This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Bad Trojan Infection on computer with vundo, metajuan,

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My computer has been infected with trojans vundo, metajuan, and adclicker. Popups appear randomly and desktop disappears. My ie is almost unusable. Also, My internet connection has slowed to a crawl. Please help. I am running windows xp and here is my hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 5:22:44 PM, on 2/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\aol\1130881873\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1130881873\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\1130881873\ee\aolsoftware.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Symantec AntiVirus\vpc32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\killer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {20A4A73D-EC61-4713-82EE-280B93480D69} - C:\WINDOWS\system32\mlljg.dll
O2 - BHO: (no name) - {A051B1FF-8D7E-418B-AABE-4FF82F4280A2} - C:\WINDOWS\system32\ddcyyyw.dll (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [4afb89af] rundll32.exe "C:\WINDOWS\system32\pxhpcoha.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello chillin15 and welcome to the What the Tech Forums (I thought I recognized the nickname)

My name is Trevuren and I will be helping you with your problem.


Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.

Notes:
Do not mouse-click Combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks for responding Trevuren! I am actually using my friends account but he mentioned that you were very helpful. Sorry for the late reply, here is my combo fix log:


ComboFix 08-02.05.3 - HP_Administrator 2008-02-05 22:33:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.527 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\mlljg.dll
C:\Program Files\WinBudget
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ahocphxp.ini
C:\WINDOWS\system32\flijqula.ini
C:\WINDOWS\system32\gjllm.ini
C:\WINDOWS\system32\gjllm.ini2
C:\WINDOWS\system32\lrotnlnp.ini
C:\WINDOWS\system32\lueqfnlv.ini
C:\WINDOWS\system32\mlljg.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rvaswotb.ini
C:\WINDOWS\system32\udspurxi.ini
C:\WINDOWS\system32\xgaeyhdp.dll
C:\WINDOWS\system32\xjxpicge.dll
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.

2008-02-05 22:41 . 2008-02-05 22:41 294 —hs—- C:\WINDOWS\system32\ahocphxp.ini
2008-02-05 21:57 . 2004-08-10 07:00 388,608 –a—— C:\kmd.exe
2008-02-05 17:17 . 2008-02-05 17:17 90,688 –a—— C:\WINDOWS\system32\pxhpcoha.dll
2008-02-04 21:49 . 2008-02-04 21:51 8,014 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-04 21:49 . 2008-02-04 21:51 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-04 21:19 . 2008-02-04 21:19 d——– C:\Program Files\RogueRemover FREE
2008-02-04 21:16 . 2008-02-04 21:16 d——– C:\Program Files\RogueRemover
2008-02-04 16:55 . 2008-02-04 23:40 2,374,965 –ahs—- C:\WINDOWS\system32\ehtnixqp.ini
2008-02-03 13:31 . 2008-02-03 13:31 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-01-29 19:31 . 2008-01-29 19:33 d——– C:\WINDOWS\BDOSCAN8
2008-01-29 10:56 . 2008-01-29 10:56 16,600 –a—— C:\WINDOWS\BM49c8ba33.xml
2008-01-29 10:56 . 2008-01-29 10:56 22 –a—— C:\WINDOWS\pskt.ini
2008-01-28 18:22 . 2008-01-28 19:01 d——– C:\Documents and Settings\HP_Administrator\.housecall6.6
2008-01-24 00:16 . 2008-01-24 00:16 d——– C:\WINDOWS\system32\nGpxx01
2008-01-24 00:16 . 2008-01-24 00:16 d——– C:\temp\cXzz9
2008-01-24 00:09 . 2008-01-24 00:09 d——– C:\Program Files\DivX
2008-01-13 20:13 . 2008-01-13 20:13 d——– C:\Documents and Settings\HP_Administrator\Application Data\QQ Games Plugin
2008-01-13 20:13 . 2008-01-13 20:13 d——– C:\Documents and Settings\HP_Administrator\Application Data\QQ Games
2008-01-13 20:10 . 2008-01-13 20:10 d——– C:\Program Files\Tencent
2008-01-10 15:27 . 2008-01-10 15:27 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 03:39 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-02-05 21:48 ——— d—–w C:\Program Files\LogMeIn
2008-02-05 02:53 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-05 02:51 110,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-05 02:51 ——— d—–w C:\Program Files\Symantec
2008-02-05 02:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-05 01:04 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-01-29 18:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 16:42 ——— d—–w C:\Program Files\Microsoft AntiSpyware
2008-01-16 15:34 ——— d—–w C:\Program Files\iTunes
2008-01-16 15:34 ——— d—–w C:\Program Files\iPod
2008-01-16 15:32 ——— d—–w C:\Program Files\QuickTime
2008-01-14 01:11 ——— d—–w C:\Program Files\AIM6
2008-01-14 01:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-01-14 01:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-07 22:55 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\U3
2007-12-07 01:18 ——— d—–w C:\Program Files\PlayFirst
2007-12-07 01:18 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\PlayFirst
2007-12-07 01:12 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-06 09:30 ——— d—–w C:\Program Files\Shockwave.com
2007-12-06 09:29 ——— d—–w C:\Program Files\Monopoly Here and Now Edition
2007-12-06 08:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2007-12-06 08:06 ——— d—–w C:\Program Files\MSN Games
2007-02-10 04:54 560 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ViewerApp.dat
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 50,736 2006-09-26 00:52:48 C:\Program Files\Common Files\AOL\1130881873\ee\bak\AOLSoftware.exe
—-a-w 50,736 2006-09-26 00:52:48 C:\Program Files\Common Files\AOL\1130881873\ee\aolsoftware.exe

—-a-r 71,216 2006-10-23 12:50:37 C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe
—-a-r 71,216 2006-10-23 12:50:37 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

—-a-w 256,576 2006-10-30 14:36:36 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 267,048 2008-01-15 08:22:56 C:\Program Files\iTunes\iTunesHelper.exe

—-a-w 282,624 2006-10-25 23:58:18 C:\Program Files\QuickTime\bak\qttask.exe
—-a-w 385,024 2008-01-10 20:27:36 C:\Program Files\QuickTime\QTTask.exe

—-a-w 15,360 2004-08-10 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
—-a-w 15,360 2004-08-10 12:00:00 C:\WINDOWS\system32\ctfmon.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 11:15 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 13:03 63048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-02 13:42 185896]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 19:49 125632]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-02-04 21:52 104080]
"4afb89af"="C:\WINDOWS\system32\pxhpcoha.dll" [2008-02-05 17:17 90688]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 07:00 53760 C:\WINDOWS\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-26 00:19 87352 C:\WINDOWS\system32\LMIinit.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=C:\WINDOWS\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=C:\WINDOWS\pss\Picture Package VCD Maker.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=C:\WINDOWS\pss\SpySubtract.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2004-06-29 12:06 88363 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a—— 2004-10-13 18:00 57344 C:\WINDOWS\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
–a—— 2004-10-13 18:17 2742272 C:\WINDOWS\ALCWZRD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra—— 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2006-11-21 17:38 52840 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-10 07:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2004-08-10 13:04 59392 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a—— 2004-03-18 02:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
–a—— 2004-12-01 12:55 126976 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06]
–a—— 2004-06-07 13:42 659456 C:\WINDOWS\system32\hphmon06.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
–a—— 2004-06-07 13:53 49152 c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
–a—— 1998-05-07 11:04 52736 c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
–a—— 2006-02-17 11:59 124520 C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2003-02-11 14:02 61440 C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
C:\Program Files\LogMeIn\LogMeInSystray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
–a—— 2004-10-14 16:54 253952 c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2006-04-12 11:40 182860 C:\Program Files\Plaxo\2.6.2.15\PlaxoHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
–a—— 2004-10-25 16:17 90112 C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
–a—— 2004-08-24 14:09 99480 C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-10 15:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2004-04-14 15:43 233472 C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-10-13 16:01 77824 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-03-15 20:37 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-02-02 13:42 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
–a—— 2007-03-14 19:49 125632 C:\PROGRA~1\SYMANT~1\VPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"svcWRSSSDK"=2 (0x2)
"SavRoam"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"MDM"=2 (0x2)
"LightScribeService"=2 (0x2)
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
"AOL ACS"=2 (0x2)

R2 CX23880;Conexant 23880 Video Capture;C:\WINDOWS\system32\drivers\cx88vid.sys [2004-11-11 17:37]
R2 CX88ENC;Conexant 2388x MPEG Encoder;C:\WINDOWS\system32\drivers\cx88enc.sys [2004-11-11 17:36]
R2 CXTUNE;Conexant 2388x Tuner;C:\WINDOWS\system32\drivers\CX88TUNE.sys [2004-11-11 17:37]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-04-17 13:00]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 10:55]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R3 CXAVXBAR;Conexant 2388x Crossbar Dual Input ;C:\WINDOWS\system32\drivers\cxavxbar.sys [2004-11-11 17:36]
S2 IcRecUsb;IC Recorder Driver;C:\WINDOWS\system32\Drivers\IcRecUsb.sys [2001-10-01 08:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 15:26:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-06-18 14:17:07 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2008-02-02 01:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Administrator.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 22:41:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\pxhpcoha.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
c:\program files\common files\aol\1130881873\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-05 22:46:58 - machine was rebooted [HP_Administrator]
ComboFix-quarantined-files.txt 2008-02-06 03:46:51
.
2008-01-29 02:42:36 — E O F —






Here is my hijackthis log file:


Logfile of HijackThis v1.99.1
Scan saved at 22:51, on 2008-02-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
c:\program files\common files\aol\1130881873\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1130881873\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\1130881873\ee\aolsoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\killer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [4afb89af] rundll32.exe "C:\WINDOWS\system32\pxhpcoha.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Your system has been infected by a trojan file infector that replaces legitimate files with infected replicas. If you look in the "AWF" section of your last ComboFix log, you will be able to see the files that have been replaced. Luckily, we will be able to reverse the "switch" and delete the infected files. First, we will clean up the rest of your system.


A. I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is often installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
I STRONGLY recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

1. Click Start, then Settings, then click Control Panel.
2. In Control Panel, double-click Add or Remove Programs.
3. In Add or Remove Programs, Remove the Viewpoint component
4. Do the same for each Viewpoint component.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\ahocphxp.ini
C:\kmd.exe
C:\WINDOWS\system32\pxhpcoha.dll
C:\WINDOWS\system32\ehtnixqp.ini
C:\WINDOWS\BM49c8ba33.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\ALCMTR.EXE

Folder::
C:\WINDOWS\system32\nGpxx01
C:\temp\cXzz9

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"4afb89af"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WRNotifier]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=-
[-HKEY_CLASSES_ROOT\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93}]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


D. Just to make sure that no new AWF infected files have appeared since your last logs, please download FindAWF to your Desktop.
  • Double-click FindAWF.exe to start the tool.
  • Select option #1 - Scan for bak folders by typing 1 and press 'Enter'
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
**Do not run any other option unless directed to do so.**
Hello again! Thanks for getting back to me again! Here are the files:



ComboFix Log File:



ComboFix 08-02.05.3 - HP_Administrator 2008-02-05 11:46:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.542 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\kmd.exe
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\BM49c8ba33.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ahocphxp.ini
C:\WINDOWS\system32\ehtnixqp.ini
C:\WINDOWS\system32\pxhpcoha.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\kmd.exe
C:\temp\cXzz9
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\BM49c8ba33.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ahocphxp.ini
C:\WINDOWS\system32\ehtnixqp.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\pxhpcoha.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.

2008-02-04 21:49 . 2008-02-04 21:51 8,014 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-04 21:49 . 2008-02-04 21:51 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-04 21:19 . 2008-02-04 21:19 d——– C:\Program Files\RogueRemover FREE
2008-02-04 21:16 . 2008-02-04 21:16 d——– C:\Program Files\RogueRemover
2008-02-03 13:31 . 2008-02-03 13:31 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-01-29 19:31 . 2008-01-29 19:33 d——– C:\WINDOWS\BDOSCAN8
2008-01-28 18:22 . 2008-01-28 19:01 d——– C:\Documents and Settings\HP_Administrator\.housecall6.6
2008-01-24 00:09 . 2008-01-24 00:09 d——– C:\Program Files\DivX
2008-01-13 20:13 . 2008-01-13 20:13 d——– C:\Documents and Settings\HP_Administrator\Application Data\QQ Games Plugin
2008-01-13 20:13 . 2008-01-13 20:13 d——– C:\Documents and Settings\HP_Administrator\Application Data\QQ Games
2008-01-13 20:10 . 2008-01-13 20:10 d——– C:\Program Files\Tencent
2008-01-10 15:27 . 2008-01-10 15:27 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 21:48 ——— d—–w C:\Program Files\LogMeIn
2008-02-05 16:50 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-02-05 16:43 ——— d—–w C:\Program Files\Viewpoint
2008-02-05 16:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-05 02:53 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-05 02:51 110,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-05 02:51 ——— d—–w C:\Program Files\Symantec
2008-02-05 02:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-05 01:04 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-01-29 18:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 16:42 ——— d—–w C:\Program Files\Microsoft AntiSpyware
2008-01-16 15:34 ——— d—–w C:\Program Files\iTunes
2008-01-16 15:34 ——— d—–w C:\Program Files\iPod
2008-01-16 15:32 ——— d—–w C:\Program Files\QuickTime
2008-01-14 01:11 ——— d—–w C:\Program Files\AIM6
2008-01-14 01:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-01-14 01:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-07 22:55 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\U3
2007-12-07 01:18 ——— d—–w C:\Program Files\PlayFirst
2007-12-07 01:18 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\PlayFirst
2007-12-07 01:12 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-06 09:30 ——— d—–w C:\Program Files\Shockwave.com
2007-12-06 09:29 ——— d—–w C:\Program Files\Monopoly Here and Now Edition
2007-12-06 08:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2007-12-06 08:06 ——— d—–w C:\Program Files\MSN Games
2007-02-10 04:54 560 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\ViewerApp.dat
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 11:15 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 13:03 63048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-02 13:42 185896]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 19:49 125632]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2008-02-04 21:52 104080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 07:00 53760 C:\WINDOWS\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-26 00:19 87352 C:\WINDOWS\system32\LMIinit.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=C:\WINDOWS\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=C:\WINDOWS\pss\Picture Package VCD Maker.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=C:\WINDOWS\pss\SpySubtract.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2004-06-29 12:06 88363 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
–a—— 2004-10-13 18:17 2742272 C:\WINDOWS\ALCWZRD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra—— 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2006-11-21 17:38 52840 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-10 07:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2004-08-10 13:04 59392 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a—— 2004-03-18 02:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
–a—— 2004-12-01 12:55 126976 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06]
–a—— 2004-06-07 13:42 659456 C:\WINDOWS\system32\hphmon06.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
–a—— 2004-06-07 13:53 49152 c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
–a—— 1998-05-07 11:04 52736 c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
–a—— 2006-02-17 11:59 124520 C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2003-02-11 14:02 61440 C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
–a—— 2004-10-14 16:54 253952 c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2006-04-12 11:40 182860 C:\Program Files\Plaxo\2.6.2.15\PlaxoHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
–a—— 2004-10-25 16:17 90112 C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
–a—— 2004-08-24 14:09 99480 C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-10 15:27 385024 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2004-04-14 15:43 233472 C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-10-13 16:01 77824 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-03-15 20:37 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-02-02 13:42 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
–a—— 2007-03-14 19:49 125632 C:\PROGRA~1\SYMANT~1\VPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"svcWRSSSDK"=2 (0x2)
"SavRoam"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"MDM"=2 (0x2)
"LightScribeService"=2 (0x2)
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
"AOL ACS"=2 (0x2)

R2 CX23880;Conexant 23880 Video Capture;C:\WINDOWS\system32\drivers\cx88vid.sys [2004-11-11 17:37]
R2 CX88ENC;Conexant 2388x MPEG Encoder;C:\WINDOWS\system32\drivers\cx88enc.sys [2004-11-11 17:36]
R2 CXTUNE;Conexant 2388x Tuner;C:\WINDOWS\system32\drivers\CX88TUNE.sys [2004-11-11 17:37]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-04-17 13:00]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 10:55]
R3 CXAVXBAR;Conexant 2388x Crossbar Dual Input ;C:\WINDOWS\system32\drivers\cxavxbar.sys [2004-11-11 17:36]
S2 IcRecUsb;IC Recorder Driver;C:\WINDOWS\system32\Drivers\IcRecUsb.sys [2001-10-01 08:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 15:26:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-06-18 14:17:07 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2008-02-02 01:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Administrator.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 11:52:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
c:\program files\common files\aol\1130881873\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-05 11:59:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-05 16:59:34
ComboFix2.txt 2008-02-06 03:46:58
.
2008-01-29 02:42:36 — E O F —



Hijackthis log file:



Logfile of HijackThis v1.99.1
Scan saved at 12:01, on 2008-02-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
c:\program files\common files\aol\1130881873\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1130881873\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\1130881873\ee\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\killer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe



Awf log file:




Find AWF report by noahdfear ©2006
Version 1.40

The current date is: 2008-02-05
The current time is: 12:02:11.62


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\ITUNES\BAK

2006-10-30 09:36 256,576 iTunesHelper.exe
1 File(s) 256,576 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

2006-10-25 18:58 282,624 qttask.exe
1 File(s) 282,624 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

2004-08-10 07:00 15,360 ctfmon.exe
1 File(s) 15,360 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK

2006-10-23 07:50 71,216 AOLDial.exe
1 File(s) 71,216 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\LOGMEIN\X86\UPDATE\3-00-606.BAK

2007-05-25 14:21 3,993,935 template.rab
2007-04-05 10:55 5,759 WapClients.cfg
2 File(s) 3,999,694 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\113088~1\EE\BAK

2006-09-25 19:52 50,736 AOLSoftware.exe
1 File(s) 50,736 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

267048 Jan 15 2008 "C:\Program Files\iTunes\iTunesHelper.exe"
256576 Oct 30 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
102400 Feb 4 2008 "C:\WINDOWS\Installer\{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}\iTunesIco.exe"
79144 Jan 16 2008 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.6.0.29\iTunesSetupAdmin.exe"
385024 Jan 10 2008 "C:\Program Files\QuickTime\QTTask.exe"
282624 Oct 25 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
15360 Aug 10 2004 "C:\WINDOWS\system32\ctfmon.exe"
15360 Aug 10 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
4817711 Nov 26 2007 "C:\Program Files\LogMeIn\template.rab"
3993935 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\template.rab"
5750 Nov 26 2007 "C:\Program Files\LogMeIn\WapClients.cfg"
5759 Apr 5 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\WapClients.cfg"
87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll"
80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll"
87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll"
14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll"
63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll"
23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll"
34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll"
23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll"
34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll"
24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll"
10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll"
13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll"
10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll"
13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll"
10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll"
21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll"
24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll"
21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll"
29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll"
26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll"
17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll"
15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll"
15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll"
21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll"
16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll"
15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll"
18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll"
15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll"
16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll"
22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll"
12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll"
16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll"
30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll"
28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll"
28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll"
34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll"
30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll"
83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll"
87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll"
83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll"
87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll"
83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll"
4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll"
3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll"
3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll"
2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll"
540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll"
460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll"
517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll"
443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll"
1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe"
869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe"
1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe"
869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe"
945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe"
697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe"
1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe"
730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe"
475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax"
319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax"
483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax"
327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax"
240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll"
193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll"
239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll"
194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll"
827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe"
599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe"
824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe"
599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe"
120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe"
116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe"
119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe"
112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe"
55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe"
58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe"
55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe"
58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe"
112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll"
111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll"
113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll"
112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll"
68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe"
324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe"
226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe"
324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe"
226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe"
87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll"
80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll"
87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll"
14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll"
63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll"
23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll"
34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll"
23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll"
34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll"
24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll"
10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll"
13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll"
10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll"
13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll"
10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll"
21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll"
24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll"
21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll"
29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll"
26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll"
17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll"
15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll"
15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll"
21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll"
16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll"
15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll"
18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll"
15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll"
16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll"
22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll"
12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll"
16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll"
16696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinterui.dll"
16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterdat.dll"
16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinterui.dll"
16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterdat.dll"
21264 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinteruint.dll"
16448 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinteruint.dll"
30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll"
28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll"
28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll"
34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll"
30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll"
24024 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprocnt.dll"
17472 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprocnt.dll"
83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll"
87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll"
83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll"
87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll"
83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll"
4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll"
3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll"
3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll"
2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll"
540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll"
460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll"
517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll"
443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll"
1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe"
869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe"
1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe"
869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe"
945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe"
697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe"
1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe"
730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe"
475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax"
319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax"
483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax"
327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax"
240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll"
193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll"
239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll"
194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll"
12088 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook9x.dll"
12352 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook9x.dll"
827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe"
599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe"
824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe"
599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe"
120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe"
116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe"
119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe"
112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe"
55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe"
58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe"
55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe"
58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe"
172352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_sc.exe"
172616 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_sc.exe"
112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll"
111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll"
113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll"
112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll"
68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe"
324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe"
226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe"
324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe"
226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe"
42032 May 25 2007 "C:\Program Files\AIM6\aolsoftware.exe"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\aolsoftware.exe"
50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\bak\AOLSoftware.exe"


end of report
Double-click FindAWF.exe to start the tool.
  • Select option #2 - Restore files from bak folders by typing 2 and press 'Enter'
  • A text file will open up. Please copy/paste the content of the following codebox (including the quote marks where applicable) into the text file:
    "C:\Program Files\Common Files\AOL\1130881873\ee\bak\AOLSoftware.exe"
    "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
    "C:\Program Files\iTunes\bak\iTunesHelper.exe"
    "C:\Program Files\QuickTime\bak\qttask.exe"
    C:\WINDOWS\system32\bak\ctfmon.exe
  • Close the .txt file and click 'Yes' to save the changes.
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: 2008-02-05 The current time is: 13:29:00.79 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\ITUNES\BAK 2006-10-30 09:36 256,576 iTunesHelper.exe 1 File(s) 256,576 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 2006-10-25 18:58 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 2004-08-10 07:00 15,360 ctfmon.exe 1 File(s) 15,360 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 2006-10-23 07:50 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\LOGMEIN\X86\UPDATE\3-00-606.BAK 2007-05-25 14:21 3,993,935 template.rab 2007-04-05 10:55 5,759 WapClients.cfg 2 File(s) 3,999,694 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\113088~1\EE\BAK 2006-09-25 19:52 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 256576 Oct 30 2006 "C:\Program Files\iTunes\iTunesHelper.exe" 256576 Oct 30 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 102400 Feb 4 2008 "C:\WINDOWS\Installer\{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}\iTunesIco.exe" 79144 Jan 16 2008 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.6.0.29\iTunesSetupAdmin.exe" 282624 Oct 25 2006 "C:\Program Files\QuickTime\qttask.exe" 282624 Oct 25 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 15360 Aug 10 2004 "C:\WINDOWS\system32\ctfmon.exe" 15360 Aug 10 2004 "C:\WINDOWS\system32\bak\ctfmon.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 4817711 Nov 26 2007 "C:\Program Files\LogMeIn\template.rab" 3993935 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\template.rab" 5750 Nov 26 2007 "C:\Program Files\LogMeIn\WapClients.cfg" 5759 Apr 5 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\WapClients.cfg" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 16696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterdat.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterdat.dll" 21264 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinteruint.dll" 16448 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinteruint.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 24024 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprocnt.dll" 17472 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprocnt.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 12088 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook9x.dll" 12352 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook9x.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 172352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_sc.exe" 172616 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_sc.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" 42032 May 25 2007 "C:\Program Files\AIM6\aolsoftware.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\bak\AOLSoftware.exe" end of report
Double-click FindAWF.exe to start the tool.
  • Select option #3 - Remove bak folders by typing e and press 'Enter'
  • A text file will open up. Please copy/paste the content of the following codebox into the text file:

    C:\PROGRA~1\ITUNES\BAK
    C:\PROGRA~1\QUICKT~1\BAK
    C:\WINDOWS\SYSTEM32\BAK
    C:\PROGRA~1\COMMON~1\AOL\ACS\BAK
    C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK
    C:\PROGRA~1\LOGMEIN\X86\UPDATE\3-00-606.BAK
  • Close the .txt file and click 'Yes' to save the changes.
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: 2008-02-06 The current time is: 2:16:37.68 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 2006-10-23 07:50 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of C:\PROGRA~1\LOGMEIN\X86\UPDATE\3-00-606.BAK 2007-05-25 14:21 3,993,935 template.rab 2007-04-05 10:55 5,759 WapClients.cfg 2 File(s) 3,999,694 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\113088~1\EE\BAK 2006-09-25 19:52 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 4817711 Nov 26 2007 "C:\Program Files\LogMeIn\template.rab" 3993935 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\template.rab" 5750 Nov 26 2007 "C:\Program Files\LogMeIn\WapClients.cfg" 5759 Apr 5 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\WapClients.cfg" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 16696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterdat.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterdat.dll" 21264 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinteruint.dll" 16448 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinteruint.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 24024 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprocnt.dll" 17472 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprocnt.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 12088 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook9x.dll" 12352 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook9x.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 172352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_sc.exe" 172616 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_sc.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" 42032 May 25 2007 "C:\Program Files\AIM6\aolsoftware.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\bak\AOLSoftware.exe" end of report
It looks as if we have to do some of this over:

Double-click FindAWF.exe to start the tool.
  • Select option #2 - Restore files from bak folders by typing 2 and press 'Enter'
  • A text file will open up. Please copy/paste the content of the following codebox into the text file:

    "C:\Program Files\Common Files\AOL\1130881873\ee\bak\AOLSoftware.exe"
    "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
  • Close the .txt file and click 'Yes' to save the changes.
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: 2008-02-06 The current time is: 7:06:41.62 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 2006-10-23 07:50 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of C:\PROGRA~1\LOGMEIN\X86\UPDATE\3-00-606.BAK 2007-05-25 14:21 3,993,935 template.rab 2007-04-05 10:55 5,759 WapClients.cfg 2 File(s) 3,999,694 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\113088~1\EE\BAK 2006-09-25 19:52 50,736 AOLSoftware.exe 1 File(s) 50,736 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 4817711 Nov 26 2007 "C:\Program Files\LogMeIn\template.rab" 3993935 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\template.rab" 5750 Nov 26 2007 "C:\Program Files\LogMeIn\WapClients.cfg" 5759 Apr 5 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\WapClients.cfg" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 16696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterdat.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterdat.dll" 21264 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinteruint.dll" 16448 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinteruint.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 24024 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprocnt.dll" 17472 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprocnt.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 12088 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook9x.dll" 12352 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook9x.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 172352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_sc.exe" 172616 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_sc.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" 42032 May 25 2007 "C:\Program Files\AIM6\aolsoftware.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\AOLSoftware.exe" 50736 Sep 25 2006 "C:\Program Files\Common Files\AOL\1130881873\ee\bak\AOLSoftware.exe" end of report
Double-click FindAWF.exe to start the tool.
  • Select option #3 - Remove bak folders by typing e and press 'Enter'
  • A text file will open up. Please copy/paste the content of the following codebox into the text file:

    C:\PROGRA~1\COMMON~1\AOL\ACS\BAK
    C:\PROGRA~1\LOGMEIN\X86\UPDATE\3-00-606.BAK
    C:\PROGRA~1\COMMON~1\AOL\113088~1\EE\BAK
  • Close the .txt file and click 'Yes' to save the changes.
  • When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here.
Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: 2008-02-06 The current time is: 7:43:53.28 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK 2006-10-23 07:50 71,216 AOLDial.exe 1 File(s) 71,216 bytes Directory of C:\PROGRA~1\LOGMEIN\X86\UPDATE\3-00-606.BAK 2007-05-25 14:21 3,993,935 template.rab 2007-04-05 10:55 5,759 WapClients.cfg 2 File(s) 3,999,694 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" 71216 Oct 23 2006 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" 4817711 Nov 26 2007 "C:\Program Files\LogMeIn\template.rab" 3993935 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\template.rab" 5750 Nov 26 2007 "C:\Program Files\LogMeIn\WapClients.cfg" 5759 Apr 5 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\WapClients.cfg" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" 87352 Nov 26 2007 "C:\WINDOWS\system32\LMIinit.dll" 80696 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIinit.dll" 87352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIinit.dll" 14912 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIinit.dll" 63040 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIinit.dll" 23736 Nov 26 2007 "C:\WINDOWS\system32\lmimirr.dll" 34104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr.dll" 23736 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr.dll" 24000 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr.dll" 10040 Nov 26 2007 "C:\WINDOWS\system32\lmimirr2.dll" 13112 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMImirr2.dll" 10040 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMImirr2.dll" 13376 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMImirr2.dll" 10304 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMImirr2.dll" 21496 Nov 26 2007 "C:\WINDOWS\system32\LMIport.dll" 24376 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIport.dll" 21496 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIport.dll" 29248 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIport.dll" 26176 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIport.dll" 17720 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinter.dll" 15160 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinter.dll" 21568 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinter.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinter.dll" 15160 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinter.dll" 18744 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIprinterui.dll" 15752 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterui.dll" 22080 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIprinterui.dll" 12192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinternt.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterui.dll" 16696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\LMIprinterdat.dll" 16960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinterui.dll" 16696 Nov 26 2007 "C:\WINDOWS\system32\spool\drivers\w32x86\3\LMIprinterdat.dll" 21264 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprinteruint.dll" 16448 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprinteruint.dll" 30008 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIproc.dll" 28472 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIproc.dll" 28472 Nov 26 2007 "C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll" 34368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIproc.dll" 30784 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIproc.dll" 24024 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIprocnt.dll" 17472 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIprocnt.dll" 83288 Nov 26 2007 "C:\WINDOWS\system32\LMIRfsClientNP.dll" 87384 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LMIRfsClientNP.dll" 83288 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LMIRfsClientNP.dll" 87648 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LMIRfsClientNP.dll" 83552 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LMIRfsClientNP.dll" 4743480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeIn.dll" 3892536 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeIn.dll" 3332672 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeIn.dll" 2635328 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeIn.dll" 540480 Nov 26 2007 "C:\Program Files\LogMeIn\x64\LogMeInSystray.dll" 460096 Nov 26 2007 "C:\Program Files\LogMeIn\x86\LogMeInSystray.dll" 517192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\LogMeInSystray.dll" 443976 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\LogMeInSystray.dll" 1284416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\openssl.exe" 869696 Nov 26 2007 "C:\Program Files\LogMeIn\x86\openssl.exe" 1284680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\openssl.exe" 869960 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\openssl.exe" 945984 Nov 26 2007 "C:\Program Files\LogMeIn\x64\raabout.exe" 697664 Nov 26 2007 "C:\Program Files\LogMeIn\x86\raabout.exe" 1014344 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\raabout.exe" 730696 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\raabout.exe" 475136 Nov 26 2007 "C:\Program Files\LogMeIn\x64\racodec.ax" 319488 Nov 26 2007 "C:\Program Files\LogMeIn\x86\racodec.ax" 483840 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\racodec.ax" 327680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\racodec.ax" 240952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rahook.dll" 193848 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook.dll" 239680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rahook.dll" 194112 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook.dll" 12088 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rahook9x.dll" 12352 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rahook9x.dll" 827200 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rainst.exe" 599360 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rainst.exe" 824392 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rainst.exe" 599624 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rainst.exe" 120128 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ramaint.exe" 116032 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ramaint.exe" 119368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ramaint.exe" 112200 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ramaint.exe" 55104 Nov 26 2007 "C:\Program Files\LogMeIn\x64\ra_reboot.exe" 58688 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_reboot.exe" 55368 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\ra_reboot.exe" 58952 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_reboot.exe" 172352 Nov 26 2007 "C:\Program Files\LogMeIn\x86\ra_sc.exe" 172616 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\ra_sc.exe" 112952 Nov 26 2007 "C:\Program Files\LogMeIn\x64\rntfywnd.dll" 111928 Nov 26 2007 "C:\Program Files\LogMeIn\x86\rntfywnd.dll" 113216 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\rntfywnd.dll" 112192 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\rntfywnd.dll" 68096 Aug 31 2000 "C:\WINDOWS\system32\zip.exe" 324416 Nov 26 2007 "C:\Program Files\LogMeIn\x64\zip.exe" 226624 Nov 26 2007 "C:\Program Files\LogMeIn\x86\zip.exe" 324680 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x64\zip.exe" 226888 May 25 2007 "C:\Program Files\LogMeIn\x86\update\3-00-606.bak\x86\zip.exe" end of report
Well there is only one way to find out if those two remaining files are worth worrying about:

1. Double-click the FindAWF icon once again

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 4 then Enter to reset domain zones

This removes all entries from the domain zones.
When the program returns to the main menu, use the following option:
Press E then Enter to EXIT

2. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
No Security Alert Window showed up when double clicking the AWF File. Here is the Kaspersky result (it stated that my computer is infected): ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT 2008-02-07 00:31 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 7/02/2008 Kaspersky Anti-Virus database records: 552902 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ M:\ Scan Statistics: Total number of scanned objects: 119625 Number of viruses found: 5 Number of infected objects: 31 Number of suspicious objects: 0 Duration of the scan process: 01:37:00 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d3761a5b4dc0ebd045e71faed1a324d_2e67e30a-8aea-4b6a-abe0-fd657a9a02a6 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-02-05_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09840000\4FA7D123.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B3C0001\4FBD2B3E.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.auj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D300001\4FB8E0B4.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EB00001\4FB90F9E.VBN Infected: not-a-virus:AdWare.Win32.SuperJuan.auj skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_1257998592_10354688_45433 Object is locked skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE9.tmp Object is locked skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{999563EA-9CC1-4299-BD82-6520E3389FF6}.TmpSBE Object is locked skipped C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\cert8.db Object is locked skipped C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\formhistory.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\history.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\key3.db Object is locked skipped C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\parent.lock Object is locked skipped C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\search.sqlite Object is locked skipped C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\HP_Administrator\Cookies\index.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\AOL OCP\AIM\Storage\data\qttrace69\localStorage\common.cls Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\fzq21m5u.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\History\History.IE5\MSHist012008020620080207\index.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\My Documents\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped C:\Documents and Settings\HP_Administrator\My Documents\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped C:\Documents and Settings\HP_Administrator\My Documents\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped C:\Documents and Settings\HP_Administrator\My Documents\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped C:\Documents and Settings\HP_Administrator\My Documents\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped C:\Documents and Settings\HP_Administrator\My Documents\LogMeIn.exe RarSFX: infected - 5 skipped C:\Documents and Settings\HP_Administrator\ntuser.dat Object is locked skipped C:\Documents and Settings\HP_Administrator\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LogMeInRemoteUser\ntuser.dat Object is locked skipped C:\Documents and Settings\LogMeInRemoteUser\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LogMeInRemoteUser.TRACEY\ntuser.dat Object is locked skipped C:\Documents and Settings\LogMeInRemoteUser.TRACEY\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0563NAV~.TMP Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0850NAV~.TMP Object is locked skipped C:\QooBox\Quarantine\C\WINDOWS\system32\pxhpcoha.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\xgaeyhdp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\xjxpicge.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\catchme2008-02-05_224100.57.zip/mlljg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.edx skipped C:\QooBox\Quarantine\catchme2008-02-05_224100.57.zip ZIP: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP3\A0000068.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP3\A0000069.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP3\A0000079.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.edx skipped C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\A0000205.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{EDA923F4-4569-4FEF-BE21-1920A97D4D58}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{9054582B-C315-4EA5-B5B1-9574522FC92A}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\change.log Object is locked skipped K:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP4\change.log Object is locked skipped K:\My Documents (Updated)\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\My Documents (Updated)\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\My Documents (Updated)\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\My Documents (Updated)\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\My Documents (Updated)\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\My Documents (Updated)\LogMeIn.exe RarSFX: infected - 5 skipped K:\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped K:\LogMeIn.exe RarSFX: infected - 5 skipped Scan process completed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI