT\backups\<B>backup-20050922-091542-924.dll</B><br>C:\WINDOWS\<B>dhdomp1.bin</B><br><br>[*]Open the <B>VundoFix</B> folder and doubleclick on <B>KillVundo.bat</B><br>[*]You will first be presented with a warning and a list of forums to seek help at.<br>it should look like this<br><div class="code"><PRE><span class="codetext">VundoFix V2.1 by Atri<br>By pressing enter you agree that you are using this at your own risk<br>Please seek assistance at one of the following forums:<br>http://www.atribune.org/forums<br>http://www.247fixes.com/forums<br>http://www.geekstogo.com/forum<br>http://forums.net-integration.net</SPAN></PRE></DIV>[*] At this point press enter one time.<br>[*] Next you will see:<br><div class="code"><PRE><span class="codetext">Type in the filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.</SPAN></PRE></DIV>[*]At this point please type the following file path (make sure to enter it exactly as below!):<br><br><B>C:\WINDOWS\SYSTEM32\ddcax.dll</B><br><br>[*]Press <B>Enter</B>, then press the <B>F6</B> key, then press <B>Enter</B> one more time to continue with the fix.<br>[*] Next you will see:<br><div class="code"><PRE><span class="codetext"> Please type in the second filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.</SPAN></PRE></DIV>[*]At this point please type the following file path (make sure to enter it exactly as below!):<br><br><B> C:\WINDOWS\SYSTEM32\xacdd.*</B><br><br>[*]Press <B>Enter</B>, then press the <B>F6</B> key, then press <B>Enter</B> one more time to continue with the fix.<br>[*]The fix will run then HijackThis will open.<br>[*]In HijackThis, please place a check next to the following items and click <B>FIX CHECKED</B>:<br><br><B> O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll<br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll</B><br><br>[*]After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.<br>[*]Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!<br>[*]Once your machine reboots please continue with the instructions below.<br><br>Then, please run this online virus scan:  <A HREF="http://www.pandasoftware.com/products/activescan.htm"><B>ActiveScan</B></A><br><br>Copy the <B>results of the ActiveScan</B> and paste them here along with a new <B>HijackThis log</B> and the <B>vundofix.txt</B> file from the vundofix folder into this topic.<br><br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14421075</guid>
<pubDate>Thu, 22 Sep 2005 15:08:59 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14420785</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Okay,<br><br>I performed the tasks that you requested. FYI, to delete C:\WINDOWS\system32\jkhgh.dll, I had to physically remove the HDD from this machine and install it as a slave in another XP machine. I tryed all other methods to no avail due to the fact that it was "being used by another process". That includes trying to delete it from a command prompt in the safe mode. Bottom line is that I got it deleted.<br><br>Here are the results of the scans that you requested:<br><br>vundofix:<br><br>Could not delete file.<br>Files Deleted sucessfully.<br><br>Activescan:<br><br>Incident&#9;Status&#9;Location<br>Spyware:Spyware/Virtumonde&#9;No disinfected&#9;C:\HJT\backups\backup-20050922-091542-924.dll<br>Virus:Eicar.Mod&#9;No disinfected&#9;C:\Program Files\PestPatrol\Help.chm[HowCanITestDetection.html]<br>Adware:adware/dealhelper&#9;No disinfected&#9;C:\WINDOWS\dhdomp1.bin<br>Spyware:Spyware/Virtumonde&#9;No disinfected&#9;C:\WINDOWS\system32\ddcax.dll<br><br>HJT:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 11:01:01 AM, on 9/22/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>c:\program files\mcafee.com\agent\mcdetect.exe<br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\HJT\HijackThis.exe<br><br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg<br>O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: Keyboard Express 3.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - &raquo;<A HREF="http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab" >bin.mcafee.com/molbin/Shared/Com&middot;&middot;&middot;tl32.cab</A><br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {53F63B36-5DB3-4C19-A8AB-2CB9AE7D57F7} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB" >www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120431258104" >update.microsoft.com/windowsupda&middot;&middot;&middot;31258104</A><br>O16 - DPF: {6EA0A4DB-0B94-40E1-9165-54F5694C19EC} (CFM2004noruna.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB" >www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB</A><br>O16 - DPF: {73989DDC-D9DE-47F7-B262-6FE39DC70BC2} (CFM2004Turbo.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB" >www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB</A><br>O16 - DPF: {797FA1DD-30E7-4093-A892-E8C2A556A583} (CFM2005TurboDMCrs.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMCrs.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;MCrs.CAB</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {A49DFBB5-A3BB-45FE-BA2F-34890123C47F} (CFM2005TurboDMC.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMC.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;oDMC.CAB</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) - <br>O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) - <br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - &raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {DB1C1859-F90A-47DE-8934-FB8CECE8E6F3} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmodnorun.CAB" >www.racelm.com/rlm/cfmaxftp/cfmp&middot;&middot;&middot;orun.CAB</A><br>O16 - DPF: {DDC38B48-52B8-4FD6-BBB3-2FC2C136FD0D} (CFM2004a.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004a.CAB" >www.racelm.com/rlm/cfm2004/cfm2004a.CAB</A><br>O16 - DPF: {F461205D-ABDC-42FE-B2E2-AFD4600B905E} (MASHControl Class) - &raquo;<A HREF="http://www.amiuptodate.com/vsc/mvt/bin/1,0,0,7/mash.cab" >www.amiuptodate.com/vsc/mvt/bin/&middot;&middot;&middot;mash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{6A551B11-F6EE-4A28-8E26-0BAB4D056B63}: NameServer = 64.166.172.8,206.13.29.12<br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll<br>O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe<br>O23 - Service: GEARSecurity_BackUp - Unknown owner - C:\WINDOWS\SYSTEM32\GEARSEC.EXE (file missing)<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br>O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14420785</guid>
<pubDate>Thu, 22 Sep 2005 14:20:52 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14418905</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Let's take care of a few things there first, and then see if after running Vundofix you can get a clean scan.<br><br>One of the files the scan found was a test file (Eicar) for scanners, and not really a virus, so we will leave that alone. We will take care of the one listed as virtumondo with the Vundofix.<br><br>The first file Panda found was in your Sun Java Runtime Environment (JRE) cache. Delete it by clearing the JRE cache directory:<br><br>1. From the Start button, click Settings  -> Control Panel <br>2. In the Control Panel, open the "Java Plug-in Control Panel" <br>3. Select the Cache Tab <br>4. Click the Clear button inside the Cache Tab, which will clear your JRE cache directory<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br><br>Using Windows Explorer, locate and delete the following files:<br><br>C:\HJT\backups\<B>backup-20050921-181624-266.dll</B><br>C:\ <B>keys.ini</B><br>C:\WINDOWS\<B>dhdom1.bin</B><br>C:\WINDOWS\system32\<B>jkhgh.dll</B><br>C:\WINDOWS\system32\<B>msfdje.gif</B><br>C:\WINDOWS\system32\<B>mshpeb.dll</B><br>C:\WINDOWS\system32\<B>msnapl.dll</B><br><br>Please reboot your computer into <B>Safe Mode</B>.  You can do this by restarting your computer and continually tapping the F8 key until a menu appears.  Use your up arrow key to highlight Safe Mode then hit enter.<br>[*]Once in safe mode open the <B>VundoFix</B> folder and doubleclick on <B>KillVundo.bat</B><br>[*]You will first be presented with a warning and a list of forums to seek help at.<br>it should look like this<br><div class="code"><PRE><span class="codetext">VundoFix V2.1 by Atri<br>By pressing enter you agree that you are using this at your own risk<br>Please seek assistance at one of the following forums:<br>http://www.atribune.org/forums<br>http://www.247fixes.com/forums<br>http://www.geekstogo.com/forum<br>http://forums.net-integration.net</SPAN></PRE></DIV>[*] At this point press enter one time.<br>[*] Next you will see:<br><div class="code"><PRE><span class="codetext">Type in the filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.</SPAN></PRE></DIV>[*]At this point please type the following file path (make sure to enter it exactly as below!):<br><br><B>C:\WINDOWS\SYSTEM32\ddcax.dll</B><br><br>[*]Press <B>Enter</B>, then press the <B>F6</B> key, then press <B>Enter</B> one more time to continue with the fix.<br>[*] Next you will see:<br><div class="code"><PRE><span class="codetext"> Please type in the second filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.</SPAN></PRE></DIV>[*]At this point please type the following file path (make sure to enter it exactly as below!):<br><br><B> C:\WINDOWS\SYSTEM32\xacdd.*</B><br><br>[*]Press <B>Enter</B>, then press the <B>F6</B> key, then press <B>Enter</B> one more time to continue with the fix.<br>[*]The fix will run then HijackThis will open.<br>[*]In HijackThis, please place a check next to the following items and click <B>FIX CHECKED</B>:<br><br><B>O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhgh.dll<br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll<br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll<br>O20 - Winlogon Notify: jkhgh - C:\WINDOWS\SYSTEM32\jkhgh.dll</B><br><br>[*]After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.<br>[*]Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!<br>[*]Once your machine reboots please continue with the instructions below.<br><br>Then, please run this online virus scan:  <A HREF="http://www.pandasoftware.com/products/activescan.htm"><B>ActiveScan</B></A><br><br>Copy the <B>results of the ActiveScan</B> and paste them here along with a new <B>HijackThis log</B> and the <B>vundofix.txt</B> file from the vundofix folder into this topic.<br><br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14418905</guid>
<pubDate>Thu, 22 Sep 2005 09:02:58 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14417238</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Okay,<br><br>First of all, thank you for assisting me, it is much appreciated.<br><br>Now as far my progress. You mentioned that I would have to this twice. I assumed that you meant perform vundo fix once, reboot, post results, then do it or something like it again, so here are the results from the first run:<br><br>Activescan:<br>Incident                      Status                        Location                                                                                                                                                                                                                                                        <br><br>Adware:Adware/RazeSpyware     No disinfected                C:\Documents and Settings\Chuck\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SecurityClassLoader.class-51cccb7c-27e64a25.class                                                                                                                   <br>Adware:Adware/StartPage.AIW   No disinfected                C:\HJT\backups\backup-20050921-181624-266.dll                                                                                                                                                                                                                   <br>Adware:adware/delfinmedia     No disinfected                C:\keys.ini                                                                                                                                                                                                                                                     <br>Virus:Eicar.Mod               No disinfected                C:\Program Files\PestPatrol\Help.chm[HowCanITestDetection.html]                                                                                                                                                                                                 <br>Adware:adware/dealhelper      No disinfected                C:\WINDOWS\dhdom1.bin                                                                                                                                                                                                                                           <br>Spyware:Spyware/Virtumonde    No disinfected                C:\WINDOWS\system32\ddcax.dll                                                                                                                                                                                                                                   <br>Adware:Adware/StartPage.AIW   No disinfected                C:\WINDOWS\system32\jkhgh.dll                                                                                                                                                                                                                                   <br>Spyware:Spyware/Omi           No disinfected                C:\WINDOWS\system32\msfdje.gif                                                                                                                                                                                                                                  <br>Spyware:Spyware/Omi           No disinfected                C:\WINDOWS\system32\mshpeb.dll                                                                                                                                                                                                                                  <br>Spyware:Spyware/Omi           No disinfected                C:\WINDOWS\system32\msnapl.dll                                                                                                                                                                      <br><br>Hijack This:<br>Logfile of HijackThis v1.99.1<br>Scan saved at 8:21:48 PM, on 9/21/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>c:\program files\mcafee.com\agent\mcdetect.exe<br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\HJT\HijackThis.exe<br><br>O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhgh.dll<br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg<br>O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: Keyboard Express 3.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - &raquo;<A HREF="http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab" >bin.mcafee.com/molbin/Shared/Com&middot;&middot;&middot;tl32.cab</A><br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {53F63B36-5DB3-4C19-A8AB-2CB9AE7D57F7} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB" >www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120431258104" >update.microsoft.com/windowsupda&middot;&middot;&middot;31258104</A><br>O16 - DPF: {6EA0A4DB-0B94-40E1-9165-54F5694C19EC} (CFM2004noruna.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB" >www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB</A><br>O16 - DPF: {73989DDC-D9DE-47F7-B262-6FE39DC70BC2} (CFM2004Turbo.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB" >www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB</A><br>O16 - DPF: {797FA1DD-30E7-4093-A892-E8C2A556A583} (CFM2005TurboDMCrs.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMCrs.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;MCrs.CAB</A><br>O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - &raquo;<A HREF="http://www.pandasoftware.com/activescan/as5free/asinst.cab" >www.pandasoftware.com/activescan&middot;&middot;&middot;inst.cab</A><br>O16 - DPF: {A49DFBB5-A3BB-45FE-BA2F-34890123C47F} (CFM2005TurboDMC.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMC.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;oDMC.CAB</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) - <br>O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) - <br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - &raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {DB1C1859-F90A-47DE-8934-FB8CECE8E6F3} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmodnorun.CAB" >www.racelm.com/rlm/cfmaxftp/cfmp&middot;&middot;&middot;orun.CAB</A><br>O16 - DPF: {DDC38B48-52B8-4FD6-BBB3-2FC2C136FD0D} (CFM2004a.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004a.CAB" >www.racelm.com/rlm/cfm2004/cfm2004a.CAB</A><br>O16 - DPF: {F461205D-ABDC-42FE-B2E2-AFD4600B905E} (MASHControl Class) - &raquo;<A HREF="http://www.amiuptodate.com/vsc/mvt/bin/1,0,0,7/mash.cab" >www.amiuptodate.com/vsc/mvt/bin/&middot;&middot;&middot;mash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{6A551B11-F6EE-4A28-8E26-0BAB4D056B63}: NameServer = 64.166.172.8,206.13.29.12<br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll<br>O20 - Winlogon Notify: jkhgh - C:\WINDOWS\SYSTEM32\jkhgh.dll<br>O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe<br>O23 - Service: GEARSecurity_BackUp - Unknown owner - C:\WINDOWS\SYSTEM32\GEARSEC.EXE (file missing)<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br>O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br><br>vundofix.txt:<br><br>Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03<br>Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org<br>Suspending PID 200 'smss.exe'<br>Threads [204]Error 0x6 : The handle is invalid.<br><br>[208]Error 0x6 : The handle is invalid.<br><br>[212]Error 0x6 : The handle is invalid.<br><br>Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03<br>Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org<br>Killing PID 1100 'explorer.exe'<br><br>Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03<br>Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org<br>Error, Cannot find a process with an image name of rundll32.exe<br><br>Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03<br>Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org<br>Killing PID 272 'winlogon.exe'<br>Error 0x6 : The handle is invalid.<br><br>Could not delete file.<br>Files Deleted sucessfully.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14417238</guid>
<pubDate>Wed, 21 Sep 2005 23:39:07 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14414945</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Fix for djcfp on DSLReports<br><br>Hi djcfp, we'll get you fixed up, but will have to do this twice, you seem to have items related to two separate vundo infections.<br><br>Please print these instructions out for use in Safe Mode.<br><br>Please download www.atribune.org/downloads/VundoFix.exe to your desktop.<br>[*]Double-click <B>VundoFix.exe</B> to extract the files<br>[*]This will create a <B>VundoFix</B> folder on your desktop.<br>[*]After the files are extracted, please reboot your computer into <B>Safe Mode</B>.  You can do this by restarting your computer and continually tapping the F8 key until a menu appears.  Use your up arrow key to highlight Safe Mode then hit enter.<br>[*]Once in safe mode open the <B>VundoFix</B> folder and doubleclick on <B>KillVundo.bat</B><br>[*]You will first be presented with a warning and a list of forums to seek help at.<br>it should look like this<br><div class="code"><PRE><span class="codetext">VundoFix V2.1 by Atri<br>By pressing enter you agree that you are using this at your own risk<br>Please seek assistance at one of the following forums:<br>http://www.atribune.org/forums<br>http://www.247fixes.com/forums<br>http://www.geekstogo.com/forum<br>http://forums.net-integration.net</SPAN></PRE></DIV>[*] At this point press enter one time.<br>[*] Next you will see:<br><div class="code"><PRE><span class="codetext">Type in the filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.</SPAN></PRE></DIV>[*]At this point please type the following file path (make sure to enter it exactly as below!):<br><br><B>C:\WINDOWS\SYSTEM32\jkhgh.dll</B><br><br>[*]Press <B>Enter</B>, then press the <B>F6</B> key, then press <B>Enter</B> one more time to continue with the fix.<br>[*] Next you will see:<br><div class="code"><PRE><span class="codetext"> Please type in the second filepath as instructed by the forum staff<br>Then Press Enter, Then F6, Then Enter Again to continue with the fix.</SPAN></PRE></DIV>[*]At this point please type the following file path (make sure to enter it exactly as below!):<br><br><B> C:\WINDOWS\SYSTEM32\hghkj.*</B><br><br>[*]Press <B>Enter</B>, then press the <B>F6</B> key, then press <B>Enter</B> one more time to continue with the fix.<br>[*]The fix will run then HijackThis will open.<br>[*]In HijackThis, please place a check next to the following items and click <B>FIX CHECKED</B>:<br><br><B>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhgh.dll<br>O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - &raquo;&raquo;<small>https</small>://<A HREF="https://components.viewpoint.com/adobe/MTSInst">components.viewpoint.com/adobe/MTSInst</A>..</B><br><br>[*]After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.<br>[*]Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!<br>[*]Once your machine reboots please continue with the instructions below.<br><br>Then, please run this online virus scan:  <A HREF="http://www.pandasoftware.com/products/activescan.htm"><B>ActiveScan</B></A><br><br>Copy the <B>results of the ActiveScan</B> and paste them here along with a new <B>HijackThis log</B> and the <B>vundofix.txt</B> file from the vundofix folder into this topic.<br><br><SMALL>--<br>Proud ASAP member since 2005</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14414945</guid>
<pubDate>Wed, 21 Sep 2005 18:55:15 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14411814</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Thank you for the reply. I will do as you suggest and wait for one of the HJT experts to instruct me on how to use <B>vundofix</B>.<br><br>I have downloaded and extracted VundoFix to my Desktop on the affected machine. I will hold here and wait for further instructions.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14411814</guid>
<pubDate>Wed, 21 Sep 2005 11:35:16 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14410978</link>
<description><![CDATA[<A HREF="/useremail/u/726016"><b>Rusty Dusty</b></A> : This topic may be of help...<br>&raquo;<A HREF="/forum/remark,14391810">hijack this log...Winfixer, cws.qttask, Vx2.Look2m</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14410978</guid>
<pubDate>Wed, 21 Sep 2005 09:30:43 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14410147</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : These will need to be fixed as well.<br><br>O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhgh.dll<br>O20 - Winlogon Notify: jkhgh - C:\WINDOWS\SYSTEM32\jkhgh.dll]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14410147</guid>
<pubDate>Wed, 21 Sep 2005 04:06:33 EDT</pubDate>
</item>

<item>
<title>Re: HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14410057</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : This is a major problem.<br><br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\<B>ddcax.dll</B><br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\<B>ddcax.dll</B><br><br>You will have to wait for one of the forum HJT helpers to show you how you use vundofix.<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14410057</guid>
<pubDate>Wed, 21 Sep 2005 03:11:07 EDT</pubDate>
</item>

<item>
<title>HJT  Log - Winfixer 2005 will not stay away</title>
<link>http://www.dslreports.com/forum/remark,14408854</link>
<description><![CDATA[<A HREF="/useremail/u/305028"><b>djcfp</b></A> : Hello,<br><br>I have read the FAQs and have done everthing there (and more) I simply cannot keep Winfixer 2005 off of this machine. I have run (with up to the second updates and in this order) Awaware SE, SPYBOT Search and Destroy, Pest Patrol Corporate, Spy Sweeper, McAfee Online Virus Scan and Hijack This (HJT Log right after other scans and fixes and once again right after an immediate reboot)I first uninstalled Winfixer through the control panel, then scanned/fixed with the above process. I am including both HJT scans as well as the logs from some of the other software. By the way, I have tryed other orders and safe mode as well.<br><br>Before Reboot:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 7:24:14 PM, on 9/20/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>c:\program files\mcafee.com\agent\mcdetect.exe<br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\PROGRA~1\McAfee.com\Agent\mcagent.exe<br>C:\HJT\HijackThis.exe<br><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhgh.dll<br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg<br>O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: Keyboard Express 3.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - &raquo;<small>https</small>://<A HREF="https://components.viewpoint.com/adobe/MTSInstallers/MetaStream3.cab">components.viewpoint.com/adobe/M&middot;&middot;&middot;eam3.cab</A><br>O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - &raquo;<A HREF="http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab" >bin.mcafee.com/molbin/Shared/Com&middot;&middot;&middot;tl32.cab</A><br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {53F63B36-5DB3-4C19-A8AB-2CB9AE7D57F7} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB" >www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120431258104" >update.microsoft.com/windowsupda&middot;&middot;&middot;31258104</A><br>O16 - DPF: {6EA0A4DB-0B94-40E1-9165-54F5694C19EC} (CFM2004noruna.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB" >www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB</A><br>O16 - DPF: {73989DDC-D9DE-47F7-B262-6FE39DC70BC2} (CFM2004Turbo.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB" >www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB</A><br>O16 - DPF: {797FA1DD-30E7-4093-A892-E8C2A556A583} (CFM2005TurboDMCrs.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMCrs.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;MCrs.CAB</A><br>O16 - DPF: {A49DFBB5-A3BB-45FE-BA2F-34890123C47F} (CFM2005TurboDMC.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMC.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;oDMC.CAB</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) - <br>O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) - <br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - &raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {DB1C1859-F90A-47DE-8934-FB8CECE8E6F3} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmodnorun.CAB" >www.racelm.com/rlm/cfmaxftp/cfmp&middot;&middot;&middot;orun.CAB</A><br>O16 - DPF: {DDC38B48-52B8-4FD6-BBB3-2FC2C136FD0D} (CFM2004a.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004a.CAB" >www.racelm.com/rlm/cfm2004/cfm2004a.CAB</A><br>O16 - DPF: {F461205D-ABDC-42FE-B2E2-AFD4600B905E} (MASHControl Class) - &raquo;<A HREF="http://www.amiuptodate.com/vsc/mvt/bin/1,0,0,7/mash.cab" >www.amiuptodate.com/vsc/mvt/bin/&middot;&middot;&middot;mash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{6A551B11-F6EE-4A28-8E26-0BAB4D056B63}: NameServer = 64.166.172.8,206.13.29.12<br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll<br>O20 - Winlogon Notify: jkhgh - C:\WINDOWS\SYSTEM32\jkhgh.dll<br>O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe<br>O23 - Service: GEARSecurity_BackUp - Unknown owner - C:\WINDOWS\SYSTEM32\GEARSEC.EXE (file missing)<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br>O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br><br>After reboot:<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 7:35:14 PM, on 9/20/2005<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>C:\WINDOWS\system32\crypserv.exe<br>c:\program files\mcafee.com\agent\mcdetect.exe<br>c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br>C:\WINDOWS\system32\nvsvc32.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>C:\WINDOWS\System32\MsPMSPSv.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>C:\WINDOWS\system32\CTHELPER.EXE<br>C:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\HJT\HijackThis.exe<br><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br>O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhgh.dll<br>O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} - C:\WINDOWS\system32\ddcax.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll<br>O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r<br>O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>O4 - HKLM\..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg<br>O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE<br>O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE<br>O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe<br>O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask<br>O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: Keyboard Express 3.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000<br>O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - &raquo;<small>https</small>://<A HREF="https://components.viewpoint.com/adobe/MTSInstallers/MetaStream3.cab">components.viewpoint.com/adobe/M&middot;&middot;&middot;eam3.cab</A><br>O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - &raquo;<A HREF="http://bin.mcafee.com/molbin/Shared/ComCtl32/6,0,80,22/ComCtl32.cab" >bin.mcafee.com/molbin/Shared/Com&middot;&middot;&middot;tl32.cab</A><br>O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/Shared/MGBrwFld.cab" >download.mcafee.com/molbin/Share&middot;&middot;&middot;wFld.cab</A><br>O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - &raquo;<A HREF="http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe" >a1540.g.akamai.net/7/1540/52/200&middot;&middot;&middot;ller.exe</A><br>O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;sctl.cab</A><br>O16 - DPF: {53F63B36-5DB3-4C19-A8AB-2CB9AE7D57F7} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB" >www.racelm.com/rlm/cfmaxftp/cfmprojmod.CAB</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120431258104" >update.microsoft.com/windowsupda&middot;&middot;&middot;31258104</A><br>O16 - DPF: {6EA0A4DB-0B94-40E1-9165-54F5694C19EC} (CFM2004noruna.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB" >www.racelm.com/rlm/cfm2004/cfm2004noruna.CAB</A><br>O16 - DPF: {73989DDC-D9DE-47F7-B262-6FE39DC70BC2} (CFM2004Turbo.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB" >www.racelm.com/rlm/cfmturbo/cfm2004turbo.CAB</A><br>O16 - DPF: {797FA1DD-30E7-4093-A892-E8C2A556A583} (CFM2005TurboDMCrs.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMCrs.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;MCrs.CAB</A><br>O16 - DPF: {A49DFBB5-A3BB-45FE-BA2F-34890123C47F} (CFM2005TurboDMC.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmturbo/cfm2005turboDMC.CAB" >www.racelm.com/rlm/cfmturbo/cfm2&middot;&middot;&middot;oDMC.CAB</A><br>O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - &raquo;<A HREF="http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab" >download.mcafee.com/molbin/share&middot;&middot;&middot;dmgr.cab</A><br>O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) - <br>O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) - <br>O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - &raquo;<A HREF="http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab" >photos.yahoo.com/ocx/us/yexplorer1_9us.cab</A><br>O16 - DPF: {DB1C1859-F90A-47DE-8934-FB8CECE8E6F3} (CFM_AXFTP_MOD.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfmaxftp/cfmprojmodnorun.CAB" >www.racelm.com/rlm/cfmaxftp/cfmp&middot;&middot;&middot;orun.CAB</A><br>O16 - DPF: {DDC38B48-52B8-4FD6-BBB3-2FC2C136FD0D} (CFM2004a.UserControl1) - &raquo;<A HREF="http://www.racelm.com/rlm/cfm2004/cfm2004a.CAB" >www.racelm.com/rlm/cfm2004/cfm2004a.CAB</A><br>O16 - DPF: {F461205D-ABDC-42FE-B2E2-AFD4600B905E} (MASHControl Class) - &raquo;<A HREF="http://www.amiuptodate.com/vsc/mvt/bin/1,0,0,7/mash.cab" >www.amiuptodate.com/vsc/mvt/bin/&middot;&middot;&middot;mash.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{6A551B11-F6EE-4A28-8E26-0BAB4D056B63}: NameServer = 64.166.172.8,206.13.29.12<br>O20 - Winlogon Notify: ddcax - C:\WINDOWS\system32\ddcax.dll<br>O20 - Winlogon Notify: jkhgh - C:\WINDOWS\SYSTEM32\jkhgh.dll<br>O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe<br>O23 - Service: GEARSecurity_BackUp - Unknown owner - C:\WINDOWS\SYSTEM32\GEARSEC.EXE (file missing)<br>O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe<br>O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe<br>O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br><br>Adaware scan:<br><br>Ad-Aware SE Build 1.06r1<br>Logfile Created on:Tuesday, September 20, 2005 5:14:47 PM<br>Created with Ad-Aware SE Personal, free for private use.<br>Using definitions file:SE1R67 20.09.2005<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>References detected during the scan:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>Other(TAC index:5):1 total references<br>WinFixer(TAC index:3):38 total references<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Definition File:<br>=========================<br>Definitions File Loaded:<br>Reference Number : SE1R67 20.09.2005<br>Internal build : 79<br>File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref<br>File size : 524443 Bytes<br>Total size : 1576182 Bytes<br>Signature data size : 1543004 Bytes<br>Reference data size : 32666 Bytes<br>Signatures total : 43850<br>CSI Fingerprints total : 1047<br>CSI data size : 37307 Bytes<br>Target categories : 15<br>Target families : 746<br><br>Memory + processor status:<br>==========================<br>Number of processors : 1<br>Processor architecture : Intel Pentium IV<br>Memory available:48 %<br>Total physical memory:523760 kb<br>Available physical memory:247692 kb<br>Total page file size:1279564 kb<br>Available on page file:1052256 kb<br>Total virtual memory:2097024 kb<br>Available virtual memory:2045144 kb<br>OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)<br><br>Ad-Aware SE Settings<br>===========================<br>Set : Search for low-risk threats<br>Set : Safe mode (always request confirmation)<br>Set : Scan active processes<br>Set : Scan registry<br>Set : Deep-scan registry<br>Set : Scan my IE Favorites for banned URLs<br>Set : Scan within archives<br>Set : Scan my Hosts file<br><br>Extended Ad-Aware SE Settings<br>===========================<br>Set : Unload recognized processes & modules during scan<br>Set : Obtain command line of scanned processes<br>Set : Scan registry for all users instead of current user only<br>Set : Always try to unload modules before deletion<br>Set : During removal, unload Explorer and IE if necessary<br>Set : Let Windows remove files in use at next reboot<br>Set : Delete quarantined objects after restoring<br>Set : Include basic Ad-Aware settings in log file<br>Set : Include additional Ad-Aware settings in log file<br>Set : Include reference summary in log file<br>Set : Include alternate data stream details in log file<br>Set : Play sound at scan completion if scan locates critical objects<br><br>9-20-2005 5:14:47 PM - Scan started. (Custom mode)<br><br>Listing running processes<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>#:1 [smss.exe]<br>    ModuleName         : \SystemRoot\System32\smss.exe<br>    Command Line       : n/a<br>    ProcessID          : 588<br>    ThreadCreationTime : 9-20-2005 11:50:27 PM<br>    BasePriority       : Normal<br><br>#:2 [winlogon.exe]<br>    ModuleName         : \??\C:\WINDOWS\system32\winlogon.exe<br>    Command Line       : n/a<br>    ProcessID          : 672<br>    ThreadCreationTime : 9-20-2005 11:50:34 PM<br>    BasePriority       : High<br><br>#:3 [services.exe]<br>    ModuleName         : C:\WINDOWS\system32\services.exe<br>    Command Line       : n/a<br>    ProcessID          : 716<br>    ThreadCreationTime : 9-20-2005 11:50:35 PM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Services and Controller app<br>    InternalName       : services.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : services.exe<br><br>#:4 [lsass.exe]<br>    ModuleName         : C:\WINDOWS\system32\lsass.exe<br>    Command Line       : n/a<br>    ProcessID          : 728<br>    ThreadCreationTime : 9-20-2005 11:50:35 PM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : LSA Shell (Export Version)<br>    InternalName       : lsass.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : lsass.exe<br><br>#:5 [svchost.exe]<br>    ModuleName         : C:\WINDOWS\system32\svchost.exe<br>    Command Line       : n/a<br>    ProcessID          : 884<br>    ThreadCreationTime : 9-20-2005 11:50:36 PM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:6 [svchost.exe]<br>    ModuleName         : C:\WINDOWS\System32\svchost.exe<br>    Command Line       : n/a<br>    ProcessID          : 996<br>    ThreadCreationTime : 9-20-2005 11:50:36 PM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:7 [spoolsv.exe]<br>    ModuleName         : C:\WINDOWS\system32\spoolsv.exe<br>    Command Line       : n/a<br>    ProcessID          : 1268<br>    ThreadCreationTime : 9-20-2005 11:50:37 PM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)<br>    ProductVersion     : 5.1.2600.2696<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Spooler SubSystem App<br>    InternalName       : spoolsv.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : spoolsv.exe<br><br>#:8 [cdac11ba.exe]<br>    ModuleName         : C:\WINDOWS\System32\drivers\CDAC11BA.EXE<br>    Command Line       : n/a<br>    ProcessID          : 1412<br>    ThreadCreationTime : 9-20-2005 11:50:43 PM<br>    BasePriority       : Normal<br>    FileVersion        : 4.20.030<br>    ProductVersion     : 4.20.030 Windows NT 2002/01/29<br>    ProductName        : SafeCast Windows NT<br>    CompanyName        : Macrovision<br>    FileDescription    : Macrovision RTS Service<br>    InternalName       : CDANTSRV<br>    LegalCopyright     : Copyright (c) 1998-2003 Macrovision Corp.<br>    OriginalFilename   : CDANTSRV.EXE<br>    Comments           : StringFileInfo: U.S. English<br><br>#:9 [crypserv.exe]<br>    ModuleName         : C:\WINDOWS\system32\crypserv.exe<br>    Command Line       : n/a<br>    ProcessID          : 1432<br>    ThreadCreationTime : 9-20-2005 11:50:43 PM<br>    BasePriority       : High<br>    FileVersion        : 5.4.0<br>    ProductVersion     : 5.4<br>    ProductName        : CrypKey Software Licensing System<br>    CompanyName        : Kenonic Controls Ltd.<br>    FileDescription    : CrypKey NT Service<br>    InternalName       : crypserv<br>    LegalCopyright     : Copyright &copy; 2000<br>    LegalTrademarks    : CrypKey<br>    OriginalFilename   : crypserv.exe<br>    Comments           : Operates in all directories, not just configured ones. Directory configuration only used for fille clean up and uninstall. 0/3 fixed problem with other partitions. 0/6 fixed problem with short paths<br><br>#:10 [mcdetect.exe]<br>    ModuleName         : c:\program files\mcafee.com\agent\mcdetect.exe<br>    Command Line       : n/a<br>    ProcessID          : 1484<br>    ThreadCreationTime : 9-20-2005 11:50:44 PM<br>    BasePriority       : Normal<br>    FileVersion        : 6, 0, 0, 7<br>    ProductVersion     : 6, 0, 0, 0<br>    ProductName        : McAfee SecurityCenter<br>    CompanyName        : McAfee, Inc<br>    FileDescription    : McAfee WSC Integration Service<br>    InternalName       : McDetect<br>    LegalCopyright     : Copyright &copy; 2005 McAfee, Inc.<br>    OriginalFilename   : McDetect.exe<br>    Comments           : McAfee WSC Integration Service<br><br>#:11 [mcshield.exe]<br>    ModuleName         : c:\PROGRA~1\mcafee.com\vso\mcshield.exe<br>    Command Line       : n/a<br>    ProcessID          : 1512<br>    ThreadCreationTime : 9-20-2005 11:50:44 PM<br>    BasePriority       : High<br><br>#:12 [mctskshd.exe]<br>    ModuleName         : c:\PROGRA~1\mcafee.com\agent\mctskshd.exe<br>    Command Line       : n/a<br>    ProcessID          : 1584<br>    ThreadCreationTime : 9-20-2005 11:50:45 PM<br>    BasePriority       : Normal<br>    FileVersion        : 6, 0, 0, 13<br>    ProductVersion     : 6, 0, 0, 0<br>    ProductName        : McAfee SecurityCenter<br>    CompanyName        : McAfee, Inc<br>    FileDescription    : McAfee Task Scheduler<br>    InternalName       : McTskshd<br>    LegalCopyright     : Copyright &copy; 2005 McAfee, Inc.<br>    OriginalFilename   : McTskshd.exe<br><br>#:13 [mdm.exe]<br>    ModuleName         : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe<br>    Command Line       : n/a<br>    ProcessID          : 1624<br>    ThreadCreationTime : 9-20-2005 11:50:47 PM<br>    BasePriority       : Normal<br>    FileVersion        : 7.00.9466<br>    ProductVersion     : 7.00.9466<br>    ProductName        : Microsoft&reg; Visual Studio .NET<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Machine Debug Manager<br>    InternalName       : mdm.exe<br>    LegalCopyright     : &copy; Microsoft Corporation.  All rights reserved.<br>    OriginalFilename   : mdm.exe<br><br>#:14 [nvsvc32.exe]<br>    ModuleName         : C:\WINDOWS\system32\nvsvc32.exe<br>    Command Line       : n/a<br>    ProcessID          : 1752<br>    ThreadCreationTime : 9-20-2005 11:50:52 PM<br>    BasePriority       : Normal<br>    FileVersion        : 6.14.10.7189<br>    ProductVersion     : 6.14.10.7189<br>    ProductName        : NVIDIA Driver Helper Service, Version 71.89<br>    CompanyName        : NVIDIA Corporation<br>    FileDescription    : NVIDIA Driver Helper Service, Version 71.89<br>    InternalName       : NVSVC<br>    LegalCopyright     : (C) NVIDIA Corporation. All rights reserved.<br>    OriginalFilename   : nvsvc32.exe<br><br>#:15 [svchost.exe]<br>    ModuleName         : C:\WINDOWS\System32\svchost.exe<br>    Command Line       : n/a<br>    ProcessID          : 1816<br>    ThreadCreationTime : 9-20-2005 11:50:53 PM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:16 [wrsssdk.exe]<br>    ModuleName         : C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe<br>    Command Line       : n/a<br>    ProcessID          : 1896<br>    ThreadCreationTime : 9-20-2005 11:50:56 PM<br>    BasePriority       : Normal<br>    FileVersion        : 1,0,4,289<br>    ProductVersion     : 1, 0<br>    ProductName        : Spy Sweeper SDK<br>    CompanyName        : Webroot Software, Inc.<br>    FileDescription    : Spy Sweeper SDK<br>    LegalCopyright     : Copyright (C) 2002 - 2004, All Rights Reserved.<br>    LegalTrademarks    : Spy Sweeper is a trademark of Webroot Software, Inc.<br>    OriginalFilename   : SpySweeper.exe<br><br>#:17 [mspmspsv.exe]<br>    ModuleName         : C:\WINDOWS\System32\MsPMSPSv.exe<br>    Command Line       : n/a<br>    ProcessID          : 176<br>    ThreadCreationTime : 9-20-2005 11:50:59 PM<br>    BasePriority       : Normal<br>    FileVersion        : 7.01.00.3055<br>    ProductVersion     : 7.01.00.3055<br>    ProductName        : Microsoft (R) DRM<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : WMDM PMSP Service<br>    InternalName       : MSPMSPSV.EXE<br>    LegalCopyright     : Copyright (C) Microsoft Corp. 1981-2000<br>    OriginalFilename   : MSPMSPSV.EXE<br><br>#:18 [explorer.exe]<br>    ModuleName         : C:\WINDOWS\Explorer.EXE<br>    Command Line       : C:\WINDOWS\Explorer.EXE<br>    ProcessID          : 916<br>    ThreadCreationTime : 9-21-2005 12:08:44 AM<br>    BasePriority       : Normal<br>    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 6.00.2900.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Windows Explorer<br>    InternalName       : explorer<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : EXPLORER.EXE<br><br>#:19 [swtrayv4.exe]<br>    ModuleName         : C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe<br>    Command Line       : "C:\PROGRA~1\MICROS~4\GAMECO~1\common\swtrayv4.exe" <br>    ProcessID          : 792<br>    ThreadCreationTime : 9-21-2005 12:08:49 AM<br>    BasePriority       : Normal<br>    FileVersion        : 4.02.145<br>    ProductVersion     : 4.02.145<br>    ProductName        : Microsoft Game Controller Software<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : MS SideWinder Tray Application<br>    InternalName       : MS SideWinder Tray Application<br>    LegalCopyright     : Copyright &copy; 1995-1999 Microsoft Corporation<br>    OriginalFilename   : SWTRAYV4.EXE<br><br>#:20 [hplamp.exe]<br>    ModuleName         : C:\SCANJET\PrecisionScanPro\HPLamp.exe<br>    Command Line       : "C:\SCANJET\PrecisionScanPro\HPLamp.exe" <br>    ProcessID          : 200<br>    ThreadCreationTime : 9-21-2005 12:08:49 AM<br>    BasePriority       : Normal<br><br>#:21 [em_exec.exe]<br>    ModuleName         : C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE<br>    Command Line       : "C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" <br>    ProcessID          : 1044<br>    ThreadCreationTime : 9-21-2005 12:08:49 AM<br>    BasePriority       : Normal<br>    FileVersion        : 9.42.57<br>    ProductVersion     : 9.42.1<br>    ProductName        : MouseWare<br>    CompanyName        : Logitech Inc.                    <br>    FileDescription    : Control Center<br>    InternalName       : EM_EXEC<br>    LegalCopyright     : Copyright &copy; Logitech Inc. 1987-2001.<br>    LegalTrademarks    : Logitech&reg; and MouseWare&reg; are registered trademarks of Logitech Inc.<br>    OriginalFilename   : EM_EXEC.CPP<br>    Comments           : Created by the MouseWare Team                                        <br><br>#:22 [cthelper.exe]<br>    ModuleName         : C:\WINDOWS\system32\CTHELPER.EXE<br>    Command Line       : "C:\WINDOWS\system32\CTHELPER.EXE" <br>    ProcessID          : 1124<br>    ThreadCreationTime : 9-21-2005 12:08:50 AM<br>    BasePriority       : Normal<br>    FileVersion        : 1, 0, 0, 2<br>    ProductVersion     : 1, 0, 0, 2<br>    ProductName        : CtHelper Application<br>    CompanyName        : Creative Technology Ltd<br>    FileDescription    : CtHelper Application<br>    InternalName       : CtHelper<br>    LegalCopyright     : Copyright (C) 2002<br>    OriginalFilename   : CtHelper.EXE<br><br>#:23 [mcagent.exe]<br>    ModuleName         : C:\PROGRA~1\mcafee.com\agent\mcagent.exe<br>    Command Line       : "C:\PROGRA~1\mcafee.com\agent\mcagent.exe" <br>    ProcessID          : 912<br>    ThreadCreationTime : 9-21-2005 12:08:55 AM<br>    BasePriority       : Normal<br>    FileVersion        : 6, 0, 0, 3<br>    ProductVersion     : 6, 0, 0, 0<br>    ProductName        : McAfee SecurityCenter<br>    CompanyName        : McAfee, Inc<br>    FileDescription    : McAfee SecurityCenter Agent<br>    InternalName       : mcagent<br>    LegalCopyright     : Copyright &copy; 2005 McAfee, Inc.<br>    OriginalFilename   : mcagent.exe<br><br>#:24 [mcvsshld.exe]<br>    ModuleName         : C:\Program Files\McAfee.com\VSO\mcvsshld.exe<br>    Command Line       : "C:\Program Files\McAfee.com\VSO\mcvsshld.exe" <br>    ProcessID          : 1528<br>    ThreadCreationTime : 9-21-2005 12:08:55 AM<br>    BasePriority       : Normal<br>    FileVersion        : 10, 0, 0, 22<br>    ProductVersion     : 10, 0, 0, 0<br>    ProductName        : McAfee VirusScan<br>    CompanyName        : McAfee, Inc.<br>    FileDescription    : McAfee VirusScan ActiveShield Resource<br>    InternalName       : McVsShld<br>    LegalCopyright     : Copyright &copy; 2005 McAfee, Inc. All Rights Reserved.<br>    OriginalFilename   : McVsShld.exe<br>    Comments           : McAfee VirusScan ActiveShield Resource<br><br>#:25 [oasclnt.exe]<br>    ModuleName         : C:\Program Files\McAfee.com\VSO\oasclnt.exe<br>    Command Line       : "C:\Program Files\McAfee.com\VSO\oasclnt.exe" <br>    ProcessID          : 1848<br>    ThreadCreationTime : 9-21-2005 12:08:56 AM<br>    BasePriority       : Normal<br>    FileVersion        : 10, 0, 0, 24<br>    ProductVersion     : 10, 0, 0, 0<br>    ProductName        : McAfee VirusScan<br>    CompanyName        : McAfee, Inc.<br>    FileDescription    : McAfee VirusScan OAS Client<br>    InternalName       : OasClnt<br>    LegalCopyright     : Copyright &copy; 2005 McAfee, Inc. All Rights Reserved.<br>    OriginalFilename   : OasClnt.exe<br>    Comments           : McAfee VirusScan OAS Client<br><br>#:26 [ctfmon.exe]<br>    ModuleName         : C:\WINDOWS\system32\ctfmon.exe<br>    Command Line       : "C:\WINDOWS\system32\ctfmon.exe" <br>    ProcessID          : 1164<br>    ThreadCreationTime : 9-21-2005 12:09:03 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : CTF Loader<br>    InternalName       : CTFMON<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : CTFMON.EXE<br><br>#:27 [mcvsescn.exe]<br>    ModuleName         : c:\progra~1\mcafee.com\vso\mcvsescn.exe<br>    Command Line       : "c:\progra~1\mcafee.com\vso\mcvsescn.exe" /disabled<br>    ProcessID          : 772<br>    ThreadCreationTime : 9-21-2005 12:09:05 AM<br>    BasePriority       : Normal<br>    FileVersion        : 10, 0, 0, 20<br>    ProductVersion     : 10, 0, 0, 0<br>    ProductName        : McAfee VirusScan<br>    CompanyName        : McAfee, Inc.<br>    FileDescription    : McAfee VirusScan E-mail Scan Module<br>    InternalName       : mcvsescn<br>    LegalCopyright     : Copyright &copy; 2005 McAfee, Inc. All Rights Reserved.<br>    OriginalFilename   : mcvsescn.EXE<br>    Comments           : McAfee VirusScan E-mail Scan Module<br><br>#:28 [keyexp.exe]<br>    ModuleName         : C:\PROGRA~1\KEYBOA~1\keyexp.exe<br>    Command Line       : "C:\PROGRA~1\KEYBOA~1\keyexp.exe" <br>    ProcessID          : 2060<br>    ThreadCreationTime : 9-21-2005 12:09:07 AM<br>    BasePriority       : Normal<br>    FileVersion        : 3.0.5.1<br>    ProductVersion     : 3.0<br>    ProductName        : Keyboard Express<br>    CompanyName        : Insight Software Solutions<br>    FileDescription    : Keyboard Express, a Windows macro program<br>    InternalName       : keyexp.exe<br>    LegalCopyright     : (c) 1996-2002 Insight Software Solutions, Inc.<br>    LegalTrademarks    : Keyboard Express<br>    OriginalFilename   : keyexp.exe<br>    Comments           : Keyboard Express is a Windows macro utility designed to aid the user in automating repetitive tasks. Keyboard Express is a Trademark of Insight Software Solutions, Inc.<br><br>#:29 [svchost.exe]<br>    ModuleName         : C:\WINDOWS\System32\svchost.exe<br>    Command Line       : n/a<br>    ProcessID          : 2336<br>    ThreadCreationTime : 9-21-2005 12:09:21 AM<br>    BasePriority       : Normal<br>    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)<br>    ProductVersion     : 5.1.2600.2180<br>    ProductName        : Microsoft&reg; Windows&reg; Operating System<br>    CompanyName        : Microsoft Corporation<br>    FileDescription    : Generic Host Process for Win32 Services<br>    InternalName       : svchost.exe<br>    LegalCopyright     : &copy; Microsoft Corporation. All rights reserved.<br>    OriginalFilename   : svchost.exe<br><br>#:30 [msiexec.exe]<br>    ModuleName         : C:\WINDOWS\system32\msiexec.exe<br>    Command Line       : n/a<br>    ProcessID          : 3156<br>    ThreadCreationTime : 9-21-2005 12:11:29 AM<br>    BasePriority       : Normal<br><br>#:31 [ad-aware.exe]<br>    ModuleName         : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe<br>    Command Line       : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" <br>    ProcessID          : 3596<br>    ThreadCreationTime : 9-21-2005 12:14:36 AM<br>    BasePriority       : Normal<br>    FileVersion        : 6.2.0.236<br>    ProductVersion     : SE 106<br>    ProductName        : Lavasoft Ad-Aware SE<br>    CompanyName        : Lavasoft Sweden<br>    FileDescription    : Ad-Aware SE Core application<br>    InternalName       : Ad-Aware.exe<br>    LegalCopyright     : Copyright &copy; Lavasoft AB Sweden<br>    OriginalFilename   : Ad-Aware.exe<br>    Comments           : All Rights Reserved<br><br>Memory scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 0<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : appid\{8c65aef6-e413-4314-815b-82717a3f1603}<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : appid\checkproduct2.dll<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{c427b3e3-28dc-4001-9590-d99b6776119b}<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{c427b3e3-28dc-4001-9590-d99b6776119b}<br>    Value              : AppID<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : interface\{4f79d1c5-24f9-4e59-8022-604d4b41d5ca}<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : typelib\{30ed49a5-ca6c-4918-b5f3-5e6818c91d8b}<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : appid\{4d05a335-1a1c-46b3-bcff-7f25b326895c}<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{328ba26a-1619-47ee-a37d-7d7a6ab1b000}<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{328ba26a-1619-47ee-a37d-7d7a6ab1b000}<br>    Value              : AppID<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : interface\{27967fbc-694b-41a6-8cce-30e59292350e}<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : interface\{c0a3779c-3345-4150-bd63-c399eb32661e}<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : typelib\{4d05a335-1a1c-46b3-bcff-7f25b326895c}<br><br>Registry Scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 12<br>Objects found so far: 12<br><br>Started deep registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : ({C427B3E3-28DC-4001-9590-D99B6776119B})<br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : CheckProduct2.CheckProduct<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : ({C427B3E3-28DC-4001-9590-D99B6776119B})<br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : CheckProduct2.CheckProduct.1<br><br>Deep registry scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 2<br>Objects found so far: 14<br><br>Started Tracking Cookie scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Tracking cookie scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 14<br><br>Deep scanning and examining files (C:)<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> WinFixer Object Recognized!<br>    Type               : File<br>    Data               : PCheck.dll<br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Object             : C:\Program Files\Common Files\WinSoftware\<br>    FileVersion        : 1.0.4.0<br>    ProductVersion     : 1.0.4.0<br>    ProductName        : Products Checker<br>    CompanyName        : WinSoftware, Ltd.<br>    FileDescription    : Products Checker<br>    InternalName       : PCheck.dll<br>    LegalCopyright     : 2005 (c) WinSoftware, Ltd. All rights reserved.<br>    OriginalFilename   : PCheck.dll<br><br> WinFixer Object Recognized!<br>    Type               : File<br>    Data               : WFF.exe<br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Object             : C:\Program Files\Common Files\WinSoftware\<br>    FileVersion        : 1.0.1.0<br>    ProductVersion     : 1.0.1.0<br><br> WinFixer Object Recognized!<br>    Type               : File<br>    Data               : WFF.sys<br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Object             : C:\WINDOWS\system32\drivers\<br>    FileVersion        : 1.0.2.0<br>    ProductVersion     : 1.0.2.0<br>    CompanyName        : WinSoftware Ltd<br>    FileDescription    : File Creation Filter Driver<br>    LegalCopyright     : Copyright (C) WinSoftware Ltd 2005<br>    OriginalFilename   : wff.sys<br><br>Disk Scan Result for C:\<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 17<br><br>Scanning Hosts file......<br>Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Hosts file scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>0 entries scanned.<br>New critical objects:0<br>Objects found so far: 17<br><br>Performing conditional scans...<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : appid\filecreationfilter.dll<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : vapfm.creationnotifier<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : vapfm.creationnotifier.1<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_CURRENT_USER<br>    Object             : software\winsoftware<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\winsoftware<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\enum\root\legacy_df_kmd<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\services\wff<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\services\wff<br>    Value              : Start<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\services\wff<br>    Value              : ErrorControl<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\services\wff<br>    Value              : Tag<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\services\wff<br>    Value              : ImagePath<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\services\wff<br>    Value              : DisplayName<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\controlset001\services\wff<br>    Value              : Group<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\enum\root\legacy_df_kmd<br><br> WinFixer Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\services\wff<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\services\wff<br>    Value              : Start<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\services\wff<br>    Value              : ErrorControl<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\services\wff<br>    Value              : Tag<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\services\wff<br>    Value              : ImagePath<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\services\wff<br>    Value              : DisplayName<br><br> WinFixer Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 3<br>    Category           : Misc<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : system\currentcontrolset\services\wff<br>    Value              : Group<br><br> Other Object Recognized!<br>    Type               : File<br>    Data               : WFF.EXE-1D35F413.pf<br>    TAC Rating         : 7<br>    Category           : Malware<br>    Comment            : <br>    Object             : C:\WINDOWS\prefetch\<br><br>Conditional scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 22<br>Objects found so far: 39<br><br>5:32:14 PM Scan Complete<br><br>Summary Of This Scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>Total scanning time:00:17:27.125<br>Objects scanned:185490<br>Objects identified:40<br>Objects ignored:0<br>New critical objects:40<br><br>Spysweeper Log:<br><br>********<br>6:44 PM: |&middot;&middot;&middot;  Start of Session, Tuesday, September 20, 2005  &middot;&middot;&middot;|<br>6:44 PM: Spy Sweeper started<br>6:44 PM: Sweep initiated using definitions version 537<br>6:44 PM: Starting Memory Sweep<br>6:47 PM: Memory Sweep Complete, Elapsed Time: 00:02:44<br>6:47 PM: Starting Registry Sweep<br>6:47 PM:   Found Adware: winantispyware 2005<br>6:47 PM:   HKU\S-1-5-21-2000478354-1580436667-854245398-1009\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\winfixer 2005\  (1 subtraces) (ID = 543254)<br>6:47 PM:   Found Adware: virtumonde<br>6:47 PM:   HKCR\msevents.msevents\  (5 subtraces) (ID = 749130)<br>6:47 PM:   HKCR\msevents.msevents.1\  (3 subtraces) (ID = 749136)<br>6:47 PM:   HKLM\software\classes\msevents.msevents\  (5 subtraces) (ID = 749153)<br>6:47 PM:   HKLM\software\classes\msevents.msevents.1\  (3 subtraces) (ID = 749157)<br>6:47 PM:   HKLM\system\currentcontrolset\control\class\{29ae0e04-08b8-4d2f-bfbe-83fb0ec73bb7}\  (3 subtraces) (ID = 795420)<br>6:47 PM:   HKU\WRSS_Profile_S-1-5-21-2000478354-1580436667-854245398-1006\software\winsoftware\winantispyware 2005\  (17 subtraces) (ID = 797676)<br>6:47 PM:   HKCR\clsid\{52b1dfc7-aafc-4362-b103-868b0683c697}\  (12 subtraces) (ID = 812324)<br>6:47 PM:   HKLM\software\classes\clsid\{52b1dfc7-aafc-4362-b103-868b0683c697}\  (12 subtraces) (ID = 812338)<br>6:47 PM:   HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{52b1dfc7-aafc-4362-b103-868b0683c697}\ (ID = 812351)<br>6:47 PM: Registry Sweep Complete, Elapsed Time:00:00:14<br>6:47 PM: Starting Cookie Sweep<br>6:47 PM:   Found Spy Cookie: reliablestats cookie<br>6:47 PM:   chuck@stats1.reliablestats[2].txt (ID = 3254)<br>6:47 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00<br>6:47 PM: Starting File Sweep<br>6:47 PM:   c:\program files\common files\winsoftware (ID = -2147476682)<br>7:04 PM:   setup.exe (ID = 150640)<br>7:08 PM:   winantispyware2005setup.exe (ID = 150641)<br>7:09 PM:   df_kmd.sys (ID = 146298)<br>7:09 PM: File Sweep Complete, Elapsed Time: 00:22:03<br>7:09 PM: Full Sweep has completed.  Elapsed time 00:25:06<br>7:09 PM: Traces Found: 76<br>7:10 PM: Removal process initiated<br>7:10 PM:   Quarantining All Traces: winantispyware 2005<br>7:10 PM:   Quarantining All Traces: virtumonde<br>7:10 PM:   Quarantining All Traces: reliablestats cookie<br>7:10 PM: Removal process completed.  Elapsed time 00:00:23<br>********]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14408854</guid>
<pubDate>Tue, 20 Sep 2005 22:54:27 EDT</pubDate>
</item>

</channel>
</rss>
