Viruses and Worms on my Computer HELP ME PLEASE! |
![]() ![]() |
Viruses and Worms on my Computer HELP ME PLEASE! |
Jan 26 2007, 04:14 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 40 OS: Windows XP |
|
|
|
Jan 26 2007, 04:27 PM
Post
#2
|
|
![]() Malware Slayer Extraordinaire! Posts: 11,517 From: Mass, USA :) OS: XP |
Hi SillyxWabbitx and welcome to GeeksToGo!
If you are having malware issues, please go to the following link and follow all the instructions carefully. You Must Read This Before Posting A Hijackthis Log this will help you clean up to 70 percent of all problems by yourself. If at the end of the process you are still having difficulty--and you may not be-- then post a hijackthis log in THIS thread. Thanks, Excal |
|
|
Jan 26 2007, 04:30 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 40 OS: Windows XP |
i went through all of that and there are still viruses and a worm on my computer, here is my hijack this log:
Logfile of HijackThis v1.99.1 Scan saved at 4:29:27 PM, on 1/26/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\Rundll32.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Steam\Steam.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\Program Files\AIM\aim.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\dllhost.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\RegCure\RegCure.exe C:\WINDOWS\system32\wuauclt.exe c:\program files\mcafee.com\shared\mghtml.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Brett\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Macromedia Flash - {AD03571F-C182-D851-A69F-96C80BF4B23B} - C:\WINDOWS\system\dlgctl32.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcafee.com/molbin/Shared/C...22/ComCtl32.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1162155549723 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1162155533864 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab O20 - AppInit_DLLs: O21 - SSODL: IEFilter - {1EAED770-7687-4B2E-AF30-0781A2FA48BF} - C:\WINDOWS\system32\IEFilter.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe |
|
|
Jan 26 2007, 05:13 PM
Post
#4
|
|
![]() Malware Slayer Extraordinaire! Posts: 11,517 From: Mass, USA :) OS: XP |
You may have a downloader trojan called Downloader.Agent.awf or Downloader.Agent.ayy. This trojan replaces legitimate files that are common on most computers with an infected file. It then moves the legitimate file to a "bak" or backup folder. Please follow the directions below to run FindAWF so we can identify the files that have been infected and the backups then restore them.
* Click here to download FindAWF.exe and save it to your desktop.
Excal |
|
|
Jan 26 2007, 06:30 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 40 OS: Windows XP |
ok, i did it and here is my report that came from the scan
Find AWF report by noahdfear ©2006 21504 byte files found ~~~~~~~~~~~~~ 21504 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 25600 byte files found ~~~~~~~~~~~~~ 25600 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 26450 byte files found ~~~~~~~~~~~~~ 26450 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 05/11/2000 01:00 AM 90,112 UpdReg.EXE 1 File(s) 90,112 bytes Directory of C:\PROGRA~1\AIM\BAK 08/01/2006 03:35 PM 67,112 aim.exe 1 File(s) 67,112 bytes Directory of C:\PROGRA~1\DELLAI~1\BAK 09/21/2003 09:21 AM 270,336 dlbfbmgr.exe 1 File(s) 270,336 bytes Directory of C:\PROGRA~1\ITUNES\BAK 02/23/2006 03:45 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 10/29/2006 07:20 PM 155,648 qttask.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\EHOME\BAK 08/10/2004 04:04 AM 59,392 ehtray.exe 1 File(s) 59,392 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/10/2004 05:00 AM 15,360 ctfmon.exe 08/20/2003 03:15 PM 483,328 hphmon05.exe 2 File(s) 498,688 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 08/25/2004 12:52 PM 339,968 atiptaxx.exe 1 File(s) 339,968 bytes Directory of C:\PROGRA~1\CYBERL~1\POWERDVD\BAK 08/23/2004 06:19 PM 57,344 DVDLauncher.exe 1 File(s) 57,344 bytes Directory of C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK 06/25/2003 11:24 AM 49,152 HPWuSchd.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 08/20/2003 03:23 PM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HP\HPCORE~1\BAK 08/20/2003 02:57 PM 221,184 hpcmpmgr.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\INTEL\INTELA~1\BAK 03/23/2004 12:16 PM 135,168 iaanotif.exe 1 File(s) 135,168 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09/03/2003 08:12 PM 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\MCAFEE\SPAMKI~1\BAK 09/26/2005 10:26 AM 110,592 MskAgent.exe 08/12/2005 04:16 PM 1,121,792 MSKDetct.exe 2 File(s) 1,232,384 bytes Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 03/24/2004 03:56 PM 1,380,352 MpfTray.exe 1 File(s) 1,380,352 bytes Directory of C:\PROGRA~1\MUSICM~1\MUSICM~2\BAK 04/19/2004 02:45 PM 131,072 mm_tray.exe 04/19/2004 02:45 PM 53,248 mmtask.exe 2 File(s) 184,320 bytes Directory of C:\PROGRA~1\REAL\REALPL~1\BAK 11/19/2004 11:42 PM 26,112 RealPlay.exe 1 File(s) 26,112 bytes Directory of C:\WINDOWS\SYSTEM32\DLA\BAK 08/13/2004 01:05 AM 122,939 tfswctrl.exe 1 File(s) 122,939 bytes Directory of C:\PROGRA~1\COMMON~1\DELL\EUSW\BAK 05/27/2004 08:05 PM 323,584 Support.exe 1 File(s) 323,584 bytes Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK 01/07/2004 01:01 AM 110,592 sgtray.exe 1 File(s) 110,592 bytes Directory of C:\PROGRA~1\CREATIVE\SOUNDB~1\SURROU~1\BAK 09/17/2003 10:43 AM 57,344 CTSysVol.exe 1 File(s) 57,344 bytes Directory of C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK 04/13/2005 03:48 AM 36,975 jusched.exe 1 File(s) 36,975 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 90112 May 11 2000 "C:\WINDOWS\bak\UpdReg.EXE" 67112 Aug 1 2006 "C:\Program Files\AIM\aim.exe" 67112 Aug 1 2006 "C:\Program Files\AIM\bak\aim.exe" 270336 Sep 21 2003 "C:\Program Files\Dell AIO Printer A960\bak\dlbfbmgr.exe" 278528 Feb 23 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 155648 Oct 29 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 59392 Aug 10 2004 "C:\WINDOWS\EHOME\bak\ehtray.exe" 15360 Aug 10 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe" 15360 Aug 10 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe" 483328 Aug 20 2003 "C:\WINDOWS\SYSTEM32\bak\hphmon05.exe" 339968 Aug 25 2004 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 57344 Aug 23 2004 "C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe" 49152 Jun 25 2003 "C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 221184 Aug 20 2003 "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe" 135168 Mar 23 2004 "C:\Program Files\Intel\Intel Application Accelerator\bak\iaanotif.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" 110592 Sep 26 2005 "C:\Program Files\McAfee\SpamKiller\MSKAgent.exe" 110592 Sep 26 2005 "C:\Program Files\McAfee\SpamKiller\bak\MskAgent.exe" 1121280 Nov 7 2006 "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" 1121792 Aug 12 2005 "C:\Program Files\McAfee\SpamKiller\bak\MSKDetct.exe" 1005096 Nov 11 2005 "C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe" 1380352 Mar 24 2004 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 53248 Apr 19 2004 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mmtask.exe" 53248 Apr 19 2004 "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mmtask.exe" 131072 Apr 19 2004 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mm_tray.exe" 131072 Apr 19 2004 "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe" 26112 Nov 19 2004 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe" 122939 Aug 13 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe" 122939 Aug 13 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe" 77824 May 27 2004 "C:\Program Files\Dell\Support\bin\Support.exe" 323584 May 27 2004 "C:\Program Files\Common Files\Dell\EUSW\bak\Support.exe" 110592 Jan 7 2004 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" 57344 Sep 17 2003 "C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\bak\CTSysVol.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" 36975 Apr 13 2005 "C:\Program Files\Java\jre1.5.0_03\bin\bak\jusched.exe" end of report i have no idea wat ne of it means |
|
|
Jan 27 2007, 01:18 PM
Post
#6
|
|
![]() Malware Slayer Extraordinaire! Posts: 11,517 From: Mass, USA :) OS: XP |
Please follow the instructions provided, you may want to print out these instructions and use them as a reference.
First download AVG Anti-Spyware from HERE and save that file to your desktop. This is a 30 day trial of the program
Thanks, Excal |
|
|
Jan 27 2007, 06:26 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 40 OS: Windows XP |
ok i ran both of the scans, and here is what came up for FindAWF
Find AWF report by noahdfear ©2006 21504 byte files found ~~~~~~~~~~~~~ 21504 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 25600 byte files found ~~~~~~~~~~~~~ 25600 "C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\data\TrafficHist.xdb" 25600 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 26450 byte files found ~~~~~~~~~~~~~ 26450 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 05/11/2000 01:00 AM 90,112 UpdReg.EXE 1 File(s) 90,112 bytes Directory of C:\PROGRA~1\AIM\BAK 08/01/2006 03:35 PM 67,112 aim.exe 1 File(s) 67,112 bytes Directory of C:\PROGRA~1\DELLAI~1\BAK 09/21/2003 09:21 AM 270,336 dlbfbmgr.exe 1 File(s) 270,336 bytes Directory of C:\PROGRA~1\ITUNES\BAK 02/23/2006 03:45 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 10/29/2006 07:20 PM 155,648 qttask.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\EHOME\BAK 08/10/2004 04:04 AM 59,392 ehtray.exe 1 File(s) 59,392 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/10/2004 05:00 AM 15,360 ctfmon.exe 08/20/2003 03:15 PM 483,328 hphmon05.exe 2 File(s) 498,688 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 08/25/2004 12:52 PM 339,968 atiptaxx.exe 1 File(s) 339,968 bytes Directory of C:\PROGRA~1\CYBERL~1\POWERDVD\BAK 08/23/2004 06:19 PM 57,344 DVDLauncher.exe 1 File(s) 57,344 bytes Directory of C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK 06/25/2003 11:24 AM 49,152 HPWuSchd.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 08/20/2003 03:23 PM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HP\HPCORE~1\BAK 08/20/2003 02:57 PM 221,184 hpcmpmgr.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\INTEL\INTELA~1\BAK 03/23/2004 12:16 PM 135,168 iaanotif.exe 1 File(s) 135,168 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09/03/2003 08:12 PM 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\MCAFEE\SPAMKI~1\BAK 09/26/2005 10:26 AM 110,592 MskAgent.exe 08/12/2005 04:16 PM 1,121,792 MSKDetct.exe 2 File(s) 1,232,384 bytes Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 03/24/2004 03:56 PM 1,380,352 MpfTray.exe 1 File(s) 1,380,352 bytes Directory of C:\PROGRA~1\MUSICM~1\MUSICM~2\BAK 04/19/2004 02:45 PM 131,072 mm_tray.exe 04/19/2004 02:45 PM 53,248 mmtask.exe 2 File(s) 184,320 bytes Directory of C:\PROGRA~1\REAL\REALPL~1\BAK 11/19/2004 11:42 PM 26,112 RealPlay.exe 1 File(s) 26,112 bytes Directory of C:\WINDOWS\SYSTEM32\DLA\BAK 08/13/2004 01:05 AM 122,939 tfswctrl.exe 1 File(s) 122,939 bytes Directory of C:\PROGRA~1\COMMON~1\DELL\EUSW\BAK 05/27/2004 08:05 PM 323,584 Support.exe 1 File(s) 323,584 bytes Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK 01/07/2004 01:01 AM 110,592 sgtray.exe 1 File(s) 110,592 bytes Directory of C:\PROGRA~1\CREATIVE\SOUNDB~1\SURROU~1\BAK 09/17/2003 10:43 AM 57,344 CTSysVol.exe 1 File(s) 57,344 bytes Directory of C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK 04/13/2005 03:48 AM 36,975 jusched.exe 1 File(s) 36,975 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 90112 May 11 2000 "C:\WINDOWS\bak\UpdReg.EXE" 67112 Aug 1 2006 "C:\Program Files\AIM\aim.exe" 67112 Aug 1 2006 "C:\Program Files\AIM\bak\aim.exe" 270336 Sep 21 2003 "C:\Program Files\Dell AIO Printer A960\bak\dlbfbmgr.exe" 278528 Feb 23 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 155648 Oct 29 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 59392 Aug 10 2004 "C:\WINDOWS\EHOME\bak\ehtray.exe" 15360 Aug 10 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe" 15360 Aug 10 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe" 483328 Aug 20 2003 "C:\WINDOWS\SYSTEM32\bak\hphmon05.exe" 339968 Aug 25 2004 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe" 57344 Aug 23 2004 "C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe" 49152 Jun 25 2003 "C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd.exe" 49152 Aug 20 2003 "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe" 221184 Aug 20 2003 "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe" 135168 Mar 23 2004 "C:\Program Files\Intel\Intel Application Accelerator\bak\iaanotif.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" 110592 Sep 26 2005 "C:\Program Files\McAfee\SpamKiller\MSKAgent.exe" 110592 Sep 26 2005 "C:\Program Files\McAfee\SpamKiller\bak\MskAgent.exe" 1121280 Nov 7 2006 "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" 1121792 Aug 12 2005 "C:\Program Files\McAfee\SpamKiller\bak\MSKDetct.exe" 1005096 Nov 11 2005 "C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe" 1380352 Mar 24 2004 "C:\Program Files\McAfee.com\Personal Firewall\bak\MpfTray.exe" 53248 Apr 19 2004 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mmtask.exe" 53248 Apr 19 2004 "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mmtask.exe" 131072 Apr 19 2004 "C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\mm_tray.exe" 131072 Apr 19 2004 "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe" 26112 Nov 19 2004 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe" 122939 Aug 13 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe" 122939 Aug 13 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe" 77824 May 27 2004 "C:\Program Files\Dell\Support\bin\Support.exe" 323584 May 27 2004 "C:\Program Files\Common Files\Dell\EUSW\bak\Support.exe" 110592 Jan 7 2004 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" 57344 Sep 17 2003 "C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\bak\CTSysVol.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" 36975 Apr 13 2005 "C:\Program Files\Java\jre1.5.0_03\bin\bak\jusched.exe" end of report and here is what came up for AVG --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 6:15:29 PM 1/27/2007 + Scan result: C:\Documents and Settings\Mark\Local Settings\Temp\czjme.exe -> Downloader.Small.dyr : Cleaned. C:\WINDOWS\SYSTEM32\sgmmljis.exe -> Downloader.Tiny.bm : Cleaned. C:\WINDOWS\SYSTEM32\ipv6motq.dll -> Logger.BZub.fh : Cleaned. C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP108\A0076901.dll -> Logger.Small.ez : Cleaned. C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@amazonsearsca.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@cnn.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@hertz.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@leeenterprises.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@scrippshgtv.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@thestreet.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@harpo.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@leeenterprises.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@nasdaq.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@powellsbooks.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@scholastic.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@stpetersburgtimes.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@bfast[2].txt -> TrackingCookie.Bfast : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@bfast[1].txt -> TrackingCookie.Bfast : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@cz11.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@cz9.clickzs[1].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@vip2.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@cz11.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@cz4.clickzs[1].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@cz5.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@data.coremetrics[2].txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@twci.coremetrics[2].txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@epilot[1].txt -> TrackingCookie.Epilot : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@www.epilot[1].txt -> TrackingCookie.Epilot : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@e-2dj6wfkyshdzgbo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@e-2dj6wfl4aldpogp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@e-2dj6wfmikjajeko.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@e-2dj6wjkyoncjilo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@ehg-lowermybills.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@ehg-charlesschwab.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@ehg-wssuk.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@ehg-foxsports.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@ehg-groupernetworks.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@ehg-mgmmirageoperations.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@ehg-youtube.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@phg.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@counter2.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@searchportal.information[1].txt -> TrackingCookie.Information : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@searchportal.information[2].txt -> TrackingCookie.Information : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@sales.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@image.masterstats[2].txt -> TrackingCookie.Masterstats : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@image.masterstats[2].txt -> TrackingCookie.Masterstats : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@data1.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@data1.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@perf.overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@data3.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@paycounter[2].txt -> TrackingCookie.Paycounter : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@paycounter[1].txt -> TrackingCookie.Paycounter : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@web4.realtracker[2].txt -> TrackingCookie.Realtracker : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@counter7.sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Brett\Local Settings\Temp\Cookies\brett@sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@counter14.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@spylog[1].txt -> TrackingCookie.Spylog : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@reduxads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\Brett\Cookies\brett@xxxcounter[2].txt -> TrackingCookie.Xxxcounter : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Cheri\Cookies\cheri@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\Mark\Cookies\mark@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\Sam\Cookies\sam@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP108\A0076899.dll -> Trojan.Agent.fd : Cleaned. C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP108\A0076904.dll -> Trojan.Agent.fd : Cleaned. C:\WINDOWS\SYSTEM32\Service.exe -> Trojan.Agent.fd : Cleaned. C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP83\A0036058.exe -> Trojan.Agent.rx : Cleaned. C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP83\A0036059.exe -> Trojan.Agent.rx : Cleaned. C:\WINDOWS\SYSTEM32\aunabljk.exe -> Trojan.GoldSpy : Cleaned. ::Report end |
|
|
Jan 28 2007, 05:16 PM
Post
#8
|
|
![]() Malware Slayer Extraordinaire! Posts: 11,517 From: Mass, USA :) OS: XP |
lets see if we can get this taking care of
Please download the two files I have attached to this post, but do not do anything with them yet Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only *NOTE* ATF deletes EVERYTHING out of temp/temporary folders and does not make backups. We will use this program later. Download the latest version of Runtime Environment (JRE) 6 Update
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. For Technical Support, double-click the e-mail address located at the bottom of each menu. Reboot back to normal mode Right-Click HERE and Save As (in IE it's "Save Target As") to download DelDomains.inf to your desktop. To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart) Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.Re-Start your Computer Please run FindAWF again and post that log, along with a fresh HiJackthis log. Thanks, Excal |
|
|
Jan 28 2007, 07:07 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 40 OS: Windows XP |
ok here we go, AWF first Find AWF report by noahdfear ©2006 21504 byte files found ~~~~~~~~~~~~~ 21504 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 25600 byte files found ~~~~~~~~~~~~~ 25600 "C:\Program Files\Java\jre1.6.0\bin\keytool.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\kinit.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\klist.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\ktab.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\orbd.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\pack200.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\policytool.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\rmid.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\rmiregistry.exe" 25600 "C:\Program Files\Java\jre1.6.0\bin\servertool.exe" 25600 "C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\data\TrafficHist.xdb" 25600 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 26450 byte files found ~~~~~~~~~~~~~ 26450 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 05/11/2000 01:00 AM 90,112 UpdReg.EXE 1 File(s) 90,112 bytes Directory of C:\PROGRA~1\AIM\BAK 08/01/2006 03:35 PM 67,112 aim.exe 1 File(s) 67,112 bytes Directory of C:\PROGRA~1\DELLAI~1\BAK 09/21/2003 09:21 AM 270,336 dlbfbmgr.exe 1 File(s) 270,336 bytes Directory of C:\PROGRA~1\ITUNES\BAK 02/23/2006 03:45 PM 278,528 iTunesHelper.exe 1 File(s) 278,528 bytes Directory of C:\PROGRA~1\MESSEN~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 10/29/2006 07:20 PM 155,648 qttask.exe 1 File(s) 155,648 bytes Directory of C:\WINDOWS\EHOME\BAK 08/10/2004 04:04 AM 59,392 ehtray.exe 1 File(s) 59,392 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/10/2004 05:00 AM 15,360 ctfmon.exe 08/20/2003 03:15 PM 483,328 hphmon05.exe 2 File(s) 498,688 bytes Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK 08/25/2004 12:52 PM 339,968 atiptaxx.exe 1 File(s) 339,968 bytes Directory of C:\PROGRA~1\CYBERL~1\POWERDVD\BAK 08/23/2004 06:19 PM 57,344 DVDLauncher.exe 1 File(s) 57,344 bytes Directory of C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK 06/25/2003 11:24 AM 49,152 HPWuSchd.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HEWLET~1\{45B61~1\BAK 08/20/2003 03:23 PM 49,152 hphupd05.exe 1 File(s) 49,152 bytes Directory of C:\PROGRA~1\HP\HPCORE~1\BAK 08/20/2003 02:57 PM 221,184 hpcmpmgr.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\INTEL\INTELA~1\BAK 03/23/2004 12:16 PM 135,168 iaanotif.exe 1 File(s) 135,168 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09/03/2003 08:12 PM 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\PROGRA~1\MCAFEE\SPAMKI~1\BAK 09/26/2005 10:26 AM 110,592 MskAgent.exe 08/12/2005 04:16 PM 1,121,792 MSKDetct.exe 2 File(s) 1,232,384 bytes Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK 03/24/2004 03:56 PM 1,380,352 MpfTray.exe 1 File(s) 1,380,352 bytes Directory of C:\PROGRA~1\MUSICM~1\MUSICM~2\BAK 04/19/20 |