This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware using Windows Installer

60 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Scotty,

I have deleted all files from the H: drive and reformatted. It is now empty and I will use it for my regular backups when we get the system cleaned.

I also deleted all the backup files from the G: drive, and have done a virus scan with clean results. This file now contains only photos, and some very old files from previous computers. I intend to go through these files after we are done, and to delete whatever I don't want to keep. For this cleanup effort, I have disconnected this disk.

Here is a new HiJackThis log and a new FindAWF log. I'm ready to proceed.

Thanks,

Ron Cobb

==============================

Logfile of HijackThis v1.99.1
Scan saved at 9:18:00 PM, on 12/30/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
C:\WINDOWS\System32\WDBtnMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\program files\common files\aol\1125684819\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1125684819\ee\aolsoftware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
C:\Program Files\American Systems\EZ Macros\EZMacros.exe
C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.myway.com/index/id/top%7Cap.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Print Screen Deluxe.lnk = C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
O4 - Startup: Shortcut to EZMacros.lnk = C:\Program Files\American Systems\EZ Macros\EZMacros.exe
O4 - Startup: URL Address Book.lnk = C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Zip Up The Web Tray Icon.lnk = C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.tscmaps.com/shared/viewer/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1189980911625
O16 - DPF: {6BF35011-3AE5-44D3-A8BB-73ED462A0BC0} (EZUploader Control) - http://www.ezprints.com/software/ezuploader.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.rentmanager.com/demo/msrdp.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://www.dlink.com/products/livedemo/plugin/h263ctrl.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D53A9247-2FEA-4E93-8EEE-9A9B07E8D760} (EZPCropFit Class) - http://www.ezprints.com/software/cropfit.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


============================


Find AWF report by noahdfear ©2006
Version 1.40

The current date is: Sun 12/30/2007
The current time is: 21:21:01.34


bak folders found
~~~~~~~~~~~


Directory of C:\HP\KBD\BAK

02/11/2003 11:02 PM 61,440 KBD.EXE
1 File(s) 61,440 bytes

Directory of C:\PROGRA~1\AMERIC~1.0A\BAK

07/12/2005 01:17 AM 50,776 AOL.EXE
09/19/2007 09:27 PM 24 shellmon.ph
2 File(s) 50,800 bytes

Directory of C:\PROGRA~1\AOL9~1.0B\BAK

04/18/2007 02:49 AM 50,736 AOL.EXE
11/19/2007 09:12 AM 24 shellmon.ph
2 File(s) 50,760 bytes

Directory of C:\PROGRA~1\LEXMAR~1\BAK

06/14/2001 12:42 PM 53,248 AcBtnMgr_X83.exe
10/18/2001 10:25 AM 40,960 ACMonitor_X83.exe
2 File(s) 94,208 bytes

Directory of C:\PROGRA~1\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\PICASA2\BAK

12/11/2006 08:36 PM 366,400 PicasaMediaDetector.exe
1 File(s) 366,400 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/02/2005 02:16 PM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SMINST\BAK

09/14/2002 12:42 AM 212,992 RECGUARD.EXE
1 File(s) 212,992 bytes

Directory of C:\WINDOWS\SYSTEM\BAK

11/26/2007 08:47 AM 183 hpsysdrv.DAT
05/07/1998 07:04 PM 52,736 hpsysdrv.exe
2 File(s) 52,919 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

03/11/2003 08:11 PM 114,688 hkcmd.exe
07/31/2002 11:28 PM 81,920 ps2.exe
2 File(s) 196,608 bytes

Directory of C:\PROGRA~1\BROADJ~1\CLIENT~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\GOOGLE\GOOGLE~2\BAK

07/12/2007 10:13 PM 68,856 GoogleToolbarNotifier.exe
1 File(s) 68,856 bytes

Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

09/13/2004 04:49 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK

04/12/2005 04:44 PM 1,187,899 MpfTray.exe
1 File(s) 1,187,899 bytes

Directory of C:\PROGRA~1\PURENE~1\PORTMA~1\BAK

04/05/2004 05:33 PM 99,480 PortAOL.exe
1 File(s) 99,480 bytes

Directory of C:\PROGRA~1\REAL\REALON~1\BAK

05/26/2006 08:21 AM 1,003,520 realplay.exe
1 File(s) 1,003,520 bytes

Directory of C:\PROGRA~1\SCANSOFT\PAPERP~1\BAK

02/27/2003 02:40 AM 40,960 IndexSearch.exe
02/27/2003 02:12 AM 57,393 pptd40nt.exe
2 File(s) 98,353 bytes

Directory of C:\PROGRA~1\SKYPE\PHONE\BAK

08/17/2007 03:45 AM 23,120,680 Skype.exe
1 File(s) 23,120,680 bytes

Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK

06/18/2002 01:01 AM 155,648 sgtray.exe
1 File(s) 155,648 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK

10/23/2006 08:50 AM 71,216 AOLDial.exe
1 File(s) 71,216 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

04/26/2003 02:30 AM 151,597 realsched.exe
1 File(s) 151,597 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\112568~1\EE\BAK

09/25/2006 08:52 PM 50,736 AOLSoftware.exe
1 File(s) 50,736 bytes

Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK

10/25/2001 02:20 PM 36,864 printray.exe
1 File(s) 36,864 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE"
45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe"
45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe"
24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe"
50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE"
74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph"
24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph"
24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph"
1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph"
1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph"
1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph"
2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph"
45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe"
45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe"
24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe"
50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE"
50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE"
74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph"
24 Sep 11 2007 "C:\Program Files\America Online 9.0a\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph"
24 Sep 16 2007 "C:\Program Files\AOL 9.0b\shellmon.ph"
24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph"
24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph"
1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph"
1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph"
1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph"
2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph"
53248 Jun 14 2001 "C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe"
40960 Oct 18 2001 "C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe"
591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe"
366400 Dec 11 2006 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe"
98304 Sep 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe"
212992 Sep 14 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
199 Sep 16 2003 "C:\WINDOWS\system\hpsysdrv.DAT"
183 Nov 26 2007 "C:\WINDOWS\system\bak\hpsysdrv.DAT"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Mar 11 2003 "C:\hp\drivers\video\865\hkcmd.exe"
114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe"
81920 Jul 31 2002 "C:\hp\drivers\keyboard\PS2.EXE"
81920 Jul 31 2002 "C:\WINDOWS\system32\bak\ps2.exe"
52272 Nov 16 2007 "C:\Program Files\Google\googletoolbar1user.exe"
441088 Nov 17 2003 "C:\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe"
69632 May 24 2007 "C:\Program Files\Google\Google Earth\googleearth.exe"
126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe"
138680 Nov 16 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe"
26694 Jul 15 2007 "C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe"
49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe"
99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe"
1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\bak\realplay.exe"
40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe"
57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe"
23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe"
155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe"
71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe"
36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe"
36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe"


end of report
Hi

Fix AWF Infection Step 2
Copy the file paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

"C:\hp\KBD\bak\KBD.EXE"
"C:\Program Files\America Online 9.0a\bak\AOL.EXE"
"C:\Program Files\AOL 9.0b\bak\AOL.EXE"
"C:\Program Files\America Online 9.0a\bak\shellmon.ph"
"C:\Program Files\AOL 9.0b\bak\shellmon.ph"
"C:\Program Files\America Online 9.0a\bak\AOL.EXE"
"C:\Program Files\AOL 9.0b\bak\AOL.EXE"
"C:\Program Files\America Online 9.0a\bak\shellmon.ph"
"C:\Program Files\AOL 9.0b\bak\shellmon.ph"
"C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe"
"C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe"
"C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
"C:\WINDOWS\system\bak\hpsysdrv.DAT"
"C:\WINDOWS\system\bak\hpsysdrv.exe"
"C:\WINDOWS\system32\bak\hkcmd.exe"
"C:\WINDOWS\system32\bak\ps2.exe"
"C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
"C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
"C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe"
"C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe"
"C:\Program Files\Real\RealOne Player\bak\realplay.exe"
"C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe"
"C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe"
"C:\Program Files\Skype\Phone\bak\Skype.exe"
"C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe"
"C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe"
"C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe"

  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Press 2 then Enter
  • Notepad will open a file named FindAWF.txt. It will appear with instructions to click below the line and paste the list of files to be restored.
  • Right click below this line and select Edit, Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
  • The program will proceed to move the legit files and will perform another scan for bak folders.
  • It may take a few minutes to complete, so please be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
I completed the AWF option 2. Here is the new AWF.txt file: Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: Mon 12/31/2007 The current time is: 17:46:08.89 bak folders found ~~~~~~~~~~~ Directory of C:\HP\KBD\BAK 02/11/2003 11:02 PM 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of C:\PROGRA~1\AMERIC~1.0A\BAK 07/12/2005 01:17 AM 50,776 AOL.EXE 09/19/2007 09:27 PM 24 shellmon.ph 2 File(s) 50,800 bytes Directory of C:\PROGRA~1\AOL9~1.0B\BAK 04/18/2007 02:49 AM 50,736 AOL.EXE 11/19/2007 09:12 AM 24 shellmon.ph 2 File(s) 50,760 bytes Directory of C:\PROGRA~1\LEXMAR~1\BAK 06/14/2001 12:42 PM 53,248 AcBtnMgr_X83.exe 10/18/2001 10:25 AM 40,960 ACMonitor_X83.exe 2 File(s) 94,208 bytes Directory of C:\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\PICASA2\BAK 12/11/2006 08:36 PM 366,400 PicasaMediaDetector.exe 1 File(s) 366,400 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 09/02/2005 02:16 PM 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of C:\WINDOWS\SMINST\BAK 09/14/2002 12:42 AM 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of C:\WINDOWS\SYSTEM\BAK 11/26/2007 08:47 AM 183 hpsysdrv.DAT 05/07/1998 07:04 PM 52,736 hpsysdrv.exe 2 File(s) 52,919 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 03/11/2003 08:11 PM 114,688 hkcmd.exe 07/31/2002 11:28 PM 81,920 ps2.exe 2 File(s) 196,608 bytes Directory of C:\PROGRA~1\BROADJ~1\CLIENT~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\GOOGLE\GOOGLE~2\BAK 07/12/2007 10:13 PM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK 09/13/2004 04:49 PM 49,152 HPWuSchd2.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 04/12/2005 04:44 PM 1,187,899 MpfTray.exe 1 File(s) 1,187,899 bytes Directory of C:\PROGRA~1\PURENE~1\PORTMA~1\BAK 04/05/2004 05:33 PM 99,480 PortAOL.exe 1 File(s) 99,480 bytes Directory of C:\PROGRA~1\REAL\REALON~1\BAK 05/26/2006 08:21 AM 1,003,520 realplay.exe 1 File(s) 1,003,520 bytes Directory of C:\PROGRA~1\SCANSOFT\PAPERP~1\BAK 02/27/2003 02:40 AM 40,960 IndexSearch.exe 02/27/2003 02:12 AM 57,393 pptd40nt.exe 2 File(s) 98,353 bytes Directory of C:\PROGRA~1\SKYPE\PHONE\BAK 08/17/2007 03:45 AM 23,120,680 Skype.exe 1 File(s) 23,120,680 bytes Directory of C:\PROGRA~1\VERITA~1\UPDATE~1\BAK 06/18/2002 01:01 AM 155,648 sgtray.exe 1 File(s) 155,648 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 10/23/2006 08:50 AM 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 04/26/2003 02:30 AM 151,597 realsched.exe 1 File(s) 151,597 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\112568~1\EE\BAK 09/25/2006 08:52 PM 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK 10/25/2001 02:20 PM 36,864 printray.exe 1 File(s) 36,864 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 61440 Feb 11 2003 "C:\hp\KBD\KBD.EXE" 61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\AOL.EXE" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\AOL.EXE" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 45125 Dec 18 2002 "C:\Program Files\America Online 8.0\aol.exe" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\AOL.EXE" 45140 Sep 24 2003 "C:\Program Files\America Online 9.0\aol.exe" 24576 Aug 27 1999 "C:\Program Files\America Online 5.0\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0a\aol.exe" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\AOL.EXE" 50776 Jul 12 2005 "C:\Program Files\America Online 9.0a\bak\AOL.EXE" 50736 Apr 18 2007 "C:\Program Files\AOL 9.0b\bak\AOL.EXE" 74 Sep 16 2007 "C:\Program Files\America Online 8.0\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0\shellmon.ph" 24 Sep 16 2007 "C:\Program Files\AOL 9.0a\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\shellmon.ph" 24 Sep 19 2007 "C:\Program Files\America Online 9.0a\bak\shellmon.ph" 24 Nov 19 2007 "C:\Program Files\AOL 9.0b\bak\shellmon.ph" 1693 Oct 21 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\shellmon.ph" 1646 Sep 26 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0a\shellmon.ph" 1634 Sep 24 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0a\shellmon.ph" 2402 Dec 14 2007 "C:\Documents and Settings\All Users\Application Data\AOL\C_AOL 9.0b\shellmon.ph" 53248 Jun 14 2001 "C:\Program Files\LexmarkX83\AcBtnMgr_X83.exe" 53248 Jun 14 2001 "C:\Program Files\LexmarkX83\bak\AcBtnMgr_X83.exe" 40960 Oct 18 2001 "C:\Program Files\LexmarkX83\ACMonitor_X83.exe" 40960 Oct 18 2001 "C:\Program Files\LexmarkX83\bak\ACMonitor_X83.exe" 591416 Sep 27 2007 "C:\Program Files\Picasa2\PicasaUpdate.exe" 366400 Dec 11 2006 "C:\Program Files\Picasa2\bak\PicasaMediaDetector.exe" 665160 Sep 27 2007 "C:\Program Files\Picasa2\cdautorun\PicasaRestore.exe" 98304 Sep 2 2005 "C:\Program Files\QuickTime\qttask.exe" 98304 Sep 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 212992 Sep 14 2002 "C:\WINDOWS\SMINST\RECGUARD.EXE" 212992 Sep 14 2002 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 183 Nov 26 2007 "C:\WINDOWS\system\hpsysdrv.DAT" 183 Nov 26 2007 "C:\WINDOWS\system\bak\hpsysdrv.DAT" 52736 May 7 1998 "C:\WINDOWS\system\hpsysdrv.exe" 52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\bak\hkcmd.exe" 114688 Mar 11 2003 "C:\hp\drivers\video\865\hkcmd.exe" 114688 Mar 11 2003 "C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\hkcmd.exe" 81920 Jul 31 2002 "C:\WINDOWS\system32\ps2.exe" 81920 Jul 31 2002 "C:\hp\drivers\keyboard\PS2.EXE" 81920 Jul 31 2002 "C:\WINDOWS\system32\bak\ps2.exe" 52272 Nov 16 2007 "C:\Program Files\Google\googletoolbar1user.exe" 441088 Nov 17 2003 "C:\Program Files\America Online 5.0\download\GoogleToolbarInstaller.exe" 69632 May 24 2007 "C:\Program Files\Google\Google Earth\googleearth.exe" 68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" 138680 Nov 16 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 12 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 126136 Nov 16 2007 "C:\Program Files\Google\Google Updater\2.2.969.23408\GoogleUpdaterRestartManager.exe" 26694 Jul 15 2007 "C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe" 49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" 49152 Sep 13 2004 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe" 1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe" 1187899 Apr 12 2005 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\PortAOL.exe" 99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe" 1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\realplay.exe" 1003520 May 26 2006 "C:\Program Files\Real\RealOne Player\bak\realplay.exe" 40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" 40960 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\IndexSearch.exe" 57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" 57393 Feb 27 2003 "C:\Program Files\ScanSoft\PaperPort\bak\pptd40nt.exe" 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\Skype.exe" 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" 155648 Jun 18 2002 "C:\Program Files\VERITAS Software\Update Manager\bak\sgtray.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" 151597 Apr 26 2003 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\AOLSoftware.exe1189973455" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1125684819\EE\bak\AOLSoftware.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\printray.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\lexmarklexmark_x83d8e5\printray.exe" 36864 Oct 25 2001 "C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\printray.exe" end of report
Hi
Fix AWF Infection Step 3

Copy the paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\hp\KBD\bak
C:\Program Files\America Online 9.0a\bak
C:\Program Files\AOL 9.0b\bak
C:\Program Files\LexmarkX83\bak
C:\Program Files\Picasa2\bak
C:\Program Files\QuickTime\bak
C:\WINDOWS\SMINST\bak
C:\WINDOWS\system\bak
C:\WINDOWS\system32\bak
C:\Program Files\Google\GoogleToolbarNotifier\bak
C:\Program Files\HP\HP Software Update\bak
C:\Program Files\McAfee.com\Personal Firewall\bak
C:\Program Files\Pure Networks\Port Magic\bak
C:\Program Files\Real\RealOne Player\bak
C:\Program Files\ScanSoft\PaperPort\bak
C:\Program Files\Skype\Phone\bak
C:\Program Files\VERITAS Software\Update Manager\bak
C:\Program Files\Common Files\AOL\ACS\bak
C:\Program Files\Common Files\Real\Update_OB\bak
C:\Program Files\Common Files\AOL\1125684819\EE\bak
C:\WINDOWS\system32\spool\drivers\w32x86\3\bak

  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Select Option 3 from the menu and press Enter.
  • Press any key to continue.
  • A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
  • Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
  • The program will proceed to remove the folders and will perform another scan for bak folders.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
Before you close FindAWF, Select Option 4 from the menu and press Enter.
When it's finished the tool will return to the main menu.
Press E to close FindAWF.


Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete. This includes your anti-virus. Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet.Re-enable the anti-virus before reconnecting to the Internet.
Here is the AWF.txt from after I ran FindAWF with Option 3. But, when FindAWF completed and I viewed the resulting AWT.txt file in NotePad, the FindAWF closed. I did not complete the instruction for me to select option 4 and then E before closing, as the program closed by itself. Should I rerun FindAWF now and select option 4, and then E to exit? Thanks, Ron Cobb ——————————————– Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Tue 01/01/2008 The current time is: 12:11:29.06 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\BROADJ~1\CLIENT~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\SKYPE\PHONE\BAK 08/17/2007 03:45 AM 23,120,680 Skype.exe 1 File(s) 23,120,680 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 10/23/2006 08:50 AM 71,216 AOLDial.exe 1 File(s) 71,216 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\Skype.exe" 23120680 Aug 17 2007 "C:\Program Files\Skype\Phone\bak\Skype.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" end of report
Here is the Kaspersky report: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Wednesday, January 02, 2008 9:46:59 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 2/01/2008 Kaspersky Anti-Virus database records: 501268 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ H:\ Scan Statistics: Total number of scanned objects: 117797 Number of viruses found: 39 Number of infected objects: 134 Number of suspicious objects: 8 Duration of the scan process: 03:25:16 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\logout.edb Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{28CB9AE0-EEDE-4512-B122-1FB33C90F2D1}.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{91C0FAEA-BE05-4C7B-8481-22F5396561F7}.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{B94E9453-C795-419A-B382-DD728F18ED33}.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR2.tmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader.zip/stcloader.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1275OinUninstaller.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle2.zip/Yazzle1275OinUninstaller.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle2.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle4.zip/Yazzle1275OinUninstaller.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle4.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012008010120080102\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\hpodvd09.log Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped C:\Program Files\America Online 9.0a\download\xz.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\Program Files\America Online 9.0a\download\xz.exe NSIS: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\01754AC2 Infected: not-a-virus:AdWare.Win32.BiSpy.n skipped C:\Program Files\Norton AntiVirus\Quarantine\01DB40C9 Infected: not-a-virus:AdWare.Win32.Adtomi.e skipped C:\Program Files\Norton AntiVirus\Quarantine\02943A50 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\029E3845 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\02A16242 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\08C274DE Infected: not-a-virus:AdWare.Win32.ClearSearch.c skipped C:\Program Files\Norton AntiVirus\Quarantine\0F792F70 Infected: not-a-virus:AdWare.Win32.ClearSearch.c skipped C:\Program Files\Norton AntiVirus\Quarantine\141F15EE Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\189642BF Infected: not-a-virus:AdWare.Win32.BetterInternet skipped C:\Program Files\Norton AntiVirus\Quarantine\19C13365 Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\1C030337 Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\1DBA5368 Infected: not-a-virus:AdWare.Win32.Adtomi.e skipped C:\Program Files\Norton AntiVirus\Quarantine\1F5D2576 Infected: Trojan-Downloader.Win32.WinShow.a skipped C:\Program Files\Norton AntiVirus\Quarantine\21D2676C Infected: not-a-virus:AdWare.Win32.ClearSearch.c skipped C:\Program Files\Norton AntiVirus\Quarantine\24267EBE Infected: not-a-virus:AdWare.Win32.BetterInternet skipped C:\Program Files\Norton AntiVirus\Quarantine\248C74C5 Infected: Trojan-Downloader.Win32.Small.go skipped C:\Program Files\Norton AntiVirus\Quarantine\24F26ACD Infected: Trojan.Win32.SecondThought.ag skipped C:\Program Files\Norton AntiVirus\Quarantine\27745D64/1/e.exe Infected: Trojan-Dropper.Win32.Small.yd skipped C:\Program Files\Norton AntiVirus\Quarantine\27745D64/2/l.html Infected: Trojan-Downloader.JS.Small.v skipped C:\Program Files\Norton AntiVirus\Quarantine\27745D64 CHM: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\27745D64 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\2BFB775F/WISE0006.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.c skipped C:\Program Files\Norton AntiVirus\Quarantine\2BFB775F/WISE0007.BIN/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Program Files\Norton AntiVirus\Quarantine\2BFB775F/WISE0007.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Program Files\Norton AntiVirus\Quarantine\2BFB775F WiseSFX: infected - 3 skipped C:\Program Files\Norton AntiVirus\Quarantine\2BFB775F WiseSFXDropper: infected - 3 skipped C:\Program Files\Norton AntiVirus\Quarantine\2BFB775F CryptFF: infected - 3 skipped C:\Program Files\Norton AntiVirus\Quarantine\306E4A24 Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\30717420 Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\30741E1C Infected: Trojan.Win32.Kolweb.f skipped C:\Program Files\Norton AntiVirus\Quarantine\30A46CCB Infected: Trojan-Downloader.Win32.Small.go skipped C:\Program Files\Norton AntiVirus\Quarantine\318A650F Infected: Net-Worm.Win32.Lovesan.a skipped C:\Program Files\Norton AntiVirus\Quarantine\34CB5BD5/index.exe Infected: Trojan-Dropper.Win32.Delf.ev skipped C:\Program Files\Norton AntiVirus\Quarantine\34CB5BD5/index.htm Infected: Trojan-Downloader.VBS.Psyme.a skipped C:\Program Files\Norton AntiVirus\Quarantine\34CB5BD5 CHM: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\34CB5BD5 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\34CE05D1/index.exe Infected: Trojan-Dropper.Win32.Delf.ev skipped C:\Program Files\Norton AntiVirus\Quarantine\34CE05D1/index.htm Infected: Trojan-Downloader.VBS.Psyme.a skipped C:\Program Files\Norton AntiVirus\Quarantine\34CE05D1 CHM: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\34CE05D1 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\3773126D Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\37773C69 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\377A6666 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\377D1062 Infected: Trojan-Downloader.Win32.WinShow.a skipped C:\Program Files\Norton AntiVirus\Quarantine\37803A5E Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\399D1D84 Infected: Trojan-Downloader.Win32.WinShow.a skipped C:\Program Files\Norton AntiVirus\Quarantine\3BAD6CC2 Infected: Trojan-Downloader.Win32.Small.go skipped C:\Program Files\Norton AntiVirus\Quarantine\3C1362CA Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\3CDF4ED9 Infected: Trojan-Spy.Win32.Idly.c skipped C:\Program Files\Norton AntiVirus\Quarantine\424D623C Infected: Trojan.Win32.Kolweb.f skipped C:\Program Files\Norton AntiVirus\Quarantine\460562BE Infected: Trojan.Win32.SecondThought.bf skipped C:\Program Files\Norton AntiVirus\Quarantine\473D28C1 Infected: Trojan-Downloader.Win32.Agent.ae skipped C:\Program Files\Norton AntiVirus\Quarantine\47A31EC9/data0002 Infected: not-a-virus:AdWare.Win32.BookedSpace.b skipped C:\Program Files\Norton AntiVirus\Quarantine\47A31EC9 NSIS: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\47A31EC9 CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\4AA106EB.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped C:\Program Files\Norton AntiVirus\Quarantine\4BFC0650 Infected: Trojan-Downloader.Win32.Small.wj skipped C:\Program Files\Norton AntiVirus\Quarantine\4E5737EF Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\51A00946.exe Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\54B115CE.exe Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\563B2538 Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\581B5B13/1/e.exe Infected: Trojan-Dropper.Win32.Small.yd skipped C:\Program Files\Norton AntiVirus\Quarantine\581B5B13/2/l.html Infected: Trojan-Downloader.JS.Small.v skipped C:\Program Files\Norton AntiVirus\Quarantine\581B5B13 CHM: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\581B5B13 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\58EE7C22 Infected: not-a-virus:AdWare.Win32.BiSpy.n skipped C:\Program Files\Norton AntiVirus\Quarantine\593813D7 Infected: Trojan.WinREG.StartPage skipped C:\Program Files\Norton AntiVirus\Quarantine\598D7D93/1/e.exe Infected: Trojan-Dropper.Win32.Small.yd skipped C:\Program Files\Norton AntiVirus\Quarantine\598D7D93/2/l.html Infected: Trojan-Downloader.JS.Small.v skipped C:\Program Files\Norton AntiVirus\Quarantine\598D7D93 CHM: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\598D7D93 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\59954777 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\5EC416C6 Infected: Trojan-Dropper.Win32.Small.ff skipped C:\Program Files\Norton AntiVirus\Quarantine\5F2A0CCD Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\5FE27EDC.class Infected: Exploit.Java.ByteVerify skipped C:\Program Files\Norton AntiVirus\Quarantine\61E82CDB Infected: not-a-virus:AdWare.Win32.ClearSearch.c skipped C:\Program Files\Norton AntiVirus\Quarantine\65250375 Infected: Trojan-Downloader.Win32.WinShow.a skipped C:\Program Files\Norton AntiVirus\Quarantine\673643C5.class Infected: Trojan.Java.ClassLoader.c skipped C:\Program Files\Norton AntiVirus\Quarantine\68342330 Infected: Trojan-Spy.Win32.Idly.c skipped C:\Program Files\Norton AntiVirus\Quarantine\686942F7/WISE0007.BIN Infected: Trojan-Downloader.Win32.VB.ca skipped C:\Program Files\Norton AntiVirus\Quarantine\686942F7/WISE0008.BIN Infected: Trojan.Win32.Revop.c skipped C:\Program Files\Norton AntiVirus\Quarantine\686942F7 WiseSFX: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\686942F7 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\686C6CF3/WISE0007.BIN Infected: Trojan-Downloader.Win32.VB.ca skipped C:\Program Files\Norton AntiVirus\Quarantine\686C6CF3/WISE0008.BIN Infected: Trojan.Win32.Revop.c skipped C:\Program Files\Norton AntiVirus\Quarantine\686C6CF3 WiseSFX: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\686C6CF3 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\686F16F0/WISE0006.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.c skipped C:\Program Files\Norton AntiVirus\Quarantine\686F16F0/WISE0007.BIN/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Program Files\Norton AntiVirus\Quarantine\686F16F0/WISE0007.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Program Files\Norton AntiVirus\Quarantine\686F16F0 WiseSFX: infected - 3 skipped C:\Program Files\Norton AntiVirus\Quarantine\686F16F0 WiseSFXDropper: infected - 3 skipped C:\Program Files\Norton AntiVirus\Quarantine\686F16F0 CryptFF: infected - 3 skipped C:\Program Files\Norton AntiVirus\Quarantine\687240EC Infected: Trojan.Win32.SecondThought.ag skipped C:\Program Files\Norton AntiVirus\Quarantine\687914E5 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\687C3EE1 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\687F68DE Infected: Trojan-Downloader.Win32.Delf.ep skipped C:\Program Files\Norton AntiVirus\Quarantine\688312DA/data0002 Infected: not-a-virus:AdWare.Win32.BookedSpace.b skipped C:\Program Files\Norton AntiVirus\Quarantine\688312DA NSIS: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\688312DA CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\68863CD6 Infected: Trojan.Win32.SecondThought.bg skipped C:\Program Files\Norton AntiVirus\Quarantine\688966D3 Infected: Trojan.Win32.SecondThought.ba skipped C:\Program Files\Norton AntiVirus\Quarantine\68903ACC Infected: Trojan-Dropper.Win32.Small.ff skipped C:\Program Files\Norton AntiVirus\Quarantine\689364C8 Infected: Trojan-Downloader.Win32.Small.go skipped C:\Program Files\Norton AntiVirus\Quarantine\68960EC4 Infected: Trojan.Win32.SecondThought.ao skipped C:\Program Files\Norton AntiVirus\Quarantine\689A38C1 Infected: Trojan.Win32.SecondThought.ao skipped C:\Program Files\Norton AntiVirus\Quarantine\68A00CBA Infected: not-a-virus:AdWare.Win32.BetterInternet skipped C:\Program Files\Norton AntiVirus\Quarantine\68A336B6 Infected: Trojan.Win32.SecondThought.av skipped C:\Program Files\Norton AntiVirus\Quarantine\68A760B2 Infected: Trojan-Downloader.Win32.Delf.ep skipped C:\Program Files\Norton AntiVirus\Quarantine\68AD34AB Infected: Exploit.HTML.CodeBaseExec skipped C:\Program Files\Norton AntiVirus\Quarantine\68B05EA8 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\68B408A4 Infected: not-a-virus:AdWare.Win32.ImiBar.b skipped C:\Program Files\Norton AntiVirus\Quarantine\68B732A0 Infected: not-a-virus:AdWare.Win32.BetterInternet skipped C:\Program Files\Norton AntiVirus\Quarantine\68E627E5 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\6ABB48CC Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\6C3D445E Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\6C406E5B Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\6C474253 Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\6DEB0AF6.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped C:\Program Files\Norton AntiVirus\Quarantine\71033965 Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\71076361 Infected: Trojan.Win32.Kolweb.g skipped C:\Program Files\Norton AntiVirus\Quarantine\710A0D5E Infected: Trojan.Win32.Kolweb.f skipped C:\Program Files\Norton AntiVirus\Quarantine\764B04CB Infected: Trojan.Win32.Kolweb.a skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABA1F82/1/e.exe Infected: Trojan-Dropper.Win32.Small.yd skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABA1F82/2/l.html Infected: Trojan-Downloader.JS.Small.v skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABA1F82 CHM: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABA1F82 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABD497F/1/e.exe Infected: Trojan-Dropper.Win32.Small.yd skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABD497F/2/l.html Infected: Trojan-Downloader.JS.Small.v skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABD497F CHM: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\7ABD497F CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\7C90160D Infected: Trojan.Win32.Kolweb.a skipped C:\System Volume Information\_restore{84385F41-106C-4862-86C4-CE41F08F6FCF}\RP1155\change.log Object is locked skipped C:\WINDOWS\Debug\oakley.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\Temp\mcafee_jz7DULHqoHyuX5z Object is locked skipped C:\WINDOWS\Temp\mcafee_WGxXq0jQNzkfQah Object is locked skipped C:\WINDOWS\Temp\mcafee_ZjUFsjTqkZEpajf Object is locked skipped C:\WINDOWS\Temp\mcmsc_5qlrqxgojW3cVpn Object is locked skipped C:\WINDOWS\Temp\mcmsc_6YNywkqmiB8xgHQ Object is locked skipped C:\WINDOWS\Temp\mcmsc_e9Zrr2k8XbTdXNK Object is locked skipped C:\WINDOWS\Temp\mcmsc_g79bB1wpu0GOGaU Object is locked skipped C:\WINDOWS\Temp\mcmsc_KZPvxgeW43wABKk Object is locked skipped C:\WINDOWS\Temp\mcmsc_RhorKwQyOZEzYRC Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Well, the good news is, there is no sign of AWF. I see there is a Norton Quarantine folder on your computer. You use McAfee now so will it be okay for me to nuke that Norton folder?
Scotty, Right on the Norton. I haven't used Norton for quite a while now, so I think we can kill any residual folders. I'm pretty sure I uninstalled the program, since it doesnt show up in the list of Control Panel/ Add-Remove Programs. I tried opening one of the programs that I previously had problems with, Veritas, and still seem to have the original problem. What happens is that when I open the program (double click the desktop icon, or select from the Start Menu), the first thing that happens is that a Windows Installer window comes up and is trying to install something. I click Cancel a couple of times and it (the Windows Installer window ) then goes away, and the Veritas program then comes up and runs. Seems to run Ok. This program, along with the ScanSoft program which had the same problem, was in the Find AWL.txt file I posted. This also happened with an HP printer related program, but it comes back and says that the program I am trying to install is on a CD, which I should insert into the drive. So, maybe there is something else buried somewhere other than the AWF problem. Do you think I should uninstall these two programs and install them again to see if this Windows Installer thing would stop? Thanks, I really appreciate your efforts and patience with me on this problem. I have had some problems in the past, but nothing like this one. Ron Cobb
Hi

Navigate to and delete the following files and/or folders (if they are present):

File::
C:\Program Files\America Online 9.0a\download\xz.exe

Folders:
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle4.zip
C:\Program Files\Norton AntiVirus


I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Viewpoint Media Player , click Remove.


Try uninstalling and re-installing those programs to see if that helps.
Scotty, I removed Viewpoint as you suggested. Then I removed the Veritas software, and deleted all the Veritas folders in the C:Program Files folder, as the uninstall did not remove them. I then installed the Veritas software from the original disk which came with a Sony DVD Drive I added to my system a couple of years ago. This installation asked to install Viewpoint, so that is where it must have come from originally. I did not install it again. Sadly, when I ran the RecordNow Veritas program I had just installed, the same thing happened as before with the Windows Installer window popping up. I clicked cancel a couple of times and the program opened, seemingly OK, but I did not write a CD to check if it works. Seems strange that this issue could survive an uninstall and reinstall. Any ideas? I did not yet reinstall the ScanSoft or other programs exhibiting the same problem. As best I recall from the beginning of this problem, all these programs I had started from the recently used programs list in the Windows Start Menu. Thanks Ron Cobb
OK, Thanks.

Here is a current HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:32:09 AM, on 1/3/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\System32\WDBtnMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\program files\common files\aol\1125684819\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1125684819\ee\aolsoftware.exe
C:\Program Files\AOL 9.0b\waol.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
C:\Program Files\American Systems\EZ Macros\EZMacros.exe
C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\AOL 9.0b\shellmon.exe
C:\Program Files\Outlook Express\msimn.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.myway.com/index/id/top%7Cap.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125684819\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Print Screen Deluxe.lnk = C:\Program Files\American Systems\Print Screen Deluxe\psdeluxe.exe
O4 - Startup: Shortcut to EZMacros.lnk = C:\Program Files\American Systems\EZ Macros\EZMacros.exe
O4 - Startup: URL Address Book.lnk = C:\Program Files\GBCS Software\URL Address Book\Urlbook.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Zip Up The Web Tray Icon.lnk = C:\Program Files\Insight Development\Zip Up The Web Pro\ZUTWTray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.tscmaps.com/shared/viewer/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1189980911625
O16 - DPF: {6BF35011-3AE5-44D3-A8BB-73ED462A0BC0} (EZUploader Control) - http://www.ezprints.com/software/ezuploader.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.rentmanager.com/demo/msrdp.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://www.dlink.com/products/livedemo/plugin/h263ctrl.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.13.16/ttinst.cab
O16 - DPF: {D53A9247-2FEA-4E93-8EEE-9A9B07E8D760} (EZPCropFit Class) - http://www.ezprints.com/software/cropfit.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hi

This could be your problem, and will certainly be the cause of your malware problem. Your Windows is well out of date.

Upgrade to Windows XP Service Pack 2, more information can be found
here. Upgrade as SP2 contains all the latest security patches and has bugs ironed out.
Scotty, I updated Windows. Some of the updates failed to install, but most did successfully. The PaperPort application would then open without the Windows installer window coming up, but the Veritas program still had it. But, this time I could see that the Windows Installer was trying to install TurboTax It's Deductable - a junk program from Intuit that coms with TurboTax, and apparently was installed along with it. So, I uninstalled the TurboTax Its Deductable, and now the Veritas program comes up fine - no Installer window. Not sure how all this has worked, but it seems to be OK now. My system seems a little slower, but I assume that is because the Windows Update process has added a lot of code. I can live with it. So, maybe it is now time to get the restore points corrected, and again set up my backup procedure. Do you agree? Let me know if you need anymore logs, etc. I will need some instructions on deleting old restore points so I can make a new one with all these changes and updates. Thanks Ron Cobb

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI