This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] online security guide live safety center malware

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i keep putting the OSG and LSC icons in the recycle bin out of habit. i guess i shouldn't be doing that while you're working on this. huh?
Please don't

Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
sorry it took so long. thanks for all your help so far… :)

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Tuesday, November 20, 2007 4:59:26 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/11/2007
Kaspersky Anti-Virus database records: 462422
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 55487
Number of viruses found: 11
Number of infected objects: 61
Number of suspicious objects: 1
Duration of the scan process: 00:57:01

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.mdb Object is locked skipped
C:\Documents and Settings\Debra Ritzema\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Debra Ritzema\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Debra Ritzema\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Debra Ritzema\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Debra Ritzema\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Debra Ritzema\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Debra Ritzema\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Debra Ritzema\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Debra Ritzema\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Debra Ritzema\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Debra Ritzema\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\hijackthis.log Suspicious: Exploit.HTML.Mht skipped
C:\Program Files\Lycos\IEagent\CSTMINST.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.o skipped
C:\Program Files\Lycos\IEagent\CSTVINST.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.a skipped
C:\qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\AntiSpyInfo\lcxrdhyo.dll.q_8043045_q.vir Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\aeyjswsv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bgwobmcs.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bkqgflho.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\cjlcqioc.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\dovlmret.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\efcdabc.dll.vir Infected: Trojan-Downloader.Win32.Agent.epy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ehxovead.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ejppfoer.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\eqaepvek.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\fnbjdhmj.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\mjuyarxp.dll.vir Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\mxutiebp.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nkdjykvn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\sbchkjpp.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\stmfrmrs.dll.vir Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\syuyjjbu.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\uiahbggw.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vaffyujp.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1359\A0059045.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1359\A0059097.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059374.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059375.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059376.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059377.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059378.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059380.dll Infected: Trojan-Downloader.Win32.Agent.epy skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059381.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059382.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059383.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059384.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059387.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059388.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059394.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059395.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059396.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059398.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059400.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059406.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059451.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059452.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059453.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059454.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059455.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059456.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059457.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059458.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059459.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059460.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059461.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059462.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1360\A0059463.exe Infected: Trojan.Win32.Agent.bxj skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1361\A0059479.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1361\A0059570.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP1361\change.log Object is locked skipped
C:\WINDOWS\czjakvuslh.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.am skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Agere Systems AC'97 Modem.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\Temp\JETDE0B.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 5:01:53 PM, on 11/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\WScript.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Nitrodial V2\nitrodial.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\Nitrodial V2\PBHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Nitrodial V2.lnk = C:\Program Files\Nitrodial V2\nitrodial.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A261AE53-0F90-4901-AAD3-9A1001AAEFA8}: NameServer = 72.35.32.161 64.85.136.161
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\Photo Server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
A. DownloadOTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the content of the quotebox below to the clipboard by highlighting ALL of
    the file paths and pressing CTRL + C (or, after highlighting, right-click and choose
    copy):

    C:\Program Files\Lycos\IEagent
    C:\WINDOWS\czjakvuslh.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be
    moved"
    window and choose Paste.
  • Click the red Moveit! button.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot
the machine to finish the move process. If you are asked to reboot the machine
choose Yes.

Please "Copy" the results from the "Results" window (to the right) and then "Paste"
them into your next reply on the forum. Reboot into Normal Mode if you have to reboot.


B. Step Three:
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    Insert Folders to be removed

    C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe
    C:\WINDOWS\system32\bak\NeroCheck.exe
    C:\WINDOWS\system32\bak\igfxtray.exe
    C:\WINDOWS\system32\bak\hphmon05.exe
    C:\WINDOWS\system32\bak\hkcmd.exe
    "C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe"
    "C:\Program Files\Winamp\bak\winampa.exe"
    "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe"
    "C:\Program Files\QuickTime\bak\qttask.exe"
    "C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe"
    "C:\Program Files\iTunes\bak\iTunesHelper.exe"
    "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe"
    "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"



  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • You will be presented with a Menu.

    1. Press 1 then Enter to scan for bak folders
    2. Press 2 then Enter to restore files from bak folders
    3. Press 3 then Enter to remove bak folders
    4. Press 4 then Enter to reset domain zones
    5. Press E then Enter to EXIT

  • Press 3, then press Enter.
  • A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
  • Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
  • The program will proceed to remove the bad folders and will perform another scan for .bak folder
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Wed 11/21/2007 The current time is: 0:07:05.03 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\ITUNES\BAK 06/14/2006 03:24 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 07/26/2006 10:49 AM 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\PROGRA~1\WINAMP\BAK 12/20/2004 01:41 PM 33,792 winampa.exe 1 File(s) 33,792 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 01:11 PM 114,688 hkcmd.exe 05/22/2003 07:55 AM 483,328 hphmon05.exe 03/11/2003 01:24 PM 155,648 igfxtray.exe 07/09/2001 09:50 AM 155,648 NeroCheck.exe 4 File(s) 909,312 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 02/28/2003 11:00 PM 315,392 atiptaxx.exe 1 File(s) 315,392 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 05/22/2003 08:03 AM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MICAC0~1\SYSTEM\BAK 07/17/2002 01:00 PM 200,767 mnyexpr.exe 1 File(s) 200,767 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 02:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\SONYSYS\VAIORE~1\BAK 04/20/2003 12:08 AM 28,672 PartSeal.exe 1 File(s) 28,672 bytes Directory of C:\PROGRA~1\NERO\DATA\XTRAS\BAK 11/11/2004 08:50 PM 212,992 mssysmgr.exe 1 File(s) 212,992 bytes Directory of C:\PROGRA~1\SUPPORT.COM\CLIENT\LSERVER\BAK 07/14/2002 02:50 PM 11,406 server.vbs 1 File(s) 11,406 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 05/07/2003 12:56 AM 188,416 hpztsb09.exe 1 File(s) 188,416 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 278528 Jun 14 2006 "C:\Program Files\iTunes\iTunesHelper.exe" 278528 Jun 14 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\qttask.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\winampa.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\bak\winampa.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\Drivers\Video\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\hkcmd.exe" 483328 May 22 2003 "C:\WINDOWS\system32\hphmon05.exe" 483328 May 22 2003 "C:\WINDOWS\system32\bak\hphmon05.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\Drivers\Video\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\bak\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\igfxtray.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\NeroCheck.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Java\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\mssysmgr.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\server.vbs" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\bak\server.vbs" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe" end of report
We are having a bit of a problem here with that infection. We will have to start from the beginning. Please delete the FindAWF tool and all logs that it may have created to date.

Please download FindAWF to your Desktop.
  • Double-click FindAWF.exe to start the tool.
  • Select option #1 - Scan for bak folders by typing 1 and press 'Enter'
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
**Do not run any other option unless directed to do so.**


Trevuren
Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Wed 11/21/2007 The current time is: 0:46:48.20 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\ITUNES\BAK 06/14/2006 03:24 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 07/26/2006 10:49 AM 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\PROGRA~1\WINAMP\BAK 12/20/2004 01:41 PM 33,792 winampa.exe 1 File(s) 33,792 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 01:11 PM 114,688 hkcmd.exe 05/22/2003 07:55 AM 483,328 hphmon05.exe 03/11/2003 01:24 PM 155,648 igfxtray.exe 07/09/2001 09:50 AM 155,648 NeroCheck.exe 4 File(s) 909,312 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 02/28/2003 11:00 PM 315,392 atiptaxx.exe 1 File(s) 315,392 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 05/22/2003 08:03 AM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MICAC0~1\SYSTEM\BAK 07/17/2002 01:00 PM 200,767 mnyexpr.exe 1 File(s) 200,767 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 02:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\SONYSYS\VAIORE~1\BAK 04/20/2003 12:08 AM 28,672 PartSeal.exe 1 File(s) 28,672 bytes Directory of C:\PROGRA~1\NERO\DATA\XTRAS\BAK 11/11/2004 08:50 PM 212,992 mssysmgr.exe 1 File(s) 212,992 bytes Directory of C:\PROGRA~1\SUPPORT.COM\CLIENT\LSERVER\BAK 07/14/2002 02:50 PM 11,406 server.vbs 1 File(s) 11,406 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 05/07/2003 12:56 AM 188,416 hpztsb09.exe 1 File(s) 188,416 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 278528 Jun 14 2006 "C:\Program Files\iTunes\iTunesHelper.exe" 278528 Jun 14 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\qttask.exe" 282624 Jul 26 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\winampa.exe" 33792 Dec 20 2004 "C:\Program Files\Winamp\bak\winampa.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\Drivers\Video\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\hkcmd.exe" 483328 May 22 2003 "C:\WINDOWS\system32\hphmon05.exe" 483328 May 22 2003 "C:\WINDOWS\system32\bak\hphmon05.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\Drivers\Video\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\bak\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\21\DriverFiles\igfxtray.exe" 155648 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\25\DriverFiles\igfxtray.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\NeroCheck.exe" 155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" 315392 Feb 28 2003 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Java\Microsoft Money\System\mnyexpr.exe" 200767 Jul 17 2002 "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe" 28672 Apr 20 2003 "C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\mssysmgr.exe" 212992 Nov 11 2004 "C:\Program Files\Nero\data\Xtras\bak\mssysmgr.exe" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\server.vbs" 11406 Jul 14 2002 "C:\Program Files\support.com\client\lserver\bak\server.vbs" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" 188416 May 7 2003 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb09.exe" end of report
Step Three:
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    Insert Folders to be removed

    C:\Program Files\iTunes\bak
    C:\Program Files\QuickTime\bak
    C:\Program Files\Winamp\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\WINDOWS\system32\bak
    C:\Program Files\ATI Technologies\ATI Control Panel\bak
    C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak
    C:\Program Files\Microsoft Money\System\bak
    C:\Program Files\VERITAS Software\Update Manager\bak
    C:\WINDOWS\SONYSYS\VAIO Recovery\bak
    C:\Program Files\Nero\data\Xtras\bak
    C:\Program Files\support.com\client\lserver\bak
    C:\WINDOWS\system32\spool\drivers\w32x86\3\bak




  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • You will be presented with a Menu.

    1. Press 1 then Enter to scan for bak folders
    2. Press 2 then Enter to restore files from bak folders
    3. Press 3 then Enter to remove bak folders
    4. Press 4 then Enter to reset domain zones
    5. Press E then Enter to EXIT

  • Press 3, then press Enter.
    [*Press any key to continue.
  • A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
  • Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
  • The program will proceed to remove the bad folders and will perform another scan for .bak folder
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Wed 11/21/2007 The current time is: 11:03:21.20 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 05/22/2003 07:55 AM 483,328 hphmon05.exe 1 File(s) 483,328 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 05/22/2003 08:03 AM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 483328 May 22 2003 "C:\WINDOWS\system32\hphmon05.exe" 483328 May 22 2003 "C:\WINDOWS\system32\bak\hphmon05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" end of report
We are getting there slowly. Please rerun the previous step with the only 2 bak files remaining.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    Insert Folders to be removed

    C:\WINDOWS\system32\bak
    C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak


  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • You will be presented with a Menu.

    1. Press 1 then Enter to scan for bak folders
    2. Press 2 then Enter to restore files from bak folders
    3. Press 3 then Enter to remove bak folders
    4. Press 4 then Enter to reset domain zones
    5. Press E then Enter to EXIT

  • Press 3, then press Enter.
  • Press any key to continue.
  • A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
  • Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
  • The program will proceed to remove the bad folders and will perform another scan for .bak folder
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
oh good. i thought this might be hopeless. i'm not getting the popups, icons, and toolbar anymore. so that's good…. Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Wed 11/21/2007 The current time is: 14:21:45.60 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 05/22/2003 07:55 AM 483,328 hphmon05.exe 1 File(s) 483,328 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 05/22/2003 08:03 AM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 483328 May 22 2003 "C:\WINDOWS\system32\hphmon05.exe" 483328 May 22 2003 "C:\WINDOWS\system32\bak\hphmon05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" 49152 May 22 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" end of report
These two just do not want to leave easily.

* Copy the content of the quotebox below to the clipboard by highlighting ALL of
the folder paths and pressing CTRL + C (or, after highlighting, right-click and choose
copy):

C:\WINDOWS\system32\bak
C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak



* Return to OTMoveIt, right click on the "Paste List of Folders to be
moved" window and choose Paste.
* Click the red Moveit! button.
* Close OTMoveIt

If a folder cannot be moved immediately you may be asked to reboot
the machine to finish the move process. If you are asked to reboot the machine
choose Yes.

Please "Copy" the results from the "Results" window (to the right) and then "Paste"
them into your next reply on the forum. Reboot into Normal Mode if you have to reboot.
C:\WINDOWS\system32\bak moved successfully. C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak moved successfully. Created on 11/21/2007 15:59:25
A.
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • You will be presented with a Menu.

    1. Press 1 then Enter to scan for bak folders
    2. Press 2 then Enter to restore files from bak folders
    3. Press 3 then Enter to remove bak folders
    4. Press 4 then Enter to reset domain zones
    5. Press E then Enter to EXIT

  • Press 4, then press Enter.
  • You will receive a warning to reset domain zones
  • Press 1 then press Enter.
  • If you have manually included sites in the trusted zones, these will need to be re-inserted.


B. Once that step is done, please run HijackThis, do a scan and post the results.

C. Finally, please tell me how your system is now running. If all seems to be OK, just give me the :thumbup: and we will proceede with the final cleanup procedures.


Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI