This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Blue Screen with Kmxcf.sys error

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:23:23 PM, on 6/2/2009
Platform: Windows XP SP2 (WinNT

5.01.2600)
MSIE: Internet Explorer v7.00

(7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows

Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

Cfg.exe
C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

FwHlp.exe
C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

Pol.exe
C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

Agent.exe
C:\Program Files\Adobe\Photoshop

Elements

4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common

Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Ashampoo\Ashampoo

Magical Defrag\bin\aDefragService.exe
C:\Program

Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\eTrust Internet

Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\Program Files\Ashampoo\Ashampoo

Magical

Defrag\bin\defragActivityMonitor.exe
C:\Program

Files\CA\SharedComponents\PPRT\bin\ITMRT

SVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\Program Files\Dell Support

Center\bin\sprtsvc.exe
C:\Program Files\Spyware

Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo

Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\CA\eTrust Internet

Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Pure

Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust Internet

Security Suite\CA Personal

Firewall\capfsem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI

Control Panel\atiptaxx.exe
C:\Program Files\Windows

Defender\MSASCui.exe
C:\Program Files\HP\HP Software

Update\HPWuSchd2.exe
C:\Program Files\Logitech\G-series

Software\LGDCore.exe
C:\Program Files\Logitech\G-series

Software\LCDMon.exe
C:\Program Files\CA\eTrust Internet

Security Suite\cctray\cctray.exe
C:\Program Files\CA\eTrust Internet

Security Suite\CA

Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\eTrust Internet

Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\eTrust Internet

Security Suite\CA Personal

Firewall\capfasem.exe
C:\Program

Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Pure

Networks Shared\Platform\nmctxth.exe
C:\Program Files\Logitech\G-series

Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series

Software\Applets\LCDCountdown\LCDCountdo

wn.exe
C:\Program Files\Pure Networks\Network

Magic\nmapp.exe
C:\Program Files\Logitech\G-series

Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Logitech\G-series

Software\Applets\LCDMedia.exe
C:\Program Files\Dell Support

Center\bin\sprtcmd.exe
C:\Program Files\CA\eTrust Internet

Security Suite\ccprovsp.exe
C:\Program Files\CA\eTrust Internet

Security Suite\CA

Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\eTrust Internet

Security Suite\CA

Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program

Files\Google\GoogleToolbarNotifier\Googl

eToolbarNotifier.exe
C:\Program Files\Microsoft

ActiveSync\WCESCOMM.EXE
C:\Program Files\Ashampoo\Ashampoo

Magical Defrag\bin\aDefragCtrl.exe
C:\Program Files\D-Link\AirPlusG

DWL-G122\AirPlus.exe
C:\Program Files\Digital Line

Detect\DLG.exe
C:\Program Files\HP\Digital

Imaging\bin\hpqtra08.exe
C:\Program

Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital

Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital

Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital

Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet

Explorer\iexplore.exe
C:\Program Files\Trend

Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\HPZinw12.exe

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page =

https://cmcu.org/
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=5

4896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=5

4896
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://www.yahoo.com
R1 -

HKCU\Software\Microsoft\Windows\CurrentV

ersion\Internet Settings,ProxyOverride =

http://localhost;*.local
O1 - Hosts: indows.
O2 - BHO: (no name) -

{02478D38-C3F9-4efb-9B51-7695ECA05670} -

(no file)
O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper

.dll
O2 - BHO: Spybot-S&D IE Protection -

{53707962-6F74-2D53-2644-206D7942484F} -

C:\Program Files\Spybot - Search &

Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) -

{7E853D72-626A-48EC-A868-BA8D5E23E045} -

(no file)
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} -

C:\Program Files\Google\Google

Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO -

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -

C:\Program

Files\Google\GoogleToolbarNotifier\5.1.1

309.3572\swg.dll
O2 - BHO: Google Dictionary Compression

sdch -

{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -

C:\Program Files\Google\Google

Toolbar\Component\fastsearch_A8904FB862B

D9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper

- {DBC80044-A445-435b-BC74-9C25C1C588A9}

- C:\Program

Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -

{E7E6F031-17CE-4C07-BC86-EABFE594F69C} -

C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_pl

ugin.dll
O2 - BHO: Kwyshell MidpX BHO -

{EBE9E2B5-B526-48BC-AD46-687263EDCB0E} -

C:\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: (no name) -

{BA52B914-B692-46c4-B683-905236F6F655} -

(no file)
O3 - Toolbar: Easy-WebPrint -

{327C2873-E90D-4c37-AA9D-10AC9BABA46C} -

C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Kwyshell MidpX -

{EBE9E2B5-B526-48BC-AD46-687263EDCB0E} -

C:\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Google Toolbar -

{2318C2B1-4965-11d4-9B18-009027A5CD4F} -

C:\Program Files\Google\Google

Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon]

RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe

/install
O4 - HKLM\..\Run: [NvMediaCenter]

RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskb

arInit
O4 - HKLM\..\Run: [ATIPTA] C:\Program

Files\ATI Technologies\ATI Control

Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033]

"C:\Program Files\D-Tools\daemon.exe"

-lang 1033
O4 - HKLM\..\Run: [vdrdpup]

C:\WINDOWS\system32\rundll32

C:\WINDOWS\system32\vdrdpup.dll,Register

VirtualChannel
O4 - HKLM\..\Run: [Windows Defender]

"C:\Program Files\Windows

Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HP Software Update]

C:\Program Files\HP\HP Software

Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Launch LGDCore]

"C:\Program Files\Logitech\G-series

Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon]

"C:\Program Files\Logitech\G-series

Software\LCDMon.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program

Files\CA\eTrust Internet Security

Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER]

"C:\Program Files\CA\eTrust Internet

Security Suite\CA

Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program

Files\CA\eTrust Internet Security

Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program

Files\CA\eTrust Internet Security

Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program

Files\CA\eTrust Internet Security

Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade]

C:\Program Files\CA\eTrust Internet

Security Suite\CA Personal

Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [eTrustPPAP]

"C:\Program Files\CA\eTrust Internet

Security Suite\eTrust PestPatrol

Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched]

"C:\Program

Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program

Files\Common Files\Pure Networks

Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program

Files\Pure Networks\Network

Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [DellSupportCenter]

"C:\Program Files\Dell Support

Center\bin\sprtcmd.exe" /P

DellSupportCenter
O4 - HKLM\..\Run: [dscactivate]

"C:\Program Files\Dell Support

Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [RoxWatchTray]

"C:\Program Files\Common Files\Roxio

Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [SPAMfighter Agent]

"C:\Program

Files\SPAMfighter\SFAgent.exe" update

delay 60
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program

Files\Google\GoogleToolbarNotifier\Googl

eToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk =

C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma

Loader.exe
O4 - Startup: BlackBerry Desktop

Redirector.lnk = C:\Program

Files\Research In

Motion\BlackBerry\Redirector.exe
O4 - Global Startup: Ashampoo Magical

Defrag.lnk = C:\Program

Files\Ashampoo\Ashampoo Magical

Defrag\bin\aDefragCtrl.exe
O4 - Global Startup: D-Link AirPlus G

Wireless Utility.lnk = C:\Program

Files\D-Link\AirPlusG

DWL-G122\AirPlus.exe
O4 - Global Startup: Digital Line

Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging

Monitor.lnk = C:\Program

Files\HP\Digital

Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart

Premier Fast Start.lnk = C:\Program

Files\HP\Digital

Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft

Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload

&with BitComet - res://C:\Program

Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload

all video with BitComet -

res://C:\Program

Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload

all with BitComet - res://C:\Program

Files\BitComet\BitComet.exe/AddAllLink.h

tm
O8 - Extra context menu item: Add to

Google Photos Screensa&ver -

res://C:\WINDOWS\system32\GPhotos.scr/20

0
O8 - Extra context menu item: E&xport to

Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCE

L.EXE/3000
O9 - Extra button: Create Mobile

Favorite -

{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create

Mobile Favorite… -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Yahoo! Services -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\Program

Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Share in Hello -

{B13B4423-2647-4cfc-A4B3-C7D56CB83487} -

C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in

H&ello -

{B13B4423-2647-4cfc-A4B3-C7D56CB83487} -

C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) -

{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

(no file)
O9 - Extra button: BitComet -

{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} -

res://C:\Program

Files\BitComet\tools\BitCometBHO_1.2.2.2

8.dll/206 (file missing)
O9 - Extra button: (no name) -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\Program Files\Spybot - Search &

Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot -

Search && Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\Program Files\Spybot - Search &

Destroy\SDHelper.dll
O9 - Extra button: MoneySide -

{E023F504-0C5A-4750-A1E7-A9046DEA8A21} -

C:\Program Files\Microsoft

Money\System\mnyviewer.dll
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:

@xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 -

{E59EB121-F339-4851-A3BA-FE49C35617C2} -

F:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 -

{E59EB121-F339-4851-A3BA-FE49C35617C2} -

F:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows

Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.BANKOFAMERICA.COM
O15 - Trusted Zone:

http://office.micorsoft.com
O16 - DPF: ChatSpace Full Java Client

3.1.0.229 -

http://surechat.com:9000/Java/cfs31229.c

ab
O16 - DPF: McAfee Wi-FiScan -

http://download.mcafee.com/molbin/iss-lo

c/mwfs/3.1.0.0/WscWlanScannerCtrl.cab
O16 - DPF: Yahoo! Chat -

http://us.chat1.yimg.com/us.yimg.com/i/c

hat/applet/c381/chat.cab
O16 - DPF: Yahoo! Literati -

http://download.games.yahoo.com/games/cl

ients/y/tt0_x.cab
O16 - DPF: Yahoo! Towers 2.0 -

http://download.games.yahoo.com/games/cl

ients/y/ywt0_x.cab
O16 - DPF:

{01111C00-3E00-11D2-8470-0060089874ED}

(Support.com ActionRunner Class) -

http://help.rr.com/Foundrysdccommon/down

load/tgctlar.cab
O16 - DPF:

{01113300-3E00-11D2-8470-0060089874ED}

(Support.com Configuration Class) -

http://help.rr.com/sdccommon/download/gr

prcus.cab
O16 - DPF:

{01234567-1234-1234-1234-012345678921} -

http://register.voiceglo.com/iax.cab
O16 - DPF:

{01A88BB1-1174-41EC-ACCB-963509EAE56B}

(SysProWmi Class) -

http://support.dell.com/systemprofiler/S

ysPro.CAB
O16 - DPF:

{06D5218D-079C-11D3-B2D1-00A0C98684AC}

(McAfee Hardware Finder Control) -

http://download.mcafee.com/molbin/clinic

/hwf/mghwinfo.cab
O16 - DPF:

{084F552D-19EB-4668-9788-984CBC781A8F} -

http://survey.otxresearch.com/Preloader.

dll
O16 - DPF:

{0C568603-D79D-11D2-87A7-00C04FF158BB}

(BrowseFolderPopup Class) -

http://download.mcafee.com/molbin/Shared

/MGBrwFld.cab
O16 - DPF:

{13E39F7E-FDA8-11D2-99DC-00C04FF40D52}

(McAfee OilChange Multi-Product Support

Filter) -

http://download.mcafee.com/molbin/OilCha

nge/MGOcFilt.cab
O16 - DPF:

{17492023-C23A-453E-A040-C7C580BBF700}

(Windows Genuine Advantage Validation

Tool) -

http://go.microsoft.com/fwlink/?linkid=3

9204
O16 - DPF:

{1842B0EE-B597-11D4-8997-00104BD12D94}

(iCC Class) -

http://www.pcpitstop.com/internet/pcpCon

nCheck.cab
O16 - DPF:

{23047A90-8511-11D2-87A5-20C252C10000}

(McAfee Clinic TreeView Class) -

http://download.mcafee.com/molbin/Shared

/MGTree.cab
O16 - DPF:

{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}

(Symantec AntiVirus scanner) -

http://security.symantec.com/sscv6/Share

dContent/vc/bin/AvSniff.cab
O16 - DPF:

{30528230-99F7-4BB4-88D8-FA1D4F56A2AB}

(YInstStarter Class) - C:\Program

Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF:

{31E68DE2-5548-4B23-88F0-C51E6A0F695E}

(Microsoft PID Sniffer) -

https://support.microsoft.com/OAS/Active

X/odc.cab
O16 - DPF:

{39B0684F-D7BF-4743-B050-FDC3F48F7E3B}

(FilePlanet Download Control Class) -

http://www.fileplanet.com/fpdlmgr/cabs/F

PDC_1_0_0_42.cab
O16 - DPF:

{406B5949-7190-4245-91A9-30A17DE16AD0}

(Snapfish Activia) -

http://photo.walgreens.com/WalgreensActi

via.cab
O16 - DPF:

{42FDC231-A411-45F8-B8B6-3B5026111DA8}

(SolitaireRush Control) -

http://www.worldwinner.com/games/v47/sol

itairerush/solitairerush.cab
O16 - DPF:

{493ACF15-5CD9-4474-82A6-91670C3DD66E}

(LinkedIn ContactFinderControl) -

http://www.linkedin.com/cab/LinkedInCont

actFinderControl.cab
O16 - DPF:

{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

http://bin.mcafee.com/molbin/shared/mcin

sctl/en-us/4,0,0,72/mcinsctl.cab
O16 - DPF:

{4F1E5B1A-2A80-42CA-8532-2D05CB959537}

(MSN Photo Upload Tool) -

http://spaces.msn.com//PhotoUpload/MsnPU

pld.cab
O16 - DPF:

{4FAE30E1-EE9C-477D-8D06-BF8D3429B60F}

(WebIQ Technology Client) -

http://webiq001.webiqonline.com/WebIQ/bi

n/WebIQ.cab
O16 - DPF:

{544EB377-350A-4295-9BEB-EAB8392E09C6}

(MSN Money Charting) -

http://fdl.msn.com/public/investor/v13/i

nvinstl.exe
O16 - DPF:

{56336BCB-3D8A-11D6-A00B-0050DA18DE71} -

http://207.188.7.150/30b5ec1b44f326ba1a1

5/netzip/RdxIE601.cab
O16 - DPF:

{56393399-041A-4650-94C7-13DFCB1F4665}

(PSFormX Control) -

http://www.my-etrust.com/Extern/RoadRunn

er/PestScan/pestscan.cab
O16 - DPF:

{5E943D9C-F8DC-4258-8E3F-A61BB3405A33} -

http://www.imagestation.com/common/class

es/batchdwnl.cab?version=4,3,2,20802
O16 - DPF:

{5ED80217-570B-4DA9-BF44-BE107C0EC166}

(Windows Live Safety Center Base Module)

-

http://cdn.scan.safety.live.com/resource

/download/scanner/wlscbase969.cab
O16 - DPF:

{644E432F-49D3-41A1-8DD5-E099162EEEC5}

(Symantec RuFSI Utility Class) -

http://security.symantec.com/sscv6/Share

dContent/common/bin/cabsa.cab
O16 - DPF:

{6B4788E2-BAE8-11D2-A1B4-00400512739B}

(PWMediaSendControl Class) -

http://216.249.24.144/code/PWActiveXImgC

tl.CAB
O16 - DPF:

{6BEA1C48-1850-486C-8F58-C7354BA3165E}

(Install Class) -

http://updates.lifescapeinc.com/installe

rs/pinstall/pinstall.cab
O16 - DPF:

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}

(MUWebControl Class) -

http://update.microsoft.com/microsoftupd

ate/v6/V5Controls/en/x86/client/muweb_si

te.cab?1125895783359
O16 - DPF:

{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B}

(GSDACtl Class) -

http://launch.gamespyarcade.com/software

/launch/alaunch.cab
O16 - DPF:

{77E32299-629F-43C6-AB77-6A1E6D7663F6}

(Groove Control) -

http://download.shockwave.com/pub/otoy/O

TOYAX.cab
O16 - DPF:

{7F8C8173-AD80-4807-AA75-5672F22B4582}

(ICSScanner Class) -

http://download.zonelabs.com/bin/promoti

ons/spywaredetector/ICSScanner37880.cab
O16 - DPF:

{7FE26BE2-B923-4B41-9834-E84DA1CC1F96}

(Maid Control) -

http://vsp.closetmaid.com/vsp/cmaidctl_v

sp.closetmaid.com_downloader.cab
O16 - DPF:

{814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9}

(DASWebDownload Class) -

http://das.microsoft.com/activate/cab/x8

6/i486/NTANSI/retail/DASAct.cab
O16 - DPF:

{8714912E-380D-11D5-B8AA-00D0B78F3D48}

(Yahoo! Webcam Upload Wrapper) -

http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF:

{88D8E8B7-A33B-4417-A385-8373484D43ED}

(InstallHelper Class) -

file://C:\DOCUME~1\Aaron\LOCALS~1\Temp\T

hereInstallHelper.dll
O16 - DPF:

{8A94C905-FF9D-43B6-8708-F0F22D22B1CB}

(Wwlaunch Control) -

http://www.worldwinner.com/games/shared/

wwlaunch.cab
O16 - DPF:

{8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2}

(There Voice Trainer) -

file://C:\Program

Files\There\ThereClient\ThereVoiceTraine

r.dll
O16 - DPF:

{8E28B3A9-FE83-45D1-B657-D5426B81A121}

(CustomerCtrl Class) -

http://cs7b.instantservice.com/jars/cust

omerxsigned33.cab
O16 - DPF:

{90C9629E-CD32-11D3-BBFB-00105A1F0D68}

(InstallShield International Setup

Player) -

http://zinio.earthc.net/images.zinio.com

/reader/isetup.cab
O16 - DPF:

{90F7E144-984F-4FA6-83A7-C9C8DCB9974C}

(RSActiveXObj Control) -

http://go.radarsync.com/RSActiveX.ocx
O16 - DPF:

{963BE66B-121D-4E6C-BF9F-1A774D9A2E41}

(MSN Money Charting) -

http://moneycentral.msn.com/cabs/pmupdat

e2.exe
O16 - DPF:

{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}

(ActiveScan Installer Class) -

http://acs.pandasoftware.com/activescan/

as5free/asinst.cab
O16 - DPF:

{9F0F185C-B50B-11D2-B53F-00A0C98684AC}

(McAfee PC Clinic OilChange Class) -

http://download.mcafee.com/molbin/OilCha

nge/MGOcCtl_new.cab
O16 - DPF:

{A8683C98-5341-421B-B23C-8514C05354F1}

(FujifilmUploader Class) -

http://www.samsphotoclub.com/upload/Fuji

filmUploadClient.cab
O16 - DPF:

{A90A5822-F108-45AD-8482-9BC8B12DD539}

(Crucial cpcScan) -

http://www.crucial.com/controls/cpcScann

er.cab
O16 - DPF:

{AA59BA6E-B44F-4514-AB3C-0C1DD2306FC3}

(MSN Money Charting) -

http://fdl.msn.com/public/investor/v12/i

nvinstl.exe
O16 - DPF:

{AAF421E6-7914-430A-9981-72B31AFF3BF4}

(There Launcher) - file://C:\Program

Files\There\ThereClient\ThereLauncher.dl

l
O16 - DPF:

{AE1C01E3-0283-11D3-9B3F-00C04F8EF466}

(HeartbeatCtl Class) -

http://fdl.msn.com/zone/datafiles/heartb

eat.cab
O16 - DPF:

{B8BE5E93-A60C-4D26-A2DC-220313175592}

(MSN Games - Installer) -

http://cdn2.zone.msn.com/binFramework/v1

0/ZIntro.cab56649.cab
O16 - DPF:

{BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -

http://bin.mcafee.com/molbin/shared/mcgd

mgr/en-us/1,0,0,16/mcgdmgr.cab
O16 - DPF:

{BDD2F926-8158-4F62-9E0D-B3B75FD1F07F}

(McObjectFactory Class) -

http://download.mcafee.com/molbin/shared

/McMySec/en-us/1,0,0,2/mcmysec.cab
O16 - DPF:

{BF31FA5E-AE8A-11D2-A1BD-0800300004C2}

(McAfee PC Clinic Internet Class) -

http://download.mcafee.com/molbin/Shared

/MCInet_new.cab
O16 - DPF:

{C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3}

(Virtools WebPlayer Class) -

http://a532.g.akamai.net/f/532/6712/4h/p

layer.virtools.com/downloads/player/Inst

all3.0/Installer.exe
O16 - DPF:

{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}

(Java Runtime Environment 1.4.0_01) -
O16 - DPF:

{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}

(Java Runtime Environment 1.4.1_02) -
O16 - DPF:

{CDB74794-A3BA-4733-B6F6-59BF16D6C15A}

(McAfee Smart Shop - Update Class) -

http://download.mcafee.com/molbin/mcaeng

/mcsmtshp.cab
O16 - DPF:

{D1E7CBDA-E60E-4970-A01C-37301EF7BF98}

(Measurement Service Client v.3.4) -

http://ccon.futuremark.com/global/msc34.

cab
O16 - DPF:

{D54160C3-DB7B-4534-9B65-190EE4A9C7F7}

(SproutLauncherCtrl Class) -

http://zone.msn.com/bingame/feed/default

/SproutLauncher.cab
O16 - DPF:

{D77EF652-9A6B-40C8-A4B9-1C0697C6CF41}

(TikGames Online Control) -

http://zone.msn.com/bingame/shpo/default

/shapo.cab
O16 - DPF:

{E504EE6E-47C6-11D5-B8AB-00D0B78F3D48}

(Yahoo! Webcam Viewer Wrapper) -

http://us.i1.yimg.com/us.yimg.com/i/chat

/webcam/v110/yvwrctl.cab
O16 - DPF:

{E5D419D6-A846-4514-9FAD-97E826C84822}

(HeartbeatCtl Class) -

http://fdl.msn.com/zone/datafiles/heartb

eat.cab
O16 - DPF:

{E5F5D008-DD2C-4D32-977D-1A0ADF03058B}

(JuniperSetupControlXP Class) -

https://secureapps.carolinas.org/dana-ca

ched/setup/JuniperSetupSP1.cab
O16 - DPF:

{E7D2588A-7FB5-47DC-8830-832605661009}

(Live Collaboration) -

https://rr.esecurecare.net/rnt/rnl/java/

RntX.cab
O16 - DPF:

{E855A2D4-987E-4F3B-A51C-64D10A7E2479}

(EPSImageControl Class) -

http://tools.ebayimg.com/eps/activex/EPS

Control_v1-0-3-0.cab
O16 - DPF:

{EF791A6B-FC12-4C68-99EF-FB9E207A39E6}

(McFreeScan Class) -

http://download.mcafee.com/molbin/iss-lo

c/vso/en-us/tools/mcfscan/2,0,0,4438/mcf

scan.cab
O16 - DPF:

{F137B9BA-89EA-4B04-9C67-2074A9DF61FD}

(Photo Upload Plugin Class) -

http://brookseckerd.pnimedia.com/upload/

activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab

?
O16 - DPF:

{F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6}

(MSN Chat Control 4.5) -

http://chat.msn.com/bin/msnchat45.cab
O16 - DPF:

{F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F}

(iPIX Media Send Class) -

http://216.249.24.60/code/iPIX-ImageWell

-ipix.cab
O18 - Protocol: skype4com -

{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch -

{B1759355-3EEC-4C1E-B0F1-B719FE26E377} -

C:\Program Files\Google\Google

Toolbar\Component\fastsearch_A8904FB862B

D9564.dll
O23 - Service: Lavasoft Ad-Aware Service

(aawservice) - Unknown owner -

C:\Program

Files\Lavasoft\Ad-Aware\aawservice.exe

(file missing)
O23 - Service: Adobe LM Service - Adobe

Systems - C:\Program Files\Common

Files\Adobe Systems

Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor

V4 (AdobeActiveFileMonitor4.0) - Unknown

owner - C:\Program Files\Adobe\Photoshop

Elements

4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device -

Apple Inc. - C:\Program Files\Common

Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
O23 - Service: AshampooDefragService -

- C:\Program Files\Ashampoo\Ashampoo

Magical Defrag\bin\aDefragService.exe
O23 - Service: Ati HotKey Poller - ATI

Technologies Inc. -

C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner

- C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple

Inc. - C:\Program

Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. -

C:\Program Files\CA\eTrust Internet

Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer

Associates International, Inc. -

C:\Program Files\CA\eTrust Internet

Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for

CDROM Access - Creative Technology Ltd -

C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown

owner - C:\Program

Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity_BackUp -

GEAR Software -

C:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: Google Software Updater

(gusvc) - Google - C:\Program

Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver -

Hewlett-Packard Company -

C:\WINDOWS\system32\spool\drivers\w32x86

\3\HPBPRO.EXE
O23 - Service: HP Status Server -

Hewlett-Packard Company -

C:\WINDOWS\system32\spool\drivers\w32x86

\3\HPBOID.EXE
O23 - Service: InstallDriver Table

Manager (IDriverT) - Macrovision

Corporation - C:\Program Files\Common

Files\InstallShield\Driver\1050\Intel

32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc.

- C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime

Protection Service (ITMRTSVC) - CA, Inc.

- C:\Program

Files\CA\SharedComponents\PPRT\bin\ITMRT

SVC.exe
O23 - Service: Java Quick Starter

(JavaQuickStarterService) - Sun

Microsystems, Inc. - C:\Program

Files\Java\jre6\bin\jqs.exe
O23 - Service: Norman API-hooking helper

(NipSvc) - Unknown owner -

C:\VIRUSfighter\Nvc\BIN\nipsvc.exe (file

missing)
O23 - Service: Pure Networks Net2Go

Service (nmraapache) - Pure Networks,

Inc. - C:\Program Files\Pure

Networks\Network

Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform

Service (nmservice) - Pure Networks,

Inc. - C:\Program Files\Common

Files\Pure Networks

Shared\Platform\nmsrvc.exe
O23 - Service: Intel® NMS (NMSSvc) -

Intel Corporation -

C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver

Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PPCtlPriv - CA, Inc. -

C:\Program Files\CA\eTrust Internet

Security Suite\CA

Anti-Spyware\PPCtlPriv.exe
O23 - Service: Roxio UPnP Renderer 9 -

Sonic Solutions - C:\Program

Files\Roxio\Digital Home

9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 -

Sonic Solutions - C:\Program

Files\Roxio\Digital Home

9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9

(RoxLiveShare9) - Sonic Solutions -

C:\Program Files\Common Files\Roxio

Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB - Sonic

Solutions - C:\Program Files\Common

Files\Roxio

Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxMediaDB9 - Sonic

Solutions - C:\Program Files\Common

Files\Roxio

Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher

9 (RoxWatch9) - Sonic Solutions -

C:\Program Files\Common Files\Roxio

Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SPAMfighter Update

Service - SPAMfighter ApS - C:\Program

Files\SPAMfighter\sfus.exe
O23 - Service: SupportSoft Sprocket

Service (dellsupportcenter)

(sprtsvc_dellsupportcenter) -

SupportSoft, Inc. - C:\Program

Files\Dell Support

Center\bin\sprtsvc.exe
O23 - Service: SPYWAREfighterRP -

Unknown owner - C:\Program

Files\SPYWAREfighter\spfprc.exe (file

missing)
O23 - Service: Spyware Terminator

Realtime Shield Service (sp_rssrv) -

Crawler.com - C:\Program Files\Spyware

Terminator\sp_rsser.exe
O23 - Service: TiVo Beacon (TivoBeacon2)

- TiVo Inc. - C:\Program Files\Common

Files\TiVo Shared\Beacon\TiVoBeacon.exe
O23 - Service: HIPS Event Manager

(UmxAgent) - CA - C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

Agent.exe
O23 - Service: HIPS Configuration

Interpreter (UmxCfg) - CA - C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

Cfg.exe
O23 - Service: HIPS Firewall Helper

(UmxFwHlp) - CA - C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

FwHlp.exe
O23 - Service: HIPS Policy Manager

(UmxPol) - CA - C:\Program

Files\CA\SharedComponents\HIPSEngine\Umx

Pol.exe
O23 - Service: SecuROM User Access

Service (V7) (UserAccess7) - Unknown

owner -

C:\WINDOWS\system32\UAService7.exe
O23 - Service: VET Message Service

(VETMSGNT) - CA, Inc. - C:\Program

Files\CA\eTrust Internet Security

Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 28487 bytes

My wife has multiple issues with her login while I have no issues. The latest issue is that she has started getting the blue screen while sending email. I returns an error with kmxcf.sys in the description. I have run Malewarebytes but it did not detect anything. I also ran "what's running" and did not notice any odd programs but I am only a novice at this. In looking at the log I can see lots of items that I do not beleive should be there, example would be all the McAfee items, but I have not removed them. Any assistance would be very appriciated.
Hi aresnik,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Open Notepad: Start > All Programs > Accessories > Notepad.
Click on Format and ensure that Wordwrap is unchecked. If it isn't, uncheck it.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI