Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

about blank


  • Please log in to reply

#1
johncstx

johncstx

    Member

  • Member
  • PipPip
  • 10 posts
my computer has been running real slow and my friend said about blank is a virus. can anyone help? im not too crafty with computers so any suggestions on my log would be sweet.

Logfile of HijackThis v1.99.1
Scan saved at 6:31:52 PM, on 10/30/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\aol\1144807810\ee\AOLOpenRide.exe
C:\Program Files\Common Files\AOL\1144807810\ee\aolsoftware.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\common files\aol\1144807810\ee\services\sscAntiSpywarePlugin\ver1_210_2_1\AOLSP Scheduler.exe
C:\Documents and Settings\John Curley\Local Settings\Temp\Temporary Directory 6 for hijackthis.zip\HijackThis.exe
c:\program files\common files\aol\1144807810\ee\aolssc.exe
C:\WINDOWS\System32\cidaemon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shsu.edu/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Startup: AOL OpenRide.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
  • 0

Advertisements


#2
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Welcome johncstx! :whistling:

I will be helping you under the guidance of one of our expert coaches.

Please give me a little time to get back to you with instructions.

Thanks
Jamie
  • 0

#3
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey johncstx

Put Hijackthis in a Permanent Location:

Please put Hijackthis in a permanent location i.e. C:\Hijackthis. See here for instructions:
  • First put hijackthis into a permanent folder.
  • Do this first - go to C: and create a new permanent folder.
  • Example C:\hijackthis
  • This is necessary to ensure you have backups should anything go wrong.
  • Then put (or download - choose "save" not "run") the hijackthis.exe file in this folder.
  • If you downloaded a zipped HJT file unzip it to the permanent folder so you have C:\hijackthis\hijackthis.exe.
This is an excellent guide if you have any problems:Step-by-step tutorial

We can definitely help you, but first you need to help us. The first step in this process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time. DO NOT UPGRADE TO SP2 AT THIS TIME
  • Click HERE for the update.
  • Apply the update.
  • REBOOT YOUR SYSTEM
  • Post a fresh Hijack This log

  • 0

#4
johncstx

johncstx

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Ok i did what you said and downloaded those programs the microsoft one took a really long time so long i let it run over night and when i woke up the computer had shut itself down either that or the program reboot it or something anyways heres my new log. thanks

Logfile of HijackThis v1.99.1
Scan saved at 1:16:54 AM, on 11/2/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
C:\WINDOWS\System32\cisvc.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\AOL\1144807810\ee\aolsoftware.exe
c:\program files\common files\aol\1144807810\ee\AOLOpenRide.exe
c:\program files\common files\aol\1144807810\ee\services\sscAntiSpywarePlugin\ver1_210_2_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1144807810\ee\aolssc.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Documents and Settings\John Curley\Local Settings\Temp\Temporary Directory 7 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shsu.edu/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Startup: AOL OpenRide.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
  • 0

#5
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Please can you follow the instructions for putting Hijackthis in a permanent location again because you seem to have missed it.

Thanks
  • 0

#6
johncstx

johncstx

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts

Please can you follow the instructions for putting Hijackthis in a permanent location again because you seem to have missed it.

Thanks


Ok I think i have the Hijack this saved in a permanent location but i have it saved twice once in a permanent and once in a temporary. the other program i had downloaded the microsoft one said it did not work because some files were damaged and i needed the original disk to repair the files??? Now what? oh and now it says my virtual memory is low...crap! my computer sucks now. what do we do now?
  • 0

#7
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey johncstx

To avoid confusion please can you delete the Hijackthis version that is in the temporary location.

Uninstall List:

1. Open Hijackthis and select: Open the Misc Tools section.
2. Then choose: Open Uninstall Manager and click Save List.
3. Save the list to your computer.
4. Then copy the contents of the list back to this thread in your next reply.

Please can you also post a Hijackthis log.
  • 0

#8
johncstx

johncstx

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts

Hey johncstx

To avoid confusion please can you delete the Hijackthis version that is in the temporary location.

Uninstall List:

1. Open Hijackthis and select: Open the Misc Tools section.
2. Then choose: Open Uninstall Manager and click Save List.
3. Save the list to your computer.
4. Then copy the contents of the list back to this thread in your next reply.

Please can you also post a Hijackthis log.


Ok I think i have it covered now. Sorry man i suck at computers. Im learning as we go though. see if this works.

3D Ultra RC Racers
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.8
AOL Registration
AOL Toolbar
AOL Uninstaller (Choose which Products to Remove)
AOL You've Got Pictures Screensaver
Classic PhoneTools
Conexant HSF V92 56K Data Fax PCI Modem
Dell Modem-On-Hold
Dell Picture Studio - Dell Image Expert
Dell Solution Center
Dell Support
Digital Line Detect
DivX
DivX Player
Easy CD Creator 5 Basic
Google Earth
HijackThis 1.99.1
hp instant support
HP Memories Disc
HP Photo Imaging Software
HP Photo Printing Software
HP Software Update
J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment Standard Edition v1.3.1_04
Kazaa Media Desktop 2.0.2
LimeWire 4.12.6
Macromedia Shockwave Player
MediaLoads
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft AntiSpyware
Microsoft Office XP Professional with FrontPage
Microsoft Picture It! Express 2000
Modem Helper
MSN Messenger 6.2
MUSICMATCH Jukebox
MySpyProtector
Paint Shop Pro 7
Photosmart 140,240,7200,7600,7700,7900 Series
Pure Networks Port Magic
QuickTime
RealPlayer Basic
Sam Menu
Screensavers Installer Version 2
Search Assistant
USB Driver
Viewpoint Media Player
WebSearch Tools
Windows XP Hotfix (SP1) [See Q312370 for more information]
Windows XP Service Pack 1a
WordPerfect Office 2002
WordPerfect Office 2002
Yahoo! Browser Services
Yahoo! Mail
Yahoo! Messenger
Yahoo! Toolbar

Logfile of HijackThis v1.99.1
Scan saved at 12:49:36 AM, on 11/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
C:\WINDOWS\System32\cisvc.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\aol\1144807810\ee\AOLOpenRide.exe
C:\Program Files\Common Files\AOL\1144807810\ee\aolsoftware.exe
c:\program files\common files\aol\1144807810\ee\services\sscAntiSpywarePlugin\ver1_210_2_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1144807810\ee\aolssc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\New Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shsu.edu/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Startup: AOL OpenRide.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JavaSoft\JRE\1.3.1_04\bin\npjava131_04.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
  • 0

#9
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey johncstx

Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

Update Java:

Your version of Java is now outdated. Java vulnerabilites are commonly exploited by viruses so I strongly recommend you update. Click here to download the latest version of java ( Java Runtime Environment (JRE) 5.0 Update 9 ). Please install it and then reboot your computer.

Remove the older versions of Java:
  • Click Start, Control Panel, Add/Remove Programs.
  • Delete all Java updates except J2SE Runtime Environment 5.0 Update 9
Uninstall Bad Programs:

1. Click Start >> Control Panel >> Add/Remove Programs
2. Select each of these programs, click Remove and follow the prompts to uninstall them:

J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment Standard Edition v1.3.1_04
Kazaa Media Desktop 2.0.2
LimeWire 4.12.6
MediaLoads
Search Assistant
WebSearch Tools


Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Download Clean.bat to your desktop: This file is used to clean out your TEMPORARY and PREFETCH files.
http://www.thatcompu...loads/clean.bat Save it on your desktop for later use

Kaspersky Online Scanner
Go to http://www.kaspersky.com/virusscanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post with another HJT log.

  • 0

#10
johncstx

johncstx

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Ok I think we definately made some progress but it seems as if a few viruses were detected so here the log and the results of the scan.


KASPERSKY ONLINE SCANNER REPORT
Tuesday, November 07, 2006 1:52:32 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 7/11/2006
Kaspersky Anti-Virus database records: 238749

Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 56138
Number of viruses found 11
Number of infected objects 65 / 0
Number of suspicious objects 0
Duration of the scan process 01:15:14

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped

C:\Documents and Settings\John Curley\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.dfd Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.did Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Documents.dsd Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kdb Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kdl Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kib Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.kpf Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\DTS\Index\MainChunk\Keywords.ksb Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Temp\2B.tmp Object is locked skipped

C:\Documents and Settings\John Curley\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\John Curley\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\John Curley\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\John Curley\Shared\# this time youve gone to far 03.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped

C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Downloads\bikini8_s.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.FunWeb.e skipped

C:\Downloads\bikini8_s.exe WiseSFX: infected - 1 skipped

C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps1 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps2 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\00010002.ci Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.fid Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.hsh Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiCL0001.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP10000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP20000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiPT0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSL0001.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSP0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiST0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiVP0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\INDEX.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk1 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk2 Object is locked skipped

C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\McAfee.com\antivirus\mcvsescn.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\McAfee.com\antivirus\oasclnt.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\McAfee.com\personal firewall\MPfTray.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Microsoft AntiSpyware\gcasServ.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\45DF2353-81ED-463D-A3B0-528FB0\A156161B-F348-48BC-84BD-1E21E9 Infected: not-a-virus:AdWare.Win32.WebSearch.an skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\45DF2353-81ED-463D-A3B0-528FB0\D406F2CC-563E-47BB-9DD4-ACFCA1 Infected: not-a-virus:AdWare.Win32.WebSearch.al skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\738268CA-9CB2-4FF0-990A-C96025\198D4E89-B6E5-4115-98BC-A05CA5 Infected: Trojan-Downloader.Win32.Wintool.f skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\738268CA-9CB2-4FF0-990A-C96025\98538E3A-FBBA-4473-A219-C26707 Infected: not-a-virus:AdWare.Win32.Wintol.y skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\8A46D8AF-E1D7-4E0C-AE27-A1486C\0C6088AF-4934-4B9F-A41C-AF2C66 Infected: not-a-virus:AdWare.Win32.WebSearch.o skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\8A46D8AF-E1D7-4E0C-AE27-A1486C\D61E5309-131B-433C-A0C4-8B6104 Infected: not-a-virus:AdWare.Win32.Wintol.ae skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\E970556E-A095-48C8-AB50-E969E1\0B98D8E3-F535-496F-ACEE-28A576 Infected: not-a-virus:AdWare.Win32.WebSearch.ac skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\EBDEE13B-C9B4-447D-869C-AB92ED\3EB04E56-93E6-4C88-B7A3-518FB4 Infected: Trojan-Downloader.Win32.Wintool.f skipped

C:\Program Files\Microsoft AntiSpyware\Quarantine\EBDEE13B-C9B4-447D-869C-AB92ED\5F28D31C-9E26-4F79-8138-CD5B89 Infected: not-a-virus:AdWare.Win32.Wintol.y skipped

C:\Program Files\Pure Networks\Port Magic\PortAOL.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Real\RealPlayer\RealPlay.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Screensavers.com\SSSInst\bin\SSSInst.dll Infected: not-a-virus:AdWare.Win32.Comet.ac skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1028\A0178679.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178738.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178741.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178742.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178743.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178744.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178745.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178746.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178747.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178748.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178749.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178750.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178751.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178752.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178753.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178754.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178755.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178756.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178757.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178758.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178759.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178760.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178761.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178762.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1030\A0178833.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1036\A0178949.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1036\A0178986.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1048\A0184511.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1055\A0190431.rbf Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1055\A0190551.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Comet.ac skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1055\A0190551.exe/stream Infected: not-a-virus:AdWare.Win32.Comet.ac skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1055\A0190551.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP1055\change.log Object is locked skipped

C:\WINDOWS\Debug\oakley.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{FE136BD2-248E-43C0-B293-CAF6080C5F60}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped

C:\WINDOWS\SYSTEM32\hkcmd.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\WINDOWS\SYSTEM32\hphmon05.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\WINDOWS\SYSTEM32\igfxtray.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\25a825e.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\25a826e.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\CORECOMP.INI Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\CTL3D32.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\DLGIMAGE.BMP Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\instchek.dll Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\Legal.txt Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\SElogo.bmp Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\SETUP.INI Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\setup1.bmp Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\setup2.bmp Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\UNINST.EXE Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\_ISREG32.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP2.DIR\_SETUP.LIB Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\25b4706.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\25b4716.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\CORECOMP.INI Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\CTL3D32.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\DLGIMAGE.BMP Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\instchek.dll Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\Legal.txt Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\SElogo.bmp Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\SETUP.INI Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\setup1.bmp Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\setup2.bmp Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\UNINST.EXE Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\_ISREG32.DLL Object is locked skipped

C:\WINDOWS\Temp\_ISTMP3.DIR\_SETUP.LIB Object is locked skipped

C:\WINDOWS\Temp\_WUTL95.DLL Object is locked skipped

C:\WINDOWS\WIADEBUG.LOG Object is locked skipped

C:\WINDOWS\WIASERVC.LOG Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 2:17:53 AM, on 11/7/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\aol\1144807810\ee\AOLOpenRide.exe
C:\Program Files\Common Files\AOL\1144807810\ee\aolsoftware.exe
C:\WINDOWS\System32\wuauclt.exe
c:\program files\common files\aol\1144807810\ee\services\sscAntiSpywarePlugin\ver1_210_2_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1144807810\ee\aolssc.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\New Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shsu.edu/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1144807810\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Startup: AOL OpenRide.lnk = C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1144807810\ee\services\sscFirewallPlugin\ver1_210_2_1\aolavupd.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
  • 0

Advertisements


#11
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey johncstx

Downloader.Agent.awf:

Please download FindAWF.exe

Run the tool and post the contents of the report in your next reply.
  • 0

#12
johncstx

johncstx

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts

Hey johncstx

Downloader.Agent.awf:

Please download FindAWF.exe

Run the tool and post the contents of the report in your next reply.


This is all spanish to me i have no idea what all this is lol. Thanks jamielaw

Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~



21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



25600 byte files found
~~~~~~~~~~~~~

25600 "C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe"
25600 "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
25600 "C:\Program Files\QuickTime\qttask.exe"
25600 "C:\WINDOWS\SYSTEM32\hkcmd.exe"
25600 "C:\WINDOWS\SYSTEM32\hphmon05.exe"
25600 "C:\WINDOWS\SYSTEM32\igfxtray.exe"
25600 "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
25600 "C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe"
25600 "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
25600 "C:\Program Files\McAfee.com\personal firewall\MPfTray.exe"
25600 "C:\Program Files\Pure Networks\Port Magic\PortAOL.exe"
25600 "C:\Program Files\Real\RealPlayer\RealPlay.exe"
25600 "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
25600 "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
25600 "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
25600 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe"
25600 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe"
25600 "C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe"


25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SYSTEM32\hkcmd.exe
C:\WINDOWS\SYSTEM32\hphmon05.exe
C:\WINDOWS\SYSTEM32\igfxtray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\McAfee.com\personal firewall\MPfTray.exe
C:\Program Files\Pure Networks\Port Magic\PortAOL.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe
C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe


26450 byte files found
~~~~~~~~~~~~~



26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\AMERIC~1.0\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\HITWAR~1\BAK

03/25/2004 05:14 PM 178,176 HitwarePKLite.exe
1 File(s) 178,176 bytes

Directory of C:\PROGRA~1\MIAF83~1\BAK

11/15/2005 12:12 PM 473,928 gcasServ.exe
1 File(s) 473,928 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/17/2004 11:43 PM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

08/18/2001 07:00 AM 13,312 ctfmon.exe
06/19/2002 02:05 PM 114,688 hkcmd.exe
02/02/2004 02:41 AM 495,616 hphmon05.exe
06/19/2002 02:14 PM 155,648 igfxtray.exe
4 File(s) 779,264 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK

12/05/2003 02:41 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\HEWLET~1\{D9466~1\BAK

11/12/2003 07:23 AM 49,152 hphupd05.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\HP\HPCORE~1\BAK

12/22/2003 07:38 AM 241,664 hpcmpmgr.exe
1 File(s) 241,664 bytes

Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK

03/07/2006 02:05 PM 992,808 MPfTray.exe
1 File(s) 992,808 bytes

Directory of C:\PROGRA~1\PURENE~1\PORTMA~1\BAK

04/05/2004 03:33 PM 99,480 PortAOL.exe
1 File(s) 99,480 bytes

Directory of C:\PROGRA~1\REAL\REALPL~1\BAK

07/06/2003 04:38 PM 26,112 RealPlay.exe
1 File(s) 26,112 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

05/02/2006 02:51 PM 3,334,144 YahooMessenger.exe
1 File(s) 3,334,144 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK

04/18/2005 12:38 PM 71,256 AOLDial.exe
1 File(s) 71,256 bytes

Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK

09/24/2006 02:50 AM 155,896 GoogleToolbarNotifier.exe
1 File(s) 155,896 bytes

Directory of C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK

08/14/2000 03:48 PM 32,768 Hpi_Monitor.exe
1 File(s) 32,768 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK

07/26/2006 02:03 AM 49,263 jusched.exe
1 File(s) 49,263 bytes


04/10/2002 04:44 PM 679,936 DirectCD.exe
1 File(s) 679,936 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK

04/20/2006 11:10 AM 50,792 AOLSoftware.exe
1 File(s) 50,792 bytes

Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK

03/27/2001 02:45 AM 36,864 printray.exe
1 File(s) 36,864 bytes

Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK

12/04/2003 06:44 AM 176,128 hpztsb09.exe
1 File(s) 176,128 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK

08/04/2006 07:13 AM 140,880 SSCRun.exe
1 File(s) 140,880 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

25600 Oct 10 2006 "C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe"
178176 Mar 25 2004 "C:\Program Files\Hitware Popup Killer Lite 3\bak\HitwarePKLite.exe"
25600 Oct 10 2006 "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
473928 Nov 15 2005 "C:\Program Files\Microsoft AntiSpyware\bak\gcasServ.exe"
25600 Oct 10 2006 "C:\Program Files\QuickTime\qttask.exe"
98304 Sep 17 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
13312 Aug 29 2002 "C:\WINDOWS\SYSTEM32\ctfmon.exe"
13312 Aug 18 2001 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe"
114688 Jun 19 2002 "C:\DRIVERS\VIDEO\HKCMD.EXE"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\hkcmd.exe"
114688 Jun 19 2002 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
114688 Jun 19 2002 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\hkcmd.exe"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\hphmon05.exe"
495616 Feb 2 2004 "C:\WINDOWS\SYSTEM32\bak\hphmon05.exe"
155648 Jun 19 2002 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\igfxtray.exe"
155648 Jun 19 2002 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
155648 Jun 19 2002 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxtray.exe"
25600 Oct 10 2006 "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
49152 Dec 5 2003 "C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe"
25600 Oct 10 2006 "C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe"
49152 Nov 12 2003 "C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\bak\hphupd05.exe"
25600 Oct 10 2006 "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
241664 Dec 22 2003 "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe"
25600 Oct 10 2006 "C:\Program Files\McAfee.com\personal firewall\MPfTray.exe"
992808 Mar 7 2006 "C:\Program Files\McAfee.com\personal firewall\bak\MPfTray.exe"
25600 Oct 10 2006 "C:\Program Files\Pure Networks\Port Magic\PortAOL.exe"
99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe"
25600 Oct 10 2006 "C:\Program Files\Real\RealPlayer\RealPlay.exe"
26112 Jul 6 2003 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe"
4621816 Sep 13 2006 "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"
3334144 May 2 2006 "C:\Program Files\Yahoo!\Messenger\bak\YahooMessenger.exe"
71256 Apr 18 2005 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
71256 Apr 18 2005 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
61440 Sep 14 2006 "C:\Program Files\Google\Google Earth\googleearth.exe"
25600 Oct 10 2006 "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
155896 Sep 24 2006 "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe"
25600 Oct 10 2006 "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
32768 Aug 14 2000 "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\bak\Hpi_Monitor.exe"
49263 Oct 12 2006 "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
49263 Jul 26 2006 "C:\Program Files\Java\jre1.5.0_08\bin\bak\jusched.exe"
25600 Oct 10 2006 "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
679936 Apr 10 2002 "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak\DirectCD.exe"
50760 Sep 29 2006 "C:\Program Files\AOL\RC\EE\aolsoftware.exe"
50760 May 9 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\AOLSoftware.exe"
50792 Apr 20 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\bak\AOLSoftware.exe"
36864 Mar 27 2001 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\printray.exe"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe"
36864 Mar 27 2001 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\bak\printray.exe"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe"
176128 Dec 4 2003 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb09.exe"
25600 Oct 10 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe"
140880 Aug 4 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\bak\SSCRun.exe"


end of report
  • 0

#13
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey johncstx

Downloader.Agent.awf:

Please launch Notepad (Start > Run, type in: notepad)
Copy/paste all the text below to it:
rmdir "C:\PROGRA~1\AMERIC~1.0\BAK"

if exist "C:\PROGRA~1\HITWAR~1\HitwarePKLite.exe" 
move "C:\PROGRA~1\HITWAR~1\BAK\HitwarePKLite.exe" "C:\PROGRA~1\HITWAR~1"
rmdir "C:\PROGRA~1\HITWAR~1\BAK"

if exist "C:\PROGRA~1\MIAF83~1\gcasServ.exe" 
move "C:\PROGRA~1\MIAF83~1\BAK\gcasServ.exe" "C:\PROGRA~1\MIAF83~1"
rmdir "C:\PROGRA~1\MIAF83~1\BAK"

if exist "C:\PROGRA~1\QUICKT~1\qttask.exe" 
move "C:\PROGRA~1\QUICKT~1\BAK\qttask.exe" "C:\PROGRA~1\QUICKT~1"
rmdir "C:\PROGRA~1\QUICKT~1\BAK"

if exist "C:\WINDOWS\SYSTEM32\ctfmon.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\ctfmon.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\WINDOWS\SYSTEM32\hkcmd.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\hkcmd.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" 
move "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak\DirectCD.exe" "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD"
rmdir "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak"

if exist "C:\WINDOWS\SYSTEM32\hphmon05.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\hphmon05.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\WINDOWS\SYSTEM32\igfxtray.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\igfxtray.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\PROGRA~1\HEWLET~1\HPSOFT~1\HPWuSchd2.exe" 
move "C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK\HPWuSchd2.exe" "C:\PROGRA~1\HEWLET~1\HPSOFT~1"
rmdir "C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK"

if exist "C:\PROGRA~1\HEWLET~1\{D9466~1\hphupd05.exe" 
move "C:\PROGRA~1\HEWLET~1\{D9466~1\BAK\hphupd05.exe" "C:\PROGRA~1\HEWLET~1\{D9466~1"
rmdir "C:\PROGRA~1\HEWLET~1\{D9466~1\BAK"

if exist "C:\PROGRA~1\HP\HPCORE~1\hpcmpmgr.exe" 
move "C:\PROGRA~1\HP\HPCORE~1\BAK\hpcmpmgr.exe" "C:\PROGRA~1\HP\HPCORE~1"
rmdir "C:\PROGRA~1\HP\HPCORE~1\BAK"

if exist "C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPfTray.exe" 
move "C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK\MPfTray.exe" "C:\PROGRA~1\MCAFEE.COM\PERSON~1"
rmdir "C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK"

if exist "C:\PROGRA~1\REAL\REALPL~1\RealPlay.exe" 
move "C:\PROGRA~1\REAL\REALPL~1\BAK\RealPlay.exe" "C:\PROGRA~1\REAL\REALPL~1"
rmdir "C:\PROGRA~1\REAL\REALPL~1\BAK"

if exist "C:\PROGRA~1\YAHOO!\MESSEN~1\YahooMessenger.exe" 
move "C:\PROGRA~1\YAHOO!\MESSEN~1\BAK\YahooMessenger.exe" "C:\PROGRA~1\YAHOO!\MESSEN~1"
rmdir "C:\PROGRA~1\YAHOO!\MESSEN~1\BAK"

if exist "C:\PROGRA~1\COMMON~1\AOL\ACS\AOLDial.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\ACS\BAK\AOLDial.exe" "C:\PROGRA~1\COMMON~1\AOL\ACS"
rmdir "C:\PROGRA~1\COMMON~1\AOL\ACS\BAK"

if exist "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\GoogleToolbarNotifier.exe" 
move "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK\GoogleToolbarNotifier.exe" "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364"
rmdir "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK"

if exist "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\Hpi_Monitor.exe" 
move "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK\Hpi_Monitor.exe" "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1"
rmdir "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK"

if exist "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\jusched.exe" 
move "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK\jusched.exe" "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\jusched.exe"
rmdir "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK"

if exist "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\AOLSoftware.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK\AOLSoftware.exe" "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE"
rmdir "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK"

if exist "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe" 
move "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK\printray.exe" "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2"
rmdir "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK"

if exist "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe" 
move "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK\hpztsb09.exe" "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3"
rmdir "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK"

if exist "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\SSCRun.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK\SSCRun.exe" "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1"
rmdir "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK"

del 123.bat

In Notepad, go to File (upper menu bar), and select: Save as
In the Save as prompt:
Save in: Desktop
File Name: "123.bat"
Save as Type: All files
Click: Save
Exit out of Notepad.

Next, on the Desktop, double click on bakfile.bat


====
Also, please run the following:

1. DelDomains
http://www.mvps.org/.../DelDomains.inf
To delete all entries in the Restricted & Trusted Zone list, right click DelDomains.inf
Select: Install

2. ResetProtocolDefaults
http://www.mvps.org/...colDefaults.reg
Right click the link, save target as or save link as, and save to the Desktop.

Locate ResetProtocolDefaults.reg on the Desktop
Right-click and select: Merge
OK the prompt

Please can you then run the Downloader.Agent.awf tool again (see post 11). Post the log back here.
  • 0

#14
johncstx

johncstx

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts

Hey johncstx

Downloader.Agent.awf:

Please launch Notepad (Start > Run, type in: notepad)
Copy/paste all the text below to it:

rmdir "C:\PROGRA~1\AMERIC~1.0\BAK"

if exist "C:\PROGRA~1\HITWAR~1\HitwarePKLite.exe" 
move "C:\PROGRA~1\HITWAR~1\BAK\HitwarePKLite.exe" "C:\PROGRA~1\HITWAR~1"
rmdir "C:\PROGRA~1\HITWAR~1\BAK"

if exist "C:\PROGRA~1\MIAF83~1\gcasServ.exe" 
move "C:\PROGRA~1\MIAF83~1\BAK\gcasServ.exe" "C:\PROGRA~1\MIAF83~1"
rmdir "C:\PROGRA~1\MIAF83~1\BAK"

if exist "C:\PROGRA~1\QUICKT~1\qttask.exe" 
move "C:\PROGRA~1\QUICKT~1\BAK\qttask.exe" "C:\PROGRA~1\QUICKT~1"
rmdir "C:\PROGRA~1\QUICKT~1\BAK"

if exist "C:\WINDOWS\SYSTEM32\ctfmon.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\ctfmon.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\WINDOWS\SYSTEM32\hkcmd.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\hkcmd.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" 
move "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak\DirectCD.exe" "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD"
rmdir "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak"

if exist "C:\WINDOWS\SYSTEM32\hphmon05.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\hphmon05.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\WINDOWS\SYSTEM32\igfxtray.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\igfxtray.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK"

if exist "C:\PROGRA~1\HEWLET~1\HPSOFT~1\HPWuSchd2.exe" 
move "C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK\HPWuSchd2.exe" "C:\PROGRA~1\HEWLET~1\HPSOFT~1"
rmdir "C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK"

if exist "C:\PROGRA~1\HEWLET~1\{D9466~1\hphupd05.exe" 
move "C:\PROGRA~1\HEWLET~1\{D9466~1\BAK\hphupd05.exe" "C:\PROGRA~1\HEWLET~1\{D9466~1"
rmdir "C:\PROGRA~1\HEWLET~1\{D9466~1\BAK"

if exist "C:\PROGRA~1\HP\HPCORE~1\hpcmpmgr.exe" 
move "C:\PROGRA~1\HP\HPCORE~1\BAK\hpcmpmgr.exe" "C:\PROGRA~1\HP\HPCORE~1"
rmdir "C:\PROGRA~1\HP\HPCORE~1\BAK"

if exist "C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPfTray.exe" 
move "C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK\MPfTray.exe" "C:\PROGRA~1\MCAFEE.COM\PERSON~1"
rmdir "C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK"

if exist "C:\PROGRA~1\REAL\REALPL~1\RealPlay.exe" 
move "C:\PROGRA~1\REAL\REALPL~1\BAK\RealPlay.exe" "C:\PROGRA~1\REAL\REALPL~1"
rmdir "C:\PROGRA~1\REAL\REALPL~1\BAK"

if exist "C:\PROGRA~1\YAHOO!\MESSEN~1\YahooMessenger.exe" 
move "C:\PROGRA~1\YAHOO!\MESSEN~1\BAK\YahooMessenger.exe" "C:\PROGRA~1\YAHOO!\MESSEN~1"
rmdir "C:\PROGRA~1\YAHOO!\MESSEN~1\BAK"

if exist "C:\PROGRA~1\COMMON~1\AOL\ACS\AOLDial.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\ACS\BAK\AOLDial.exe" "C:\PROGRA~1\COMMON~1\AOL\ACS"
rmdir "C:\PROGRA~1\COMMON~1\AOL\ACS\BAK"

if exist "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\GoogleToolbarNotifier.exe" 
move "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK\GoogleToolbarNotifier.exe" "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364"
rmdir "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK"

if exist "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\Hpi_Monitor.exe" 
move "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK\Hpi_Monitor.exe" "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1"
rmdir "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK"

if exist "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\jusched.exe" 
move "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK\jusched.exe" "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\jusched.exe"
rmdir "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK"

if exist "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\AOLSoftware.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK\AOLSoftware.exe" "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE"
rmdir "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK"

if exist "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe" 
move "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK\printray.exe" "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2"
rmdir "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK"

if exist "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe" 
move "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK\hpztsb09.exe" "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3"
rmdir "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK"

if exist "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\SSCRun.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK\SSCRun.exe" "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1"
rmdir "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK"

del 123.bat

In Notepad, go to File (upper menu bar), and select: Save as
In the Save as prompt:
Save in: Desktop
File Name: "123.bat"
Save as Type: All files
Click: Save
Exit out of Notepad.

Next, on the Desktop, double click on bakfile.bat


====
Also, please run the following:

1. DelDomains
http://www.mvps.org/.../DelDomains.inf
To delete all entries in the Restricted & Trusted Zone list, right click DelDomains.inf
Select: Install

2. ResetProtocolDefaults
http://www.mvps.org/...colDefaults.reg
Right click the link, save target as or save link as, and save to the Desktop.

Locate ResetProtocolDefaults.reg on the Desktop
Right-click and select: Merge
OK the prompt

Please can you then run the Downloader.Agent.awf tool again (see post 11). Post the log back here.


Thanks JLAw
HERE IS THE NEW LOG:



Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~



21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



25600 byte files found
~~~~~~~~~~~~~

25600 "C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe"
25600 "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
25600 "C:\Program Files\QuickTime\qttask.exe"
25600 "C:\WINDOWS\SYSTEM32\hkcmd.exe"
25600 "C:\WINDOWS\SYSTEM32\hphmon05.exe"
25600 "C:\WINDOWS\SYSTEM32\igfxtray.exe"
25600 "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
25600 "C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe"
25600 "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
25600 "C:\Program Files\McAfee.com\personal firewall\MPfTray.exe"
25600 "C:\Program Files\Pure Networks\Port Magic\PortAOL.exe"
25600 "C:\Program Files\Real\RealPlayer\RealPlay.exe"
25600 "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
25600 "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
25600 "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
25600 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe"
25600 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe"
25600 "C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe"


25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SYSTEM32\hkcmd.exe
C:\WINDOWS\SYSTEM32\hphmon05.exe
C:\WINDOWS\SYSTEM32\igfxtray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\McAfee.com\personal firewall\MPfTray.exe
C:\Program Files\Pure Networks\Port Magic\PortAOL.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe
C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe


26450 byte files found
~~~~~~~~~~~~~



26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\HITWAR~1\BAK

03/25/2004 05:14 PM 178,176 HitwarePKLite.exe
1 File(s) 178,176 bytes

Directory of C:\PROGRA~1\MIAF83~1\BAK

11/15/2005 12:12 PM 473,928 gcasServ.exe
1 File(s) 473,928 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/17/2004 11:43 PM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

08/18/2001 07:00 AM 13,312 ctfmon.exe
06/19/2002 02:05 PM 114,688 hkcmd.exe
02/02/2004 02:41 AM 495,616 hphmon05.exe
06/19/2002 02:14 PM 155,648 igfxtray.exe
4 File(s) 779,264 bytes

Directory of C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK

12/05/2003 02:41 PM 49,152 HPWuSchd2.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\HEWLET~1\{D9466~1\BAK

11/12/2003 07:23 AM 49,152 hphupd05.exe
1 File(s) 49,152 bytes

Directory of C:\PROGRA~1\HP\HPCORE~1\BAK

12/22/2003 07:38 AM 241,664 hpcmpmgr.exe
1 File(s) 241,664 bytes

Directory of C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK

03/07/2006 02:05 PM 992,808 MPfTray.exe
1 File(s) 992,808 bytes

Directory of C:\PROGRA~1\PURENE~1\PORTMA~1\BAK

04/05/2004 03:33 PM 99,480 PortAOL.exe
1 File(s) 99,480 bytes

Directory of C:\PROGRA~1\REAL\REALPL~1\BAK

07/06/2003 04:38 PM 26,112 RealPlay.exe
1 File(s) 26,112 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

05/02/2006 02:51 PM 3,334,144 YahooMessenger.exe
1 File(s) 3,334,144 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\ACS\BAK

04/18/2005 12:38 PM 71,256 AOLDial.exe
1 File(s) 71,256 bytes

Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK

09/24/2006 02:50 AM 155,896 GoogleToolbarNotifier.exe
1 File(s) 155,896 bytes

Directory of C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK

08/14/2000 03:48 PM 32,768 Hpi_Monitor.exe
1 File(s) 32,768 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK

07/26/2006 02:03 AM 49,263 jusched.exe
1 File(s) 49,263 bytes


04/10/2002 04:44 PM 679,936 DirectCD.exe
1 File(s) 679,936 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK

04/20/2006 11:10 AM 50,792 AOLSoftware.exe
1 File(s) 50,792 bytes

Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK

03/27/2001 02:45 AM 36,864 printray.exe
1 File(s) 36,864 bytes

Directory of C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK

12/04/2003 06:44 AM 176,128 hpztsb09.exe
1 File(s) 176,128 bytes

Directory of C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK

08/04/2006 07:13 AM 140,880 SSCRun.exe
1 File(s) 140,880 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

25600 Oct 10 2006 "C:\Program Files\Hitware Popup Killer Lite 3\HitwarePKLite.exe"
178176 Mar 25 2004 "C:\Program Files\Hitware Popup Killer Lite 3\bak\HitwarePKLite.exe"
25600 Oct 10 2006 "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
473928 Nov 15 2005 "C:\Program Files\Microsoft AntiSpyware\bak\gcasServ.exe"
25600 Oct 10 2006 "C:\Program Files\QuickTime\qttask.exe"
98304 Sep 17 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
13312 Aug 29 2002 "C:\WINDOWS\SYSTEM32\ctfmon.exe"
13312 Aug 18 2001 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe"
114688 Jun 19 2002 "C:\DRIVERS\VIDEO\HKCMD.EXE"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\hkcmd.exe"
114688 Jun 19 2002 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
114688 Jun 19 2002 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\hkcmd.exe"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\hphmon05.exe"
495616 Feb 2 2004 "C:\WINDOWS\SYSTEM32\bak\hphmon05.exe"
155648 Jun 19 2002 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\igfxtray.exe"
155648 Jun 19 2002 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
155648 Jun 19 2002 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxtray.exe"
25600 Oct 10 2006 "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
49152 Dec 5 2003 "C:\Program Files\Hewlett-Packard\HP Software Update\bak\HPWuSchd2.exe"
25600 Oct 10 2006 "C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe"
49152 Nov 12 2003 "C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\bak\hphupd05.exe"
25600 Oct 10 2006 "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
241664 Dec 22 2003 "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe"
25600 Oct 10 2006 "C:\Program Files\McAfee.com\personal firewall\MPfTray.exe"
992808 Mar 7 2006 "C:\Program Files\McAfee.com\personal firewall\bak\MPfTray.exe"
25600 Oct 10 2006 "C:\Program Files\Pure Networks\Port Magic\PortAOL.exe"
99480 Apr 5 2004 "C:\Program Files\Pure Networks\Port Magic\bak\PortAOL.exe"
25600 Oct 10 2006 "C:\Program Files\Real\RealPlayer\RealPlay.exe"
26112 Jul 6 2003 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe"
4621816 Sep 13 2006 "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"
3334144 May 2 2006 "C:\Program Files\Yahoo!\Messenger\bak\YahooMessenger.exe"
71256 Apr 18 2005 "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
71256 Apr 18 2005 "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe"
61440 Sep 14 2006 "C:\Program Files\Google\Google Earth\googleearth.exe"
25600 Oct 10 2006 "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
155896 Sep 24 2006 "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe"
25600 Oct 10 2006 "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
32768 Aug 14 2000 "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\bak\Hpi_Monitor.exe"
49263 Oct 12 2006 "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
49263 Jul 26 2006 "C:\Program Files\Java\jre1.5.0_08\bin\bak\jusched.exe"
25600 Oct 10 2006 "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
679936 Apr 10 2002 "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak\DirectCD.exe"
50760 Sep 29 2006 "C:\Program Files\AOL\RC\EE\aolsoftware.exe"
50760 May 9 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\AOLSoftware.exe"
50792 Apr 20 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\bak\AOLSoftware.exe"
36864 Mar 27 2001 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\printray.exe"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe"
36864 Mar 27 2001 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\bak\printray.exe"
25600 Oct 10 2006 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe"
176128 Dec 4 2003 "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb09.exe"
25600 Oct 10 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\SSCRun.exe"
140880 Aug 4 2006 "C:\Program Files\Common Files\AOL\1144807810\EE\services\sscFirewallPlugin\ver1_210_2_1\bak\SSCRun.exe"


end of report
  • 0

#15
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey johncstx

I've modified the batch slightly - it should work this time ( cross your fingers :whistling: )

Downloader.Agent.awf:

Please launch Notepad (Start > Run, type in: notepad)
Copy/paste all the text below to it:
rmdir "C:\PROGRA~1\AMERIC~1.0\BAK" /S /Q 

if exist "C:\PROGRA~1\HITWAR~1\HitwarePKLite.exe" 
move "C:\PROGRA~1\HITWAR~1\BAK\HitwarePKLite.exe" "C:\PROGRA~1\HITWAR~1"
rmdir "C:\PROGRA~1\HITWAR~1\BAK" /S /Q 

if exist "C:\PROGRA~1\MIAF83~1\gcasServ.exe" 
move "C:\PROGRA~1\MIAF83~1\BAK\gcasServ.exe" "C:\PROGRA~1\MIAF83~1"
rmdir "C:\PROGRA~1\MIAF83~1\BAK" /S /Q 

if exist "C:\PROGRA~1\QUICKT~1\qttask.exe" 
move "C:\PROGRA~1\QUICKT~1\BAK\qttask.exe" "C:\PROGRA~1\QUICKT~1"
rmdir "C:\PROGRA~1\QUICKT~1\BAK" /S /Q 

if exist "C:\WINDOWS\SYSTEM32\ctfmon.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\ctfmon.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK" /S /Q 

if exist "C:\WINDOWS\SYSTEM32\hkcmd.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\hkcmd.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK" /S /Q 

if exist "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" 
move "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak\DirectCD.exe" "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD"
rmdir "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\bak" /S /Q 

if exist "C:\WINDOWS\SYSTEM32\hphmon05.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\hphmon05.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK" /S /Q 

if exist "C:\WINDOWS\SYSTEM32\igfxtray.exe" 
move "C:\WINDOWS\SYSTEM32\BAK\igfxtray.exe" "C:\WINDOWS\SYSTEM32"
rmdir "C:\WINDOWS\SYSTEM32\BAK" /S /Q 

if exist "C:\PROGRA~1\HEWLET~1\HPSOFT~1\HPWuSchd2.exe" 
move "C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK\HPWuSchd2.exe" "C:\PROGRA~1\HEWLET~1\HPSOFT~1"
rmdir "C:\PROGRA~1\HEWLET~1\HPSOFT~1\BAK" /S /Q 

if exist "C:\PROGRA~1\HEWLET~1\{D9466~1\hphupd05.exe" 
move "C:\PROGRA~1\HEWLET~1\{D9466~1\BAK\hphupd05.exe" "C:\PROGRA~1\HEWLET~1\{D9466~1"
rmdir "C:\PROGRA~1\HEWLET~1\{D9466~1\BAK" /S /Q 

if exist "C:\PROGRA~1\HP\HPCORE~1\hpcmpmgr.exe" 
move "C:\PROGRA~1\HP\HPCORE~1\BAK\hpcmpmgr.exe" "C:\PROGRA~1\HP\HPCORE~1"
rmdir "C:\PROGRA~1\HP\HPCORE~1\BAK" /S /Q 

if exist "C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPfTray.exe" 
move "C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK\MPfTray.exe" "C:\PROGRA~1\MCAFEE.COM\PERSON~1"
rmdir "C:\PROGRA~1\MCAFEE.COM\PERSON~1\BAK" /S /Q 

if exist "C:\PROGRA~1\REAL\REALPL~1\RealPlay.exe" 
move "C:\PROGRA~1\REAL\REALPL~1\BAK\RealPlay.exe" "C:\PROGRA~1\REAL\REALPL~1"
rmdir "C:\PROGRA~1\REAL\REALPL~1\BAK" /S /Q 

if exist "C:\PROGRA~1\YAHOO!\MESSEN~1\YahooMessenger.exe" 
move "C:\PROGRA~1\YAHOO!\MESSEN~1\BAK\YahooMessenger.exe" "C:\PROGRA~1\YAHOO!\MESSEN~1"
rmdir "C:\PROGRA~1\YAHOO!\MESSEN~1\BAK" /S /Q 

if exist "C:\PROGRA~1\COMMON~1\AOL\ACS\AOLDial.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\ACS\BAK\AOLDial.exe" "C:\PROGRA~1\COMMON~1\AOL\ACS"
rmdir "C:\PROGRA~1\COMMON~1\AOL\ACS\BAK" /S /Q 

if exist "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\GoogleToolbarNotifier.exe" 
move "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK\GoogleToolbarNotifier.exe" "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364"
rmdir "C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK" /S /Q 

if exist "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\Hpi_Monitor.exe" 
move "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK\Hpi_Monitor.exe" "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1"
rmdir "C:\PROGRA~1\HEWLET~1\PHOTOS~1\PHOTOI~1\BAK" /S /Q 

if exist "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\jusched.exe" 
move "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK\jusched.exe" "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\jusched.exe"
rmdir "C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK" /S /Q 

if exist "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\AOLSoftware.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK\AOLSoftware.exe" "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE"
rmdir "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\BAK" /S /Q 

if exist "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\printray.exe" 
move "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK\printray.exe" "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2"
rmdir "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\2\BAK" /S /Q 

if exist "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb09.exe" 
move "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK\hpztsb09.exe" "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3"
rmdir "C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\BAK" /S /Q 

if exist "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\SSCRun.exe" 
move "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK\SSCRun.exe" "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1"
rmdir "C:\PROGRA~1\COMMON~1\AOL\114480~1\EE\SERVICES\SSCFIR~1\VER1_2~1\BAK" /S /Q 

del 123.bat

In Notepad, go to File (upper menu bar), and select: Save as
In the Save as prompt:
Save in: Desktop
File Name: "123.bat"
Save as Type: All files
Click: Save
Exit out of Notepad.

Next, on the Desktop, double click on bakfile.bat


====
Also, please run the following:

1. DelDomains
http://www.mvps.org/.../DelDomains.inf
To delete all entries in the Restricted & Trusted Zone list, right click DelDomains.inf
Select: Install

2. ResetProtocolDefaults
http://www.mvps.org/...colDefaults.reg
Right click the link, save target as or save link as, and save to the Desktop.

Locate ResetProtocolDefaults.reg on the Desktop
Right-click and select: Merge
OK the prompt

Please can you then run the Downloader.Agent.awf tool again (see post 11). Post the log back here.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP