View Single Post
Old 08-16-2007, 09:23 AM   #10 (permalink)
Ried
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,553
OS: WinXP and Vista


Re: Possible virus -- changed windows background (not desktop background)

1. Download FindAWF

2. Download AVG Anti Spyware

Install AVG Anti Spyware
  • Double-click the icon on Desktop to launch AVG
  • On the main Status screen, under Your Computer's Security, click Resident Shield
  • Click the word active to change it to inactive
  • On the top of the main screen click Update.
  • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Do Not Automatically generate report after every scan"


3. When you have finished updating, run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).

4. Delete the following files if they still exist:

C:\OLD\W\smsys.dat
C:\OLD\W\explorer.exe


5. Run FindAWF.exe. When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here along with the AVG A-S results.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."

Last edited by Ried; 08-16-2007 at 09:25 AM.
Ried is offline