This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Another Win32.Trojan.Rx victim.

18 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from June 23, 2007, 6:20 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Elrond Admin/Teacher Emeritus
More work for you.

Copy/paste the following quote box into a new Notepad (not wordpad) document. Before starting select Format from the top menu and make sure Word Wrap is NOT checked.
if exist "C:\Program Files\AIM\aim.exe" del /q "C:\Program Files\AIM\aim.exe"
copy /y "C:\Program Files\AIM\bak\aim.exe" "C:\Program Files\AIM\aim.exe"

if exist "C:\program files\itunes\iTunesHelper.exe" del /q "C:\program files\itunes\iTunesHelper.exe"
copy /y "C:\program files\itunes\bak\iTunesHelper.exe" "C:\program files\itunes\iTunesHelper.exe"

if exist "C:\Program Files\MSNMES~1\MsnMsgr.Exe" del /q "C:\Program Files\MSNMES~1\MsnMsgr.Exe"
copy /y "C:\Program Files\MSNMES~1\bak\MsnMsgr.Exe" "C:\Program Files\MSNMES~1\MsnMsgr.Exe"

if exist "C:\PROGRA~1\QUICKT~1\qttask.exe" del /q "C:\PROGRA~1\QUICKT~1\qttask.exe"
copy /y "C:\PROGRA~1\QUICKT~1\BAK\qttask.exe" "C:\PROGRA~1\QUICKT~1\qttask.exe"

if exist "C:\WINDOWS\SMINST\RECGUARD.EXE" del /q "C:\WINDOWS\SMINST\RECGUARD.EXE"
copy /y "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" "C:\WINDOWS\SMINST\RECGUARD.EXE"

if exist "C:\WINDOWS\SYSTEM\hpsysdrv.exe" del /q "C:\WINDOWS\SYSTEM\hpsysdrv.exe"
copy /y "C:\WINDOWS\SYSTEM\bak\hpsysdrv.exe" "C:\WINDOWS\SYSTEM\hpsysdrv.exe"

if exist "C:\WINDOWS\SYSTEM32\hkcmd.exe" del /q "C:\WINDOWS\SYSTEM32\hkcmd.exe"
copy /y "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" "C:\WINDOWS\SYSTEM32\hkcmd.exe"

if exist "C:\WINDOWS\SYSTEM32\igfxtray.exe" del /q "C:\WINDOWS\SYSTEM32\igfxtray.exe"
copy /y "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" "C:\WINDOWS\SYSTEM32\igfxtray.exe"

if exist "C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe" del /q "C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe"
copy /y "C:\PROGRA~1\MCAFEE.COM\AGENT\bak\mcagent.exe" "C:\\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe"

if exist "C:\PROGRA~1\MCAFEE.COM\AGENT\mcupdate.exe" del /q "C:\PROGRA~1\MCAFEE.COM\AGENT\mcupdate.exe"
copy /y "C:\PROGRA~1\MCAFEE.COM\AGENT\bak\mcupdate.exe" "C:\PROGRA~1\MCAFEE.COM\AGENT\mcupdate.exe"

if exist "C:\PROGRA~1\MCAFEE.COM\PERSON~1\MpfTray.exe" del /q "C:\PROGRA~1\MCAFEE.COM\PERSON~1\MpfTray.exe"
copy /y "C:\PROGRA~1\MCAFEE.COM\PERSON~1\bak\MpfTray.exe" "C:\PROGRA~1\MCAFEE.COM\PERSON~1\MpfTray.exe"

if exist "C:\PROGRA~1\MCAFEE.COM\VSO\mcmnhdlr.exe" del /q "C:\PROGRA~1\MCAFEE.COM\VSO\mcmnhdlr.exe"
copy /y "C:\PROGRA~1\MCAFEE.COM\VSO\bak\mcmnhdlr.exe" "C:\PROGRA~1\MCAFEE.COM\VSO\mcmnhdlr.exe"

if exist "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe" del /q "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
copy /y "C:\PROGRA~1\MCAFEE.COM\VSO\bak\mcvsshld.exe" "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"

if exist "C:\PROGRA~1\MCAFEE.COM\VSO\oasclnt.exe" del /q "C:\PROGRA~1\MCAFEE.COM\VSO\oasclnt.exe""
copy /y "C:\PROGRA~1\MCAFEE.COM\VSO\bak\oasclnt.exe" "C:\PROGRA~1\MCAFEE.COM\VSO\oasclnt.exe""

if exist "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe" del /q "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
copy /y "C:\PROGRA~1\PANICW~1\POP-UP~2\bak\PSFree.exe" "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"

if exist "C:\PROGRA~1\VERITA~1\UPDATE~1\sgtray.exe" del /q "C:\PROGRA~1\VERITA~1\UPDATE~1\sgtray.exe"
copy /y "C:\PROGRA~1\VERITA~1\UPDATE~1\bak\sgtray.exe" "C:\PROGRA~1\VERITA~1\UPDATE~1\sgtray.exe"

if exist "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\realsched.exe" del /q "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\realsched.exe"
copy /y "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\bak\realsched.exe" "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\realsched.exe"

if exist "C:\PROGRA~1\HEWLET~1\DIGITA~1\UNLOAD\hpqcmon.exe" del /q "C:\PROGRA~1\HEWLET~1\DIGITA~1\UNLOAD\hpqcmon.exe"
copy /y "C:\PROGRA~1\HEWLET~1\DIGITA~1\UNLOAD\bak\hpqcmon.exe" "C:\PROGRA~1\HEWLET~1\DIGITA~1\UNLOAD\hpqcmon.exe"

Go to the menu at the top of the Notepad File and Save as
Save it to your Desktop as "awf.bat" (you MUST include the quotes)

Now, reboot your computer in Safe Mode:
Restart your computer and as soon as it starts booting up again continuously tap F8
A menu should appear, use the arrow keys to select Safe Mode and press enter

Locate awf.bat on your Desktop and double-click it.

Now reboot your computer normally and run FindAWF once more to create a new log.


Edited 6/6
KomTiely
hey, i have not done the things in your previous post, so i will wait for a new post
KomTiely
cancel that
Elrond Admin/Teacher Emeritus
In the interim I will start working on the next round. ;)
Elrond Admin/Teacher Emeritus
Still waiting for your answers. Do you still need help?
Elrond Admin/Teacher Emeritus
This topic is now closed due to inactivity. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Please do not contact us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.