This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antivirus 2009

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok it ran and rebooted. It said not to open any programs so I didn't but AIM popped up and McAfee opened up. I hope that doesn't interfere. I got tired of watching the blue screen say it was preparing a log so I thought I would check in lol
reyadawnbringer,

Hopefully, by the time you read this, your log has appeared. If it doesn't:

  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here

You're doing good here but, I'm tired. I'm going to be. I'll review your log in 7 or 8 hours.
Ok I will certainly do that and I can't tell you how much I appreciate you staying up and helping me. I TRULY appreciate your help so very much! I will post the log in a little bit, gotta run up and check it again, I will check in with you again tomorrow. Thanks again!
Ok here it is :)

ComboFix 08-11-11.01 - Kim Eyler 2008-11-13 1:10:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.229 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kim Eyler\Application Data\gadcom
c:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\hpothb07.dat
c:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\hpothb07.tif
c:\program files\icroso~1
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\AdCache
c:\windows\system32\AdCache\B_329_0_0_106800.htm
c:\windows\system32\AdCache\B_329_0_0_107400.htm
c:\windows\system32\AdCache\B_329_1_0_449200.gif
c:\windows\system32\AdCache\B_329_1_0_449600.gif
c:\windows\system32\AdCache\B_329_1_0_454300.gif
c:\windows\system32\AdCache\B_329_2_0_106800.htm
c:\windows\system32\AdCache\B_329_2_0_107400.htm
c:\windows\system32\AdCache\B_329_3_0_106800.htm
c:\windows\system32\AdCache\B_329_3_0_107400.htm
c:\windows\system32\AdCache\B_329_4_0_111600.htm
c:\windows\system32\AdCache\B_329_4_0_152400.htm
c:\windows\system32\AdCache\B_329_4_0_155300.htm
c:\windows\system32\AdCache\B_329_4_0_164100.htm
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_1_0_449200.gif
c:\windows\system32\cache329\B_329_1_0_449600.gif
c:\windows\system32\cache329\B_329_1_0_454300.gif
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\B_329_4_0_111600.htm
c:\windows\system32\cache329\B_329_4_0_152400.htm
c:\windows\system32\cache329\B_329_4_0_155300.htm
c:\windows\system32\cache329\B_329_4_0_164100.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_4_0_111600.htm
c:\windows\system32\cache329\t_B_329_4_0_152400.htm
c:\windows\system32\cache329\t_B_329_4_0_155300.htm
c:\windows\system32\cache329\t_B_329_4_0_164100.htm
c:\windows\system32\MSINET.oca
c:\windows\system32\msupdate.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
.

2008-11-13 00:07 . 2008-11-13 00:07 d——– c:\documents and settings\LocalService\Application Data\McAfee
2008-11-12 23:30 . 2008-11-12 23:31 d——– c:\documents and settings\Kim Eyler\SmitfraudFix
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\documents and settings\Kim Eyler\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-11-12 23:13 d—-c— c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-10-22 16:10 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-11-12 23:13 . 2008-10-22 16:10 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-11-12 06:26 . 2008-11-12 06:26 1,393 –a—— c:\windows\imsins.BAK
2008-11-12 06:16 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-11-12 06:15 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-11-11 17:33 . 2008-11-11 18:41 d—-c— C:\SDAT
2008-11-11 17:30 . 2008-11-11 17:25 95,253,636 –a–c— C:\sdat5430.exe
2008-11-10 18:07 . 2008-11-12 23:32 2,568 –a—— c:\windows\SYSTEM32\tmp.reg
2008-11-10 16:41 . 2005-03-16 14:21 0 –ah-c— c:\documents and settings\Administrator\hpothb07.dat
2008-11-10 16:40 . 2005-03-02 00:57 d—-c— c:\documents and settings\Administrator\Application Data\Jasc Software Inc
2008-11-10 16:40 . 2005-03-02 00:57 d–h-c— c:\documents and settings\Administrator\Application Data\Gtek
2008-11-10 16:40 . 2008-11-10 16:41 d—-c— c:\documents and settings\Administrator
2008-11-10 16:33 . 2008-11-10 16:33 d——– c:\program files\Trend Micro
2008-11-10 16:28 . 2008-11-10 16:28 d——– c:\program files\CCleaner
2008-11-10 13:53 . 2008-11-10 16:48 d—-c— c:\documents and settings\All Users\Application Data\avg8
2008-11-09 09:50 . 2008-11-09 09:50 9,662 –a—— c:\windows\SYSTEM32\ZoneAlarmIconUS.ico
2008-11-09 09:50 . 2008-11-09 09:50 4,286 –a—— c:\windows\SYSTEM32\Jamster.ico
2008-11-09 09:34 . 2008-11-10 13:39 d–hs—- c:\windows\RXJpYyBFeWxlcg
2008-11-09 09:29 . 2008-11-09 09:29 d——– c:\windows\ooow
2008-11-09 09:29 . 2008-11-10 13:36 d——– c:\program files\Common Files\ooow
2008-11-08 12:11 . 2008-11-09 12:11 527 –a—— c:\windows\SYSTEM32\TDSSpaxt.dat
2008-11-08 09:03 . 2008-11-08 11:36 58 –a—— c:\windows\SYSTEM32\winwp.bmp
2008-11-08 08:59 . 2008-11-08 08:59 527 –a—— c:\windows\SYSTEM32\TDSSosvd.dat
2008-11-08 08:58 . 2008-11-08 08:58 10,000 –a—— c:\windows\SYSTEM32\jsne87fidgf.dll
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DRIVERS\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DLLCACHE\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DRIVERS\null.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DLLCACHE\null.sys
2008-11-08 08:58 . 2008-11-08 08:58 2 –a–c— C:\-1463443965
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\windows\SYSTEM32\sX3i19
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\temp\PRE45
2008-11-08 08:57 . 2008-11-08 08:57 150,528 –a—— c:\windows\SYSTEM32\mkrnl.exe
2008-11-08 08:56 . 2008-11-08 08:56 34,816 –a—— c:\windows\SYSTEM32\prun.exe
2008-11-06 06:29 . 2008-11-06 06:29 6,144 –ahsc— C:\Thumbs.db
2008-11-04 07:11 . 2008-11-04 07:11 d——– C:\MSI
2008-11-04 07:11 . 2008-11-04 07:11 52 –a—— c:\windows\FPRINCE.INI
2008-11-03 19:46 . 2008-11-03 19:46 d——– c:\windows\Reader Rabbit Creative Studio
2008-11-03 19:46 . 2000-12-21 07:43 194,048 –a—— c:\windows\RRPW.pol
2008-11-03 19:35 . 2008-11-03 19:35 d——– c:\program files\Disney Interactive
2008-11-03 19:33 . 2008-11-03 19:35 1,259 –a—— c:\windows\disney.ini
2008-11-03 19:22 . 2008-11-03 19:22 d——– c:\windows\WNBackup
2008-11-03 19:22 . 2008-11-11 17:31 d——– C:\KA
2008-11-03 19:22 . 1998-09-24 18:31 270,848 –a—— c:\windows\unwise.exe
2008-11-03 19:22 . 2008-11-03 19:22 218 –a—— c:\windows\KA.INI
2008-11-03 19:22 . 2008-11-03 19:22 60 –a—— c:\windows\SIERRA.INI
2008-11-03 19:12 . 2008-11-06 06:36 d——– c:\program files\The Learning Company
2008-10-31 15:50 . 2008-10-31 15:50 0 –a—— c:\windows\SETUP32.INI
2008-10-26 08:55 . 2008-10-15 11:34 337,408 ——— c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-15 02:11 . 2008-09-08 05:41 333,824 ——— c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-10-15 02:10 . 2008-08-14 05:11 2,189,184 ——— c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-15 02:10 . 2008-08-14 05:09 2,145,280 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,066,048 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,023,936 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-10-15 02:10 . 2008-09-15 07:12 1,846,400 ——— c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 09:42 . 2008-10-14 09:42 d–hs—- c:\windows\ftpcache
2008-10-14 09:41 . 2004-03-29 15:23 90,112 –a—— c:\windows\unvise32.exe
2008-10-14 09:38 . 2008-10-14 09:38 d——– c:\program files\Hooked on Phonics Learning

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 21:51 ——— d—–w c:\documents and settings\Kim Eyler\Application Data\McAfee
2008-11-11 15:20 ——— dc—-w c:\documents and settings\All Users\Application Data\McAfee
2008-11-10 23:25 ——— d—–w c:\program files\Audible
2008-11-08 12:17 ——— d—–w c:\program files\Lx_cats
2008-11-06 13:04 ——— d—–w c:\program files\GamingSquared
2008-11-06 12:50 ——— d—–w c:\program files\Broderbund
2008-11-06 11:40 ——— d—–w c:\program files\Real
2008-11-06 11:39 ——— d—–w c:\program files\Kids Cam Show and Share Creativity Center
2008-11-06 11:38 ——— d—–w c:\program files\Dell Games
2008-11-06 11:33 ——— d—–w c:\program files\_uninstallation_info
2008-11-06 11:32 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-06 11:32 ——— d—–w c:\program files\PopCap Games
2008-11-06 11:31 ——— d—–w c:\program files\GameFiesta
2008-11-06 11:31 ——— d—–w c:\program files\Free Offers from Freeze.com
2008-11-04 00:35 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-09-18 10:58 ——— d—–w c:\program files\Blubster
2008-09-13 19:08 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-09-13 18:42 ——— d—–w c:\program files\Shockwave.com
2008-09-13 18:40 ——— d—–w c:\program files\RealArcade
2008-09-13 18:39 ——— d—–w c:\program files\Family Feud
2008-09-13 18:39 ——— d—–w c:\program files\Chuzzle Deluxe
2008-09-13 18:37 ——— d—–w c:\program files\AOL Games
2008-09-07 02:09 0 -c–a-w c:\program files\temp01
2006-02-02 14:59 322 -c-ha-w c:\documents and settings\Kim Eyler\hpothb07.dat
2006-02-02 14:56 169 -c-ha-w c:\documents and settings\NetworkService\hpothb07.dat
2005-08-14 15:55 0 -c-ha-w c:\documents and settings\LocalService\hpothb07.dat
2005-07-16 12:04 70,076 -c–a-w c:\documents and settings\Eric Eyler\Winsock2.reg
2005-03-16 19:21 368 -c-ha-w c:\documents and settings\Kim Eyler\Application Data\hpothb07.dat
2005-03-16 19:21 164 -c-ha-w c:\documents and settings\All Users\hpothb07.dat
2005-03-16 19:21 0 -c-ha-w c:\documents and settings\Default User\hpothb07.dat
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c–a-w 408,576 2004-10-31 11:21:32 c:\dell\bak\PreODM.EXE

-c–a-w 307,200 2005-10-24 20:53:40 c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe

-c–a-w 1,404,928 2004-10-14 21:42:54 c:\program files\Analog Devices\Core\bak\smax4pnp.exe

-c–a-w 429,568 2001-03-26 04:35:20 c:\program files\Browser Mouse\Browser Mouse\1.0\bak\lwbwheel.exe

-c–a-w 50,792 2006-04-20 17:10:13 c:\program files\Common Files\AOL\1135353641\ee\bak\AOLSoftware.exe
—-a-w 50,760 2006-05-10 00:24:16 c:\program files\Common Files\AOL\1135353641\ee\AOLSoftware.exe

-c–a-w 180,269 2005-03-05 02:07:39 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe

-c–a-w 290,816 2004-04-12 02:15:14 c:\program files\Dell\Media Experience\bak\PCMService.exe

-c–a-w 306,688 2004-07-19 13:51:24 c:\program files\Dell Support\bak\DSAgnt.exe

-c–a-w 69,632 2002-04-11 09:19:34 c:\program files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe

-c–a-w 221,184 2003-09-04 02:12:44 c:\program files\Intel\Modem Event Monitor\bak\IntelMEM.exe

-c–a-w 36,975 2005-11-10 18:03:52 c:\program files\Java\jre1.5.0_06\bin\bak\jusched.exe

-c–a-w 94,208 2005-08-01 12:05:04 c:\program files\Lexmark 2300 Series\bak\ezprint.exe

-c–a-w 200,704 2005-07-21 06:07:22 c:\program files\Lexmark 2300 Series\bak\lxcgmon.exe

-c–a-w 299,008 2005-07-12 13:36:32 c:\program files\Lexmark Fax Solutions\bak\fm3032.exe

-c–a-w 892,928 2003-12-01 16:38:16 c:\program files\Logitech\iTouch\bak\iTouch.exe

-c–a-w 98,304 2005-03-02 06:01:57 c:\program files\QuickTime\bak\qttask.exe
—-a-w 282,624 2006-10-25 23:58:18 c:\program files\QuickTime\qttask.exe

-c–a-w 77,824 2005-09-20 14:32:24 c:\windows\SYSTEM32\bak\hkcmd.exe

-c–a-w 114,688 2005-09-20 14:36:20 c:\windows\SYSTEM32\bak\igfxpers.exe

-c–a-w 94,208 2005-09-20 14:35:40 c:\windows\SYSTEM32\bak\igfxtray.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Name of App"="c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe" [2006-03-10 667735]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.CDVC"= cdvccodc.dll
"VIDC.NTN1"= NUVision.ax

[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak easyshare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim6]
–a—— 2008-08-06 10:21 50472 c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gadcom]
c:\documents and settings\Kim Eyler\Application Data\gadcom\gadcom.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Blubster\\Blubster.exe"=
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys [2006-07-18 99840]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd30d845-872b-11db-8a57-001111e20b6d}]
\Shell\AutoRun\command - E:\SH-S182M(TS-H652M).exe
.
Contents of the 'Scheduled Tasks' folder

2008-11-08 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\RUNDLL32.EXE [2008-04-13 19:12]

2008-11-07 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (MAIN-Kim Eyler).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []

2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{74891e76-ce67-4171-9676-ab71285d320a} - (no file)
WebBrowser-{74891E76-CE67-4171-9676-AB71285D320A} - (no file)


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Kim Eyler\Application Data\Mozilla\Firefox\Profiles\cpimp2gf.default\
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 01:16:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Name of App = c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe??| ??????? ??????? ?B?????Kim Eyler?y?l?e?r???(??????|@??|????=??|Y??|????????@???x?????C?@??? ??????? ?B?????????????????????061210122311500?2?3?1?1?5?0?0???????????????????????????????????????????(?????G

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\AIM6\aolsoftware.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
c:\windows\SYSTEM32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-11-13 1:36:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-13 06:36:30

Pre-Run: 18,718,834,688 bytes free
Post-Run: 19,133,571,072 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

332 — E O F — 2008-11-12 11:28:56
I know we are still in the middle of fixing this (possibly the end?) but I have a few questions. I go to a website called webkinzinsider and so do my kids. They have a bulletin board and MANY members are reporting this same virus and similar problems. They say at the time it started the computer rebooted and I do recall something like this. Everyone has this one site in common so that is why I ask. My friend is having the exact same messages come up on her computer and she goes there also. The owners are very nice and really protective of the members, I don't want to point the finger BUT if it is at all possible it came from there I want to inform others to beware. My friend said it is possible it came from the pictures members posted on the site and not the site itself. I was just curious if there was any way to know or what you would suspect. I am also concerned about visiting the site and getting this stuff back again????? Is there something I should download or purchase to have more protection than just McAfee? Should Windows Firewall be turned on? I think I turned it off because it conflicted with McAfee. I am running Windows Defender and McAfee on the Vista. THANK YOU so very much. Sorry for all of the questions. Good Night! :wavey:
reyadawnbringer,

Should Windows Firewall be turned on?

Absolutely. Do it immediately.

I can't tell where you got infected. All I can tell you for sure is you don't have "this" virus. You've got at least half a dozen of various types. I'd say we are in the middle of fixing things. I believe I know most of the problems. The trick is to now fix them.

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.

Then

FindAWF

Click here to download FindAWF.exe and save it to your desktop.
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to Press any key to continue.
  • Press 1 and then Enter, and the FindAWF tool will begin scanning your computer for the infected AWF files and the backups the trojan created.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt which will automatically be saved to your desktop or to the same location as FindAWF.exe.
  • Copy and paste the contents of the AWF.txt file in your next reply.
Ok I went and checked and Windows Firewall was enabled SHEW!

I did the first scan and here are the results


SDFix: Version 1.240
Run by [removed] on Thu 11-13-2008 at 11:01

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\-14634~1 - Deleted
C:\WINDOWS\SYSTEM32\TDSSOSVD.dat - Deleted
C:\WINDOWS\SYSTEM32\TDSSPAXT.dat - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 11:31:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe"="C:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe:*:Enabled:2300 Series Server"
"C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe"="C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe:*:Enabled:2300 Series Printer Status"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Blubster\\Blubster.exe"="C:\\Program Files\\Blubster\\Blubster.exe:*:Enabled:Blubster"
"C:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"="C:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"="C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Tue 24 Aug 2004 155,648 A..H. — "C:\DELL\PRIMOSDK.DLL"
Tue 24 Aug 2004 360,448 A..H. — "C:\DELL\PX.DLL"
Wed 28 Jul 2004 56,832 A..H. — "C:\DELL\PXCPYA64.EXE"
Wed 28 Jul 2004 108,544 A..H. — "C:\DELL\PXCPYI64.EXE"
Wed 18 Aug 2004 389,120 A..H. — "C:\DELL\PXDRV.DLL"
Mon 2 Aug 2004 20,576 A..H. — "C:\DELL\PXHELP20.SYS"
Mon 2 Aug 2004 54,976 A..H. — "C:\DELL\PXHELP64.SYS"
Mon 2 Aug 2004 32,272 A..H. — "C:\DELL\PXHELPER.SYS"
Mon 2 Aug 2004 26,720 A..H. — "C:\DELL\PXHLPA64.SYS"
Mon 2 Aug 2004 57,344 A..H. — "C:\DELL\PXHPINST.EXE"
Mon 2 Aug 2004 53,760 A..H. — "C:\DELL\PXINSA64.EXE"
Mon 2 Aug 2004 104,960 A..H. — "C:\DELL\PXINSI64.EXE"
Tue 24 Aug 2004 159,744 A..H. — "C:\DELL\PXMAS.DLL"
Wed 28 Jul 2004 57,344 A..H. — "C:\DELL\PXSETUP.EXE"
Tue 24 Aug 2004 339,968 A..H. — "C:\DELL\PXWAVE.DLL"
Thu 20 May 2004 28,672 A..H. — "C:\DELL\VXBLOCK.DLL"
Wed 12 Sep 2007 31 A..H. — "C:\WINDOWS\uccspecc.sys"
Tue 24 Aug 2004 155,648 A..H. — "C:\DELL\MEDIAEXE\PRIMOSDK.DLL"
Tue 24 Aug 2004 360,448 A..H. — "C:\DELL\MEDIAEXE\PX.DLL"
Wed 28 Jul 2004 56,832 A..H. — "C:\DELL\MEDIAEXE\PXCPYA64.EXE"
Wed 28 Jul 2004 108,544 A..H. — "C:\DELL\MEDIAEXE\PXCPYI64.EXE"
Wed 18 Aug 2004 389,120 A..H. — "C:\DELL\MEDIAEXE\PXDRV.DLL"
Mon 2 Aug 2004 20,576 A..H. — "C:\DELL\MEDIAEXE\PXHELP20.SYS"
Mon 2 Aug 2004 54,976 A..H. — "C:\DELL\MEDIAEXE\PXHELP64.SYS"
Mon 2 Aug 2004 32,272 A..H. — "C:\DELL\MEDIAEXE\PXHELPER.SYS"
Mon 2 Aug 2004 26,720 A..H. — "C:\DELL\MEDIAEXE\PXHLPA64.SYS"
Mon 2 Aug 2004 57,344 A..H. — "C:\DELL\MEDIAEXE\PXHPINST.EXE"
Mon 2 Aug 2004 53,760 A..H. — "C:\DELL\MEDIAEXE\PXINSA64.EXE"
Mon 2 Aug 2004 104,960 A..H. — "C:\DELL\MEDIAEXE\PXINSI64.EXE"
Tue 24 Aug 2004 159,744 A..H. — "C:\DELL\MEDIAEXE\PXMAS.DLL"
Wed 28 Jul 2004 57,344 A..H. — "C:\DELL\MEDIAEXE\PXSETUP.EXE"
Tue 24 Aug 2004 339,968 A..H. — "C:\DELL\MEDIAEXE\PXWAVE.DLL"
Thu 20 May 2004 28,672 A..H. — "C:\DELL\MEDIAEXE\VXBLOCK.DLL"
Wed 29 Oct 2008 848 A.SH. — "C:\WINDOWS\SYSTEM32\KGyGaAvL.sys"
Sat 9 Jul 2005 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 12 Sep 2008 20,487 A.SHR — "C:\Program Files\McAfee\MQC\MRU.bak"
Fri 12 Sep 2008 265 A.SHR — "C:\Program Files\McAfee\MQC\qcconf.bak"
Thu 17 Apr 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp"
Sat 9 Jul 2005 4,348 A..H. — "C:\Documents and Settings\Kim Eyler\My Documents\My Music\License Backup\drmv1key.bak"
Sat 17 Sep 2005 20 A..H. — "C:\Documents and Settings\Kim Eyler\My Documents\My Music\License Backup\drmv1lic.bak"
Sat 9 Jul 2005 400 A.SH. — "C:\Documents and Settings\Kim Eyler\My Documents\My Music\License Backup\drmv2key.bak"
Wed 9 Mar 2005 88 A..H. — "C:\Documents and Settings\Kim Eyler\Application Data\GlobalSCAPE\CuteFTP\5.0\cuteftp.sys"
Sat 9 Jul 2005 4,348 …H. — "C:\Documents and Settings\Kim Eyler\Application Data\Real\Rhapsody\wmlicbackup\drmv1key.bak"
Sat 2 Dec 2006 20 A..H. — "C:\Documents and Settings\Kim Eyler\Application Data\Real\Rhapsody\wmlicbackup\drmv1lic.bak"
Sat 9 Jul 2005 400 A.SH. — "C:\Documents and Settings\Kim Eyler\Application Data\Real\Rhapsody\wmlicbackup\drmv2key.bak"
Wed 2 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Wed 2 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Fri 4 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Fri 4 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Mon 25 Apr 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"

Finished!



off to run the next scan now.

Thanks for your answers to my questions, I appreciate you taking the time. :notworthy:

Be back after the next scan :)
ok here is the next report Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Thu 11-13-2008 The current time is: 12:03:10.42 bak folders found ~~~~~~~~~~~ Directory of C:\DELL\BAK 10-31-2004 06:21 408,576 PreODM.EXE 1 File(s) 408,576 bytes Directory of C:\PROGRA~1\DELLSU~1\BAK 07-19-2004 08:51 306,688 DSAgnt.exe 1 File(s) 306,688 bytes Directory of C:\PROGRA~1\LEXMAR~1\BAK 08-01-2005 07:05 94,208 ezprint.exe 07-21-2005 01:07 200,704 lxcgmon.exe 2 File(s) 294,912 bytes Directory of C:\PROGRA~1\LEXMAR~2\BAK 07-12-2005 08:36 299,008 fm3032.exe 1 File(s) 299,008 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 03-02-2005 01:01 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 09-20-2005 09:32 77,824 hkcmd.exe 09-20-2005 09:36 114,688 igfxpers.exe 09-20-2005 09:35 94,208 igfxtray.exe 3 File(s) 286,720 bytes Directory of C:\PROGRA~1\ANALOG~1\CORE\BAK 10-14-2004 16:42 1,404,928 smax4pnp.exe 1 File(s) 1,404,928 bytes Directory of C:\PROGRA~1\DELL\MEDIAE~1\BAK 04-11-2004 21:15 290,816 PCMService.exe 1 File(s) 290,816 bytes Directory of C:\PROGRA~1\HEWLET~1\HPSHAR~1\BAK 04-11-2002 04:19 69,632 hpgs2wnd.exe 1 File(s) 69,632 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09-03-2003 21:12 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\LOGITECH\ITOUCH\BAK 12-01-2003 11:38 892,928 iTouch.exe 1 File(s) 892,928 bytes Directory of C:\PROGRA~1\ADOBE\ACROBA~2.0\READER\BAK 10-24-2005 15:53 307,200 AdobeUpdateManager.exe 1 File(s) 307,200 bytes Directory of C:\PROGRA~1\BROWSE~1\BROWSE~1\1.0\BAK 03-25-2001 23:35 429,568 lwbwheel.exe 1 File(s) 429,568 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 03-04-2005 21:07 180,269 realsched.exe 1 File(s) 180,269 bytes Directory of C:\PROGRA~1\JAVA\JRE15~3.0_0\BIN\BAK 11-10-2005 13:03 36,975 jusched.exe 1 File(s) 36,975 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\113535~1\EE\BAK 04-20-2006 12:10 50,792 AOLSoftware.exe 1 File(s) 50,792 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 408576 Oct 31 2004 "C:\DELL\bak\PreODM.EXE" 306688 Jul 19 2004 "C:\Program Files\Dell Support\bak\DSAgnt.exe" 94208 Aug 1 2005 "C:\Program Files\Lexmark 2300 Series\bak\ezprint.exe" 200704 Jul 21 2005 "C:\Program Files\Lexmark 2300 Series\bak\lxcgmon.exe" 299008 Jul 12 2005 "C:\Program Files\Lexmark Fax Solutions\bak\fm3032.exe" 282624 Oct 25 2006 "C:\Program Files\QuickTime\qttask.exe" 98304 Mar 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 118784 Feb 10 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE" 77824 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 126976 Jan 23 2005 "C:\DELL\drivers\R96001\Win2000\hkcmd.exe" 126976 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0008\DriverFiles\hkcmd.exe" 114688 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxpers.exe" 155648 Feb 10 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE" 94208 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" 155648 Jan 23 2005 "C:\DELL\drivers\R96001\Win2000\igfxtray.exe" 155648 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0008\DriverFiles\igfxtray.exe" 1404928 Oct 14 2004 "C:\DRIVERS\AUDIO\SMAX4PNP.EXE" 1404928 Oct 14 2004 "C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe" 290816 Apr 11 2004 "C:\Program Files\Dell\Media Experience\bak\PCMService.exe" 69632 Apr 11 2002 "C:\Program Files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" 892928 Dec 1 2003 "C:\Program Files\Logitech\iTouch\bak\iTouch.exe" 303616 May 15 2003 "C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\AdobeUpdateManager.exe" 303616 May 15 2003 "C:\Program Files\Adobe\Acrobat 6.0\Reader\AdobeUpdateManager.exe" 307200 Oct 24 2005 "C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe" 429568 Mar 25 2001 "C:\Program Files\Browser Mouse\Browser Mouse\1.0\bak\lwbwheel.exe" 180269 Mar 4 2005 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" 32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe" 36975 Mar 4 2005 "C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" 36975 Jun 3 2005 "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" 36975 Nov 10 2005 "C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe" 41824 Oct 8 2007 "C:\Program Files\AIM6\aolsoftware.exe" 50760 May 9 2006 "C:\Program Files\Common Files\AOL\1135353641\ee\AOLSoftware.exe" 50792 Apr 20 2006 "C:\Program Files\Common Files\AOL\1135353641\ee\bak\AOLSoftware.exe"
reyadawnbringer,

Fix AWF Infection Step 2
Copy the file paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

EXAMPLE >>"C:\DELL\bak\PreODM.EXE"
"C:\Program Files\Dell Support\bak\DSAgnt.exe"
"C:\Program Files\Lexmark 2300 Series\bak\ezprint.exe"
"C:\Program Files\Lexmark 2300 Series\bak\lxcgmon.exe"
"C:\Program Files\Lexmark Fax Solutions\bak\fm3032.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
"C:\WINDOWS\SYSTEM32\bak\igfxpers.exe"
"C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
"C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe"
"C:\Program Files\Dell\Media Experience\bak\PCMService.exe"
"C:\Program Files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe"
"C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"
"C:\Program Files\Logitech\iTouch\bak\iTouch.exe"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe"
"C:\Program Files\Browser Mouse\Browser Mouse\1.0\bak\lwbwheel.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe"
"C:\Program Files\Common Files\AOL\1135353641\ee\bak\AOLSoftware.exe"

  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Press 2 then Enter
  • Notepad will open a file named FindAWF.txt. It will appear with instructions to click below the line and paste the list of files to be restored.
  • Right click below this line and select Edit, Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
  • The program will proceed to move the legit files and will perform another scan for bak folders.
  • It may take a few minutes to complete, so please be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
ok done, here is the new log Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: Thu 11-13-2008 The current time is: 13:13:47.93 bak folders found ~~~~~~~~~~~ Directory of C:\DELL\BAK 10-31-2004 06:21 408,576 PreODM.EXE 1 File(s) 408,576 bytes Directory of C:\PROGRA~1\DELLSU~1\BAK 07-19-2004 08:51 306,688 DSAgnt.exe 1 File(s) 306,688 bytes Directory of C:\PROGRA~1\LEXMAR~1\BAK 08-01-2005 07:05 94,208 ezprint.exe 07-21-2005 01:07 200,704 lxcgmon.exe 2 File(s) 294,912 bytes Directory of C:\PROGRA~1\LEXMAR~2\BAK 07-12-2005 08:36 299,008 fm3032.exe 1 File(s) 299,008 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 03-02-2005 01:01 98,304 qttask.exe 1 File(s) 98,304 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 09-20-2005 09:32 77,824 hkcmd.exe 09-20-2005 09:36 114,688 igfxpers.exe 09-20-2005 09:35 94,208 igfxtray.exe 3 File(s) 286,720 bytes Directory of C:\PROGRA~1\ANALOG~1\CORE\BAK 10-14-2004 16:42 1,404,928 smax4pnp.exe 1 File(s) 1,404,928 bytes Directory of C:\PROGRA~1\DELL\MEDIAE~1\BAK 04-11-2004 21:15 290,816 PCMService.exe 1 File(s) 290,816 bytes Directory of C:\PROGRA~1\HEWLET~1\HPSHAR~1\BAK 04-11-2002 04:19 69,632 hpgs2wnd.exe 1 File(s) 69,632 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09-03-2003 21:12 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\LOGITECH\ITOUCH\BAK 12-01-2003 11:38 892,928 iTouch.exe 1 File(s) 892,928 bytes Directory of C:\PROGRA~1\ADOBE\ACROBA~2.0\READER\BAK 10-24-2005 15:53 307,200 AdobeUpdateManager.exe 1 File(s) 307,200 bytes Directory of C:\PROGRA~1\BROWSE~1\BROWSE~1\1.0\BAK 03-25-2001 23:35 429,568 lwbwheel.exe 1 File(s) 429,568 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 03-04-2005 21:07 180,269 realsched.exe 1 File(s) 180,269 bytes Directory of C:\PROGRA~1\JAVA\JRE15~3.0_0\BIN\BAK 11-10-2005 13:03 36,975 jusched.exe 1 File(s) 36,975 bytes Directory of C:\PROGRA~1\COMMON~1\AOL\113535~1\EE\BAK 04-20-2006 12:10 50,792 AOLSoftware.exe 1 File(s) 50,792 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 408576 Oct 31 2004 "C:\DELL\bak\PreODM.EXE" 306688 Jul 19 2004 "C:\Program Files\Dell Support\DSAgnt.exe" 306688 Jul 19 2004 "C:\Program Files\Dell Support\bak\DSAgnt.exe" 94208 Aug 1 2005 "C:\Program Files\Lexmark 2300 Series\ezprint.exe" 94208 Aug 1 2005 "C:\Program Files\Lexmark 2300 Series\bak\ezprint.exe" 200704 Jul 21 2005 "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" 200704 Jul 21 2005 "C:\Program Files\Lexmark 2300 Series\bak\lxcgmon.exe" 299008 Jul 12 2005 "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" 299008 Jul 12 2005 "C:\Program Files\Lexmark Fax Solutions\bak\fm3032.exe" 98304 Mar 2 2005 "C:\Program Files\QuickTime\qttask.exe" 98304 Mar 2 2005 "C:\Program Files\QuickTime\bak\qttask.exe" 118784 Feb 10 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE" 77824 Sep 20 2005 "C:\WINDOWS\SYSTEM32\hkcmd.exe" 77824 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 126976 Jan 23 2005 "C:\DELL\drivers\R96001\Win2000\hkcmd.exe" 126976 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0008\DriverFiles\hkcmd.exe" 114688 Sep 20 2005 "C:\WINDOWS\SYSTEM32\igfxpers.exe" 114688 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxpers.exe" 155648 Feb 10 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE" 94208 Sep 20 2005 "C:\WINDOWS\SYSTEM32\igfxtray.exe" 94208 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" 155648 Jan 23 2005 "C:\DELL\drivers\R96001\Win2000\igfxtray.exe" 155648 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0008\DriverFiles\igfxtray.exe" 1404928 Oct 14 2004 "C:\DRIVERS\AUDIO\SMAX4PNP.EXE" 1404928 Oct 14 2004 "C:\Program Files\Analog Devices\Core\smax4pnp.exe" 1404928 Oct 14 2004 "C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe" 290816 Apr 11 2004 "C:\Program Files\Dell\Media Experience\PCMService.exe" 290816 Apr 11 2004 "C:\Program Files\Dell\Media Experience\bak\PCMService.exe" 69632 Apr 11 2002 "C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" 69632 Apr 11 2002 "C:\Program Files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" 892928 Dec 1 2003 "C:\Program Files\Logitech\iTouch\iTouch.exe" 892928 Dec 1 2003 "C:\Program Files\Logitech\iTouch\bak\iTouch.exe" 303616 May 15 2003 "C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\AdobeUpdateManager.exe" 303616 May 15 2003 "C:\Program Files\Adobe\Acrobat 6.0\Reader\AdobeUpdateManager.exe" 307200 Oct 24 2005 "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" 307200 Oct 24 2005 "C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe" 429568 Mar 25 2001 "C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe" 429568 Mar 25 2001 "C:\Program Files\Browser Mouse\Browser Mouse\1.0\bak\lwbwheel.exe" 180269 Mar 4 2005 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" 180269 Mar 4 2005 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" 32881 Sep 28 2004 "C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe" 36975 Mar 4 2005 "C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" 36975 Jun 3 2005 "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" 36975 Nov 10 2005 "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" 36975 Nov 10 2005 "C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe" 41824 Oct 8 2007 "C:\Program Files\AIM6\aolsoftware.exe" 50792 Apr 20 2006 "C:\Program Files\Common Files\AOL\1135353641\ee\AOLSoftware.exe" 50792 Apr 20 2006 "C:\Program Files\Common Files\AOL\1135353641\ee\bak\AOLSoftware.exe" end of report
reyadawnbringer,

Fix AWF Infection Step 3

Copy the paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

EXAMPLE >>C:\DELL\bak
C:\Program Files\Dell Support\bak
C:\Program Files\Lexmark 2300 Series\bak
C:\Program Files\Lexmark 2300 Series\bak
C:\Program Files\Lexmark Fax Solutions\bak
C:\Program Files\QuickTime\bak
C:\WINDOWS\SYSTEM32\bak
C:\WINDOWS\SYSTEM32\bak
C:\WINDOWS\SYSTEM32\bak
C:\Program Files\Analog Devices\Core\bak
C:\Program Files\Dell\Media Experience\bak
C:\Program Files\Hewlett-Packard\HP Share-to-Web\bak
C:\Program Files\Intel\Modem Event Monitor\bak
C:\Program Files\Logitech\iTouch\bak
C:\Program Files\Adobe\Acrobat 7.0\Reader\bak
C:\Program Files\Browser Mouse\Browser Mouse\1.0\bak
C:\Program Files\Common Files\Real\Update_OB\bak
C:\Program Files\Java\jre1.5.0_06\bin\bak
C:\Program Files\Common Files\AOL\1135353641\ee\bak

  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Select Option 3 from the menu and press Enter.
  • Press any key to continue.
  • A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
  • Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
  • The program will proceed to remove the folders and will perform another scan for bak folders.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
Before you close FindAWF, Select Option 4 from the menu and press Enter.
When it's finished the tool will return to the main menu.
Press E to close FindAWF.
This was kind of scary it said error and files not found and then it closed I never got to push 4 in it it just brought up the file Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Thu 11-13-2008 The current time is: 15:19:01.84 bak folders found ~~~~~~~~~~~ Directory of C:\DELL\BAK 10-31-2004 06:21 408,576 PreODM.EXE 1 File(s) 408,576 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 408576 Oct 31 2004 "C:\DELL\bak\PreODM.EXE" end of report
reyadawnbringer,

That's because I screwed up your script. The word example shouldn't be there. :blush:

We need to do that again without the errors :)


Fix AWF Infection Step 3

Copy the paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\DELL\bak

  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Select Option 3 from the menu and press Enter.
  • Press any key to continue.
  • A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
  • Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
  • The program will proceed to remove the folders and will perform another scan for bak folders.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.
Before you close FindAWF, Select Option 4 from the menu and press Enter.
When it's finished the tool will return to the main menu.
Press E to close FindAWF.
oh ok no problem C:\DELL\bak so THAT is all I am supposed to copy and paste into there? also step 2 had the word example in it will we need to do that step again also?
reyadawnbringer,

so THAT is all I am supposed to copy and paste into there?

Yes

also step 2 had the word example in it will we need to do that step again also?

Nope. You are correct that I screwed up my directions but I got away with it that time. :blush:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI