Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://ftp.coupons.com/r3120/cpbrxpie.cab O16 - DPF: Yahoo! McAfee® Multiple malware can also use the same start-up entries, in this case only those with significant differences (such as file location) are repeated in this database.

Scan your system now to identify issues with this process and services that can be safely removed. For a list of tasks/processes you should try the list at PC Pitstop, the Process Library from Uniblue or one of the many others now available. Indication of Infection This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section. Effectively the "master" process which calls the different program features and makes sure they are running.

On restart press the ctrl key promptly to access the boot menu and the Safe Mode option. Companion) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/ym/yiebio5_0_2_7.cab O16 - DPF: Yahoo!

I have Spybot S&D, but couldn't find the virus/spybot/whatever. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+SHIFT+ESC. Advertisements do not imply our endorsement of that product or service. This process is not considered CPU intensive.

Auto-protect and E-mail check will not function without thisYesCommon ClientYccApp.exePart of older versions of Symantec's security products including Norton 360, Norton Internet Security, Norton AntiVirus and the now discontinued Norton SystemWorks Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc. Auto-protect and E-mail check will not function without thisYesSymantec ServiceXccApp.exeAdded by the AKHER.D WORM! There are a number of virus and malware entries listed in this database where specific removal instructions haven't been given.

As more than 25K entries in this database related to malware you should use a quality internet security package. These pages are concerned with startup programs from the common startup locations shown above ONLY. This entry appears if you choose to install the program using the default settings as service on an NT based OS (NT/2K/XP/Vista). By the way, if your task manager works (ctrl-alt-del) you may be able to end task the cbrss.exe process and complete the rest of the operation without using Safe Mode.

It was a "spybot" variant. Alternatively, you can search the full database or use the alphabetical index on that page. If you don't have regularly scheduled backups then choose the startup installation option and run it manually when requiredYesexkatajXcbkdkiw.exeAdded by the FANBOT-F WORM!NoCallBumpingYcbpopw.exeRelated to the Gazel 128 PCI ISDN adapter by Chinese Checkers - http://download.games.yahoo.com/games/clients/y/cct0_x.cab O16 - DPF: Yahoo!

Application using this process: Unknown Recommended: Scan your system for invalid registry entries. NiteHawk, Sep 14, 2003 #5 Rollin' Rog Joined: Dec 9, 2000 Messages: 45,855 NightHawk lives up to his name! (Tx, might have to change mine to "Mr. System Tools SpeedUpMyPC PC Mechanic Toolbox ProcessQuicklink Copyright © 2004-2016 Uniblue. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL.

A safe way to stop these errors is to uninstall the application and run a system scan to automatically identify any PC issues. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. They are spread manually, often under the premise that they are beneficial or wanted.

Auto-protect and E-mail check will not function without thisYesNorton Auto-ProtectXccApp.exeAdded by the AKHER.D WORM!

Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. No, create an account now. This displays some startup programs AND other background tasks and "Services". For further information on this and how to identify and disable start-up programs please visit the Introduction page.

Runs as a service on an NT based OS (such as Windows 8/7/Vista/XP)NonortonsantivirusXccEvtMngr.exeDetected by Sophos as Troj/Hzdoor-ANoSunJavaSchedXccEvtMngr.exeDetected by Sophos as W32/Sdbot-YPNoccEvtMrg.exeXccEvtMrg.exeDetected by Trend Micro as WORM_RBOT.GZNo FIRST PREV ( Page 107 Effectively the "master" process which calls the different program features and makes sure they are running.

In Safe Mode run Explorer and delete this file: C:\WINDOWS\SYSTEM\CBRSS.EXE Also run HijackThis and check and "fix" the following entries: O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM FILES\MYWAY\MYBAR\1.BIN\MYBAR.DLL O3 Most of them affect XP/2k systems, but this one does its thing on Win98 as well. Klondike Solitaire - http://yog55.games.scd.yahoo.com/yog/y/ks12_x.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://geotoo.mkm-wpe.net/activex/AxisCamControl.ocx O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: Yahoo! Run a full system scan. (On-Demand Scan) 4.

MahJong - http://download.games.yahoo.com/games/clients/y/ot0_x.cab O16 - DPF: Toki Toki Boom - http://download.games.yahoo.com/games/clients/y/vtm_x.cab O16 - DPF: {8BDF4BDB-7C40-4DC8-B2DD-138D8059698C} (Focus Control) - http://mirror.worldwinner.com/games/v40/focus/focus.cab O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - http://mirror.worldwinner.com/games/v40/tilecity/tilecity.cab O16 - DPF: {7BC394DE-07B8-412B-9F98-52E7E7A4ABD4} Note - this is not the legitimate Symantec/Norton file normally located in %CommonFiles%\Symantec Shared. Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab O16 - DPF: Yahoo! Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet O4 - HKLM\..\RunOnce: [SpyBotSnD] "C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE" /autocheck O4 - HKCU\..\RunOnce: [Microsoft System Restore Configuration] CBRSS.EXE O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc. File Location Unknown This entry has been requested 2,847 times. Magoo") While your at it, you might also want to install, UPDATE and run Spybot to clean out any residual files or entries left by the MyBar search Hijacker as well. Scan your system now to identify unused processes that are using up valuable resources.

If this is the case then you could try ComboFix, a program written by sUBs that can remove many different types of Trojans and Worms. Notes & Warnings If you can help identify new entries and verify/identify those entries with a "?" status (especially hardware specific - such as laptops and motherboards) then please E-mail us Otherwise there would be multiple entries for popular filenames that viruses often use - such as "svchost.exe" above for example. Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More...

Description Added by a variant of the SPYBOT WORM! Fleet - http://download.games.yahoo.com/games/clients/y/fltt2_x.cab O16 - DPF: Yahoo!