igrek001 Posted March 19, 2010 Author Posted March 19, 2010 This is the second OTL report: OTL Extras logfile created on: 18.03.2010 23:19:55 - Run 1 OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Administrator\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000419 | Country: Russia | Language: RUS | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 82,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 89,00% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 233,76 Gb Total Space | 208,62 Gb Free Space | 89,25% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 232,83 Gb Total Space | 211,49 Gb Free Space | 90,84% Space Free | Partition Type: FAT32 Drive F: | 5,45 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive G: | 1,91 Gb Total Space | 0,93 Gb Free Space | 48,55% Space Free | Partition Type: FAT H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: WXP-F03WF61 Current User Name: Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = SlimBrowserHtml] -- C:\Program Files\SlimBrowser\sbrowser.exe (FlashPeak, Inc.) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .exe [@ = exefile] -- Reg Error: Key error. File not found .html [@ = SlimBrowserHtml] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Program Files\SlimBrowser\sbrowser.exe" -nosp -ni (FlashPeak, Inc.) https [open] -- "C:\Program Files\SlimBrowser\sbrowser.exe" -nosp -ni (FlashPeak, Inc.) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 1 "FirewallOverride" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "443:TCP" = 443:TCP:*:Disabled:ooVoo TCP port 443 "443:UDP" = 443:UDP:*:Disabled:ooVoo UDP port 443 "37674:TCP" = 37674:TCP:*:Disabled:ooVoo TCP port 37674 "37674:UDP" = 37674:UDP:*:Disabled:ooVoo UDP port 37674 "37675:UDP" = 37675:UDP:*:Disabled:ooVoo UDP port 37675 "3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\BitLord\BitLord.exe" = C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord -- (BitLord - The Ultimate Torrent Downloader) "C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule -- (eMule-Project.net - Official eMule Homepage. Downloads, Help, Docu, News...) "C:\Program Files\Mail.Ru\Agent\magent.exe" = C:\Program Files\Mail.Ru\Agent\magent.exe:*:Enabled:Mail.Ru Aaaio -- (Mail.Ru) "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation) "C:\Documents and Settings\Administrator\tetatet\tetatet.exe" = C:\Documents and Settings\Administrator\tetatet\tetatet.exe:*:Enabled:tetatet -- () "C:\Program Files\Adobe\Acrobat.com\Acrobat.com.exe" = C:\Program Files\Adobe\Acrobat.com\Acrobat.com.exe:*:Enabled:Acrobat.com -- () "C:\Program Files\ooVoo\ooVoo.exe" = C:\Program Files\ooVoo\ooVoo.exe:*:Disabled:ooVoo -- (ooVoo) "C:\Program Files\Hercules\Classic Silver\Station2.exe" = C:\Program Files\Hercules\Classic Silver\Station2.exe:*:Enabled:Hercules Webcam Station Evolution -- (Guillemot Corporation S.A.) "C:\Program Files\SlimBrowser\sbrowser.exe" = C:\Program Files\SlimBrowser\sbrowser.exe:*:Enabled:FlashPeak SlimBrowser -- (FlashPeak, Inc.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR "{04BA5899-1B3C-4AE4-8384-60DAE6258E75}" = Âûøèâêà Êðåñòîì 1.0 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Средство передачи Windows Live "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{2350150C-6528-4517-A634-DEA66983C881}" = Joydesk Games Setup - Silly "{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java 6 Update 15 "{26D3E377-1DCA-4043-9410-B4A9BACF1033}" = Nero 7 Ultra Edition "{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6 "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java 6 Update 4 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{37CE2810-CD35-4592-9B3D-4E662B2AC1C2}" = eBook Librarian "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3E5CBADD-2E51-47C1-BBE2-B802DB6DA56A}" = Akmos MetaTrader 4.00 "{4740F152-2F61-4DEF-80C4-BFDEC8D928C3}" = Windows Live Messenger "{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack "{4E8FD73A-B055-4A62-9C37-FF36D2186328}" = AVEO USB2.0 PC Camera(S5HVTV1P20821) "{4F61F885-704C-465A-9FB9-26AEF1D2B2D9}" = Russian Phonetic YaWert - WinRus.com "{518A8485-E038-4A8C-A76B-1C868D95F13E}" = Помощник по входу в Windows Live "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8DC069E7-893C-41E1-9442-DE89FEC33371}" = Xobni Core "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard "{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003 "{903B0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Project Professional 2003 "{90510409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003 "{9091E58F-3A35-45BA-BE8A-BEAB0E236BBB}" = Основные компоненты Windows Live "{94A6BCE1-291D-4BA4-B8CE-C5B169F7A6D4}" = Russian Phonetic Student - WinRus.com "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{97F81AF1-0E47-DC99-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 ATL (x86) WinSXS MSM "{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One "{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM "{9CE2B4FB-8127-4058-B028-C5961242A480}" = Pattern Maker for cross stitch - v4 "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2 "{AF8CFA6B-3365-412D-A272-807D23B7BB59}" = Windows Live Writer "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0 "{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{BECFBF9A-9BCD-4AA6-B131-7326166648E5}" = Windows Live Toolbar "{BF731945-7AAD-45E3-A202-A60C9213915C}_is1" = ISODisk 1.1 "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D7349BBF-A382-4130-823D-EEF5B3003BD3}" = Фотоальбом Windows Live "{DB0D2734-55AB-437E-B629-1F167CAF7921}" = Ryijy Stitch Designer "{E46B2F8A-6CCD-4949-871D-F9664F2113AB}" = PayPal Plug-In "{E911BE56-F8DB-48BB-B9AA-217F5096122F}" = Windows Live Sync "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0 "{F87A8E11-02A4-4875-A3A5-5961081B0E4E}" = OpenOffice.org 2.4 "{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo "{FD4FE0F7-91FC-43A2-9C3A-187553991FFF}" = Hercules Classic Silver Webcam "25 Кадр_is1" = 25 Кадр "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11 "ALUpdate_is1" = ALTools Update "ALZip_is1" = ALZip "Âûøèâêà Êðåñòîì 1.0" = Âûøèâêà Êðåñòîì 1.0 "avast5" = avast! Free Antivirus "AVS Update Manager_is1" = AVS Update Manager 1.0 "AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3 "AVS4YOU Video Converter 6_is1" = AVS Video Converter 6 "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Creative PC-CAM Center" = Creative PC-CAM Center "Creative PD1110" = Creative WebCam NX Driver (1.02.01.0827) "Creative PD1120" = Creative WebCam NX Ultra Driver (1.01.03.0112) "Creative WebCam Monitor" = Creative WebCam Monitor "Creative WebCam NX Ultra User's Guide English" = Creative WebCam NX Ultra User's Guide (English) "eMule" = eMule "eMuleTV_is1" = eMuleTV 2.1 "ffdshow" = ffdshow (remove only) "FormatFactory (¸ñʽ¹¤³§)" = FormatFactory (¸ñʽ¹¤³§) V1.70 ¶à¹úÓïÑÔ°æ "free-downloads.net Toolbar" = free-downloads.net Toolbar "HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "Living 3D Dolphins Full Screen Saver" = Living 3D Dolphins Full Screen Saver "MailRuSputnik" = Mail.Ru Спутник 2.0.1.29 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.0.17)" = Mozilla Firefox (3.0.17) "MRA" = Mail.Ru Агент 5.2 (сборка 2405, для всех пользователей) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MSNINST" = MSN "My.Freeze.com NetAssistant" = My.Freeze.com NetAssistant "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PROSet" = Intel® PRO Network Adapters and Drivers "RealPlayer 12.0" = RealPlayer "SlimBrowser" = SlimBrowser (remove only) "Tetatet" = Tetatet Beta "The_Pirate_Bay Toolbar" = The_Pirate_Bay Toolbar "TV_Mule Toolbar" = TV_Mule Toolbar "VLC media player" = VLC media player 0.9.2 "Window Washer" = Window Washer "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Основные компоненты Windows Live "WinRAR archiver" = WinRAR archiver "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XobniMain" = Xobni "Yahoo! Companion" = Yahoo! Toolbar "Вышивка Крестом 1.0" = Вышивка Крестом 1.0 Quote
igrek001 Posted March 19, 2010 Author Posted March 19, 2010 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "QIP Infium" = QIP Infium 2.0.9026 RC4 ========== Last 10 Event Log Errors ========== [ Antivirus Events ] Error - 30.10.2008 15:49:59 | Computer Name = WXP-F03WF61 | Source = avast! | ID = 33554522 Description = Error - 11.06.2009 17:43:50 | Computer Name = WXP-F03WF61 | Source = avast! | ID = 33554522 Description = Error - 06.11.2009 22:52:28 | Computer Name = WXP-F03WF61 | Source = avast! | ID = 33554522 Description = Error - 09.11.2009 3:28:13 | Computer Name = WXP-F03WF61 | Source = avast! | ID = 33554522 Description = [ Application Events ] Error - 28.02.2010 1:25:11 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application Stitch color.exe, version 1.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 28.02.2010 1:27:01 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application Stitch color.exe, version 1.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 28.02.2010 1:31:39 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application Stitch color.exe, version 1.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 28.02.2010 1:37:45 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application Stitch color.exe, version 1.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 28.02.2010 1:50:46 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application Stitch color.exe, version 1.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 28.02.2010 15:15:51 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application Stitch color.exe, version 1.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 05.03.2010 2:28:30 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application sbrowser.exe, version 4.1.2.8, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 07.03.2010 21:59:58 | Computer Name = WXP-F03WF61 | Source = Application Error | ID = 1000 Description = Faulting application alcohol.exe, version 2.0.0.1331, faulting module , version 0.0.0.0, fault address 0x00000000. Error - 07.03.2010 22:57:31 | Computer Name = WXP-F03WF61 | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.6000.16981, faulting module , version 0.0.0.0, fault address 0x00000000. Error - 10.03.2010 0:48:31 | Computer Name = WXP-F03WF61 | Source = Application Hang | ID = 1002 Description = Hanging application Fixer.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 18.03.2010 23:24:15 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:24:35 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:24:55 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:25:15 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:25:35 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:25:55 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:26:15 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:26:35 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:26:55 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding Error - 18.03.2010 23:27:15 | Computer Name = WXP-F03WF61 | Source = DCOM | ID = 10000 Description = Unable to start a DCOM Server: {25E8A7CA-5874-4F85-BC00-35210131C444}. The error: "%2" Happened while starting this command: "C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding < End of report > Quote
ExTS Admin Starbuck Posted March 19, 2010 ExTS Admin Posted March 19, 2010 Hi igrek001 Malwarebytes Anti Malware: Please update MBAM and run another scan: Start MBAM Click on the Update tab >> click Search for Updates If it says that MBAM needs to close to update it... let it close and then restart it. On restart >> click the Scan button. Don't forget: When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found". Click OK to close the message box and continue with the removal process. Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found. Make sure that everything is checked, and click Remove Selected. When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below) The log is automatically saved and can be viewed by clicking the Logs tab in MBAM. Copy and paste the contents of that report in your next reply and exit MBAM.Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware. Please let me have the scan report in your next reply. Thanks Quote Member of:UNITE
igrek001 Posted March 20, 2010 Author Posted March 20, 2010 Hello, Starbuck! I don't have this MBAM program... where I can download it??.. Quote
ExTS Admin Starbuck Posted March 20, 2010 ExTS Admin Posted March 20, 2010 I don't have this MBAM program... where I can download it??.. It's already on your system. This is from your add/remove list: "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware Click start >>> Programs >>> Malwarebytes Anti malware. Quote Member of:UNITE
igrek001 Posted March 23, 2010 Author Posted March 23, 2010 Hello, Starbuck! Here is the report from Malwarebytes scanner: Malwarebytes' Anti-Malware 1.44 Database version: 3510 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 22.03.2010 23:27:53 mbam-log-2010-03-22 (23-27-53).txt Scan type: Quick Scan Objects scanned: 119874 Time elapsed: 10 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thank you very much!! Quote
ExTS Admin Starbuck Posted March 23, 2010 ExTS Admin Posted March 23, 2010 Hi igrek001 I'm not surprised that MBAM didn't find anything..... it's so far out of date! Malwarebytes' Anti-Malware 1.44 Database version: 3510 Todays Database version is 3907. This means that MBAM has been updated 397 times since you last updated your copy: Please update MBAM and run another scan: Start MBAM Click on the Update tab >> click Search for Updates If it says that MBAM needs to close to update it... let it close and then restart. On restart >> click the Scan button. Don't forget: When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found". Click OK to close the message box and continue with the removal process. Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found. Make sure that everything is checked, and click Remove Selected. When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below) The log is automatically saved and can be viewed by clicking the Logs tab in MBAM. Copy and paste the contents of that report in your next reply and exit MBAM.Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware. Thanks Quote Member of:UNITE
igrek001 Posted March 26, 2010 Author Posted March 26, 2010 Hello, Starbuck!!.. I can't update MBAM program: when I click on 'Check for Updates' in the Update tab, message appears: 'An error occured. Please report the following error code to the MBAM support team. Error code: 732 (12007,0) Quote
ExTS Admin Starbuck Posted March 26, 2010 ExTS Admin Posted March 26, 2010 Hi igrek001 I can't update MBAM program: when I click on 'Check for Updates' in the Update tab, message appears: 'An error occured. That's one of the reasons i wanted you to try to update it and run a scan. Sometimes this type of malware removes parts of MBAM. Try removing the program and download a fresh copy using the instructions below. Please download Malwarebytes Anti-Malware and save it to your desktop. Make sure you are connected to the Internet. Double-click on Download_mbam-setup.exe to install the application. When the installation begins, follow the prompts and do not make any changes to default settings. When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-Malware Launch Malwarebytes' Anti-Malware [*]Then click Finish. [*]MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install. [*]On the Scanner tab:Make sure the "Perform Full Scan" option is selected. Then click on the Scan button. [*]If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button. [*]The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient. [*]When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found". [*]Click OK to close the message box and continue with the removal process. [*]Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found. [*]Make sure that everything is checked, and click Remove Selected. [*]When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below) [*]The log is automatically saved and can be viewed by clicking the Logs tab in MBAM. [*]Copy and paste the contents of that report in your next reply and exit MBAM.Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware. Thanks Quote Member of:UNITE
igrek001 Posted March 28, 2010 Author Posted March 28, 2010 Hello, Starbuck!... Even after reinstallation, there was the 3510 version... but it found 11 infected malwares, and removed all of them... I'm sending you copy of the logfile, which was saved: Malwarebytes' Anti-Malware 1.44 Database version: 3510 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 28.03.2010 0:35:23 mbam-log-2010-03-28 (00-35-23).txt Scan type: Full Scan (C:\|D:\|E:\|) Objects scanned: 195454 Time elapsed: 43 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 11 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Desktopicon\eBayShortcuts.exe.vir (Adware.ADON) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\Program Files\Wyeke\uninstall.exe.vir (Adware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP207\A0034106.exe (Adware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP207\A0034107.exe (Adware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP207\A0034108.exe (Adware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP207\A0034110.exe (Adware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP208\A0034309.exe (Adware.ADON) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP208\A0034312.exe (Adware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP208\A0034356.sys (Malware.Trace) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP209\A0036346.sys (Malware.Trace) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{6B8BF05F-EEFE-4A41-96AD-B82E393DA7FC}\RP210\A0036516.sys (Malware.Trace) -> Quarantined and deleted successfully. Quote
ExTS Admin Starbuck Posted March 28, 2010 ExTS Admin Posted March 28, 2010 Hi igrek001 We have to get this program updated, it's no use to us like it is. Let's try this again: Start MBAM Click on the Update tab http://img.photobucket.com/albums/v708/starbuck50/mbam1.png click Check for Updates http://img.photobucket.com/albums/v708/starbuck50/mbam2.png If it says that MBAM needs to close to update it... let it close and then restart. When it reopens >> click the Scan button. If that brings no joy, do you have MBAM on your laptop? if not.... please install a fresh copy from this link: Malwarebytes Anti-Malware once installed, update it to the latest definitions.... should be at least 3922 Now we need to transfer the 'rules.ref' file from the laptop to the other m/c. (either by usb stick or cd) Copy rules.ref to the location indicated for your operating system. If you cannot see the folder, then you may have to show Hidden Files * XP: C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware * Vista: C:\Documents and Settings\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware Then perform a new Quick Scan in normal mode and check all items found for removal. Don't forgot to reboot afterwards. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. When done, click the Logs tab and copy/paste the contents of the new report in your next reply. Thanks Quote Member of:UNITE
igrek001 Posted March 28, 2010 Author Posted March 28, 2010 Hello, Starbuck!.. I downloaded the MBAM to my laptop, then updated it to the 3924 version, but cannot transfer to my PC. Cannot find the rules.ref file, and when I try to copy all MBAM folder from fleshdrive, always error message appears. The same result I got, when tried to update MBAM on my PC... :-( Quote
ExTS Admin Starbuck Posted March 28, 2010 ExTS Admin Posted March 28, 2010 Hi igrek001, I know that the infected system is XP, but what OS is the laptop? Let me know and i'll give you detailed instructions. Thanks Quote Member of:UNITE
igrek001 Posted March 28, 2010 Author Posted March 28, 2010 Laptop has the same Window XP OC... Quote
ExTS Admin Starbuck Posted March 29, 2010 ExTS Admin Posted March 29, 2010 Hi igrek001 Since both OS are XP... this will be a bit easier. Step 1 Run the MBAM update on the laptop and get the latest definitions. Then close MBAM Step 2 Perform this step on each system: Make sure that you can see hidden files. Click Start. Click My Computer. Select the Tools menu and click Folder Options. Select the View Tab. Under the Hidden files and folders heading select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Click Yes to confirm. Uncheck the Hide file extensions for known file types. Click OK. Step 3 Perform this step on the laptop: We need to navigate to: C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Rules.ref Click Start. Click My Computer. Click on the C drive Click Documents and Settings folder Click All Users folder Click Application Data folder Click Malwarebytes folder Click Malwarebytes' Anti-Malware folder You will now see the 'rules.ref' file Right click on the 'rules.ref' file ... hold the right button in on the mouse and drag the file to the 'Desktop' When you release the button a menu will appear.... select 'Copy Here'. You will now have a copy of the 'Rules.ref' file on your Desktop. Insert your USB stick and transfer the file to the USB stick. Step 4 Perform this step on the 'infected system': Insert the USB stick. open the USB stick contents and transfer the 'rules.ref' to the desktop. (using the same right click method as before) Now navigate to: C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware using the same method as before. After you open the last folder you will see the old rules.ref file. Now using the right click method as before.... transfer the file from your Desktop to the same folder that the old rules.ref is in. (only this time select... Move here) You will get a message asking if you want to replace the old file with the new one.... click yes to overwrite the old file. Now close all the windows and start MBAM and run a scan. It will now scan using the new definitions. Step 5 Perform this step on each system: Hide System Files Click Start. Open My Computer. Select Tools menu Click Folder Options. Select the View Tab. Uncheck Show hidden files and foldersin the Hidden files and folders section. Select Hide protected operating system files (recommended) option. Check the Hide file extensions for known file types option. Click Yes. Click OK. Quote Member of:UNITE
igrek001 Posted March 31, 2010 Author Posted March 31, 2010 Hello, Starbuck!! Here is the last MBAM report: Malwarebytes' Anti-Malware 1.45 Malwarebytes Database version: 3935 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 30.03.2010 23:32:01 mbam-log-2010-03-30 (23-32-01).txt Scan type: Full scan (C:\|D:\|E:\|) Objects scanned: 188773 Time elapsed: 43 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 5 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\WEK9EMDHI9 (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Administrator\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Administrator\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.165.35,93.188.166.148 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bfef929e-af0f-4247-8c6d-05d5a689b84f}\NameServer (Trojan.DNSChanger) -> Data: 93.188.165.35,93.188.166.148 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{fe3e2402-ed94-4db7-83e6-fdeb07696206}\NameServer (Trojan.DNSChanger) -> Data: 93.188.165.35,93.188.166.148 -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thank you very much for your patience and real help!!! Igor Quote
ExTS Admin Starbuck Posted March 31, 2010 ExTS Admin Posted March 31, 2010 Hi igrek001 Nice one....I knew we'd get there in the end. :) Looks like MBAM has done a good job. Let's get an online scan done now and check for any leftovers. Step 1 I'd like you to do an ESET OnlineScanHold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop. Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop. [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png [*]Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetStart.png button. [*]Accept any security warnings from your browser. [*]Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png [*]Click the Start button. [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. [*]When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png [*]Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. [*]Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetBack.png button. [*]Click http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetFinish.png A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Step 2 Let me have a fresh set of reports from OTL as well, using the following instructions: Double click on OTL.exe to run it. Under Extra Registry section, select Use SafeList. Don't check the boxes beside 'LOP Check' and 'Purity Check' this time. Click on Run Scan at the top left hand corner. When done, two Notepad files will open. Please post the contents of these 2 Notepad files in your next reply. In your next reply, please submit: Eset scan report Both reports from OTL If the files are too big, feel free to attach them. Thanks Quote Member of:UNITE
igrek001 Posted April 3, 2010 Author Posted April 3, 2010 Hello, Starbuck! Yesterday I tried to perform Eset online scan. But the process was very long: I waited for 2 hours (it was found 3 threads), and go to sleep, lieving scan process go one. When I stand up in the morning the PC was still on, but no any sign of performed scan....:-( It looks that when scan was finished, Eset close itself and restart my computor. May be, later I find time to perform Eset scan again, but I still don't know how to save it to Desktop.. Thank you - Igor Quote
ExTS Admin Starbuck Posted April 3, 2010 ExTS Admin Posted April 3, 2010 Hi Igor, Let me have the new reports from OTL and i'll check them through. How is the system behaving generally? Quote Member of:UNITE
igrek001 Posted April 5, 2010 Author Posted April 5, 2010 Hello, Starbuck! The system generally works ok, but a bit slowly. Here is the OTL new report: OTL logfile created on: 04.04.2010 23:05:59 - Run 2 OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Administrator\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000419 | Country: Russia | Language: RUS | Date Format: dd.MM.yyyy 3,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 85,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 91,00% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 233,76 Gb Total Space | 206,86 Gb Free Space | 88,49% Space Free | Partition Type: NTFS D: Drive not present or media not loaded Drive E: | 232,83 Gb Total Space | 211,49 Gb Free Space | 90,84% Space Free | Partition Type: FAT32 F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: WXP-F03WF61 Current User Name: Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Minimal Quick Scan ========== Processes (SafeList) ========== PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com) PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files\SlimBrowser\sbrowser.exe (FlashPeak, Inc.) PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software) PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software) PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software) PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation) PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\OpenOffice.org 2.4\program\soffice.bin (OpenOffice.org) PRC - C:\Program Files\OpenOffice.org 2.4\program\soffice.exe (OpenOffice.org) PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) PRC - C:\Program Files\Belkin\F5D7050v5\Belkinwcui.exe (Belkin) PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) PRC - C:\Program Files\Webroot\Washer\wwDisp.exe (Webroot Software) PRC - C:\WINDOWS\system32\wwSecure.exe (Webroot Software, Inc.) PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.) PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard) PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.) PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.) PRC - C:\WINDOWS\system32\Crypserv.exe (Kenonic Controls Ltd.) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools) MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealPlayer) MOD - C:\WINDOWS\system32\msvcp71.dll (Microsoft Corporation) MOD - C:\WINDOWS\system32\msvcr71.dll (Microsoft Corporation) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software) SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software) SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software) SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software) SRV - (XobniService) -- C:\Program Files\Xobni\XobniService.exe (Xobni Corporation) SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) SRV - (wwSecSvc) -- C:\WINDOWS\system32\wwSecure.exe (Webroot Software, Inc.) SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP) SRV - (Crypkey License) -- C:\WINDOWS\System32\Crypserv.exe (Kenonic Controls Ltd.) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google IE - HKCU\..\URLSearchHook: {09900DE8-1DCA-443F-9243-26FF581438AF} - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (@Mail.Ru) IE - HKCU\..\URLSearchHook: {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {ca9e4d90-1386-42f8-9f36-df74277aabc2} - C:\Program Files\TV_Mule\tbTV_1.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search" FF - prefs.js..browser.search.defaulturl: "{searchTerms - Suchen}" FF - prefs.js..browser.search.selectedEngine: "free-downloads.net Customized Web Search" FF - prefs.js..browser.startup.homepage: "Search" FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: paypalfirefoxplugin@orbiscom:2.2.15.0 FF - prefs.js..extensions.enabledItems: {4CFC8387-5FB1-47C1-8AA4-5B7B906A591E}:1.0 FF - prefs.js..extensions.enabledItems: {37964A3C-4EE8-47b1-8321-34DE2C39BA4D}:2.0.1.20 FF - prefs.js..extensions.enabledItems: {ecdee021-0d17-467f-a1ff-c7a115230949}:2.5.6.0 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0 FF - HKLM\software\mozilla\Firefox\Extensions\\paypalfirefoxplugin@orbiscom: C:\Program Files\PayPal\PayPal Plug-In [2008.11.13 06:16:21 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.03.11 01:16:06 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.03.11 01:15:49 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.03.11 01:16:16 | 000,000,000 | ---D | M] [2008.12.12 00:25:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions [2010.03.06 03:22:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xtv209is.default\extensions [2009.10.02 23:33:46 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xtv209is.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2009.03.22 08:29:23 | 000,000,000 | ---D | M] (Спутник @Mail.Ru) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xtv209is.default\extensions\{37964A3C-4EE8-47b1-8321-34DE2C39BA4D} [2010.02.25 00:06:09 | 000,000,000 | ---D | M] (free-downloads.net Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xtv209is.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949} [2010.01.20 13:16:28 | 000,000,939 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xtv209is.default\searchplugins\conduit.xml [2010.03.07 22:57:33 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2010.03.07 22:57:33 | 000,000,000 | ---D | M] (Wyeke) -- C:\Program Files\Mozilla Firefox\extensions\{4CFC8387-5FB1-47C1-8AA4-5B7B906A591E} [2009.12.09 00:05:41 | 000,002,377 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wyeke127.xml [2010.03.07 22:57:33 | 000,002,376 | ---- | M] () -- C:\Program Files\Mozilla Firefo Quote
igrek001 Posted April 5, 2010 Author Posted April 5, 2010 part 2: O1 HOSTS File: ([2010.03.26 00:49:33 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O2 - BHO: (PCCBHO.CPCCBHO) - {22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF} - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll (Capital Intellect Inc) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (MailRuBHO Class) - {8984B388-A5BB-4DF7-B274-77B879E179DB} - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (@Mail.Ru) O2 - BHO: (greatbar23dec2009 Toolbar) - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll (Conduit Ltd.) O2 - BHO: (TV Nova Toolbar) - {ca9e4d90-1386-42f8-9f36-df74277aabc2} - C:\Program Files\TV_Mule\tbTV_1.dll (Conduit Ltd.) O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O2 - BHO: (OToolbarHelper Class) - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll () O2 - BHO: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.) O2 - BHO: (XBTBPos00 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\My.Freeze.com Toolbar\freeze_sa_us.dll File not found O3 - HKLM\..\Toolbar: (Ñïóòíèê@Mail.Ru) - {09900DE8-1DCA-443F-9243-26FF581438AF} - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (@Mail.Ru) O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (greatbar23dec2009 Toolbar) - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (TV Nova Toolbar) - {ca9e4d90-1386-42f8-9f36-df74277aabc2} - C:\Program Files\TV_Mule\tbTV_1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (PayPal Plug-In) - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll () O3 - HKLM\..\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Ñïóòíèê@Mail.Ru) - {09900DE8-1DCA-443F-9243-26FF581438AF} - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (@Mail.Ru) O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (greatbar23dec2009 Toolbar) - {A33FA729-D155-4B23-842B-2C665ECABDB6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (TV Nova Toolbar) - {CA9E4D90-1386-42F8-9F36-DF74277AABC2} - C:\Program Files\TV_Mule\tbTV_1.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software) O4 - HKLM..\Run: [MAgent] C:\Program Files\Mail.Ru\Agent\MAgent.exe (Mail.Ru) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKCU..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKCU..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com) O4 - HKCU..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe (Webroot Software) O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin Wireless G USB Adapter Client Utility.lnk = C:\Program Files\Belkin\F5D7050v5\Belkinwcui.exe (Belkin) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Íàéòè â èíòåðíåòå - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (@Mail.Ru) O8 - Extra context menu item: Íàéòè â ñëîâàðÿõ - C:\Program Files\Mail.Ru\Sputnik\MailRuSputnik.dll (@Mail.Ru) O9 - Extra Button: Отправка в блог - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Отправка в блог Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc) O9 - Extra Button: Mail.Ru Агент - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Program Files\Mail.Ru\Agent\magent.exe (Mail.Ru) O9 - Extra 'Tools' menuitem : Mail.Ru Агент - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - C:\Program Files\Mail.Ru\Agent\magent.exe (Mail.Ru) O9 - Extra Button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (Capital Intellect, Inc) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1210299458796 (WUWebControl Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210299513640 (MUWebControl Class) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 68.87.71.230 68.87.73.246 O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation) O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.07.28 13:13:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2010.03.18 23:09:48 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2009.05.20 08:12:16 | 000,000,000 | ---D | M] - E:\autorun -- [ FAT32 ] O32 - AutoRun File - [2010.03.18 23:09:50 | 000,000,000 | RHSD | M] - E:\autorun.inf -- [ FAT32 ] O33 - MountPoints2\{64f62da2-96af-11dd-8251-00173fd65f11}\Shell - "" = AutoRun O33 - MountPoints2\{64f62da2-96af-11dd-8251-00173fd65f11}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{64f62da2-96af-11dd-8251-00173fd65f11}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found ========== Files/Folders - Created Within 14 Days ========== [2010.03.30 22:37:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010.03.30 22:37:38 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010.03.28 16:44:12 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2010.01.20 02:13:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009.12.04 21:13:31 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll [2009.12.04 21:13:31 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll [2009.11.19 02:39:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Xobni [2008.10.28 05:20:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia [2008.10.28 05:20:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Adobe [2008.10.09 09:15:33 | 022,404,904 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe [2008.10.08 17:08:08 | 005,047,800 | ---- | C] (Mail.Ru) -- C:\Program Files\magentsetup.exe [2008.05.08 22:58:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2008.05.08 21:29:23 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft [2006.07.28 13:13:28 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 14 Days ========== Quote
igrek001 Posted April 5, 2010 Author Posted April 5, 2010 and part 3: [2010.04.04 23:00:47 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job [2010.04.04 23:00:44 | 000,000,434 | ---- | M] () -- C:\WINDOWS\tasks\RegPowerClean.job [2010.04.04 23:00:43 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010.04.04 23:00:40 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\RPCReminder.job [2010.04.04 23:00:40 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3105199670-2300768646-1652051771-500.job [2010.04.04 23:00:27 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010.04.04 23:00:15 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010.04.04 12:07:11 | 005,505,024 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT [2010.04.04 12:07:11 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini [2010.04.04 12:04:09 | 000,000,525 | ---- | M] () -- C:\hpfr3420.xml [2010.04.04 11:57:01 | 000,001,056 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3105199670-2300768646-1652051771-500UA.job [2010.04.04 11:04:43 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Microsoft Office Word 2003.lnk [2010.04.03 01:23:29 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3105199670-2300768646-1652051771-500.job [2010.04.02 03:57:35 | 000,002,344 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Google Chrome.lnk [2010.04.01 22:57:01 | 000,001,004 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3105199670-2300768646-1652051771-500Core.job [2010.04.01 22:37:01 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FlashPeak SlimBrowser.lnk [2010.03.30 22:37:52 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2010.03.30 22:36:36 | 005,918,720 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe [2010.03.29 15:24:58 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010.03.29 15:24:46 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010.03.28 18:00:44 | 000,000,106 | ---- | M] () -- C:\Documents and Settings\Administrator\default.pls [2010.03.28 18:00:35 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2010.03.24 18:04:47 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\letter to Evercare.doc [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2010.03.30 22:37:52 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2010.03.14 23:39:31 | 000,013,184 | -HS- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\w3gXo856Mln [2010.03.05 02:28:12 | 000,014,476 | -HS- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\05rTajk [2010.02.28 00:34:33 | 000,000,085 | ---- | C] () -- C:\WINDOWS\Crypkey.ini [2010.02.28 00:34:30 | 000,024,608 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys [2010.02.28 00:34:30 | 000,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll [2009.12.07 01:46:23 | 000,000,140 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\xobni_installer_updater.log [2009.12.04 21:13:31 | 000,015,478 | ---- | C] () -- C:\WINDOWS\snpstd3.ini [2009.11.06 23:32:59 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\xobni_installer_updater.log [2009.10.29 13:53:13 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\MFC_InstDrvDLL.dll [2009.10.02 14:07:02 | 000,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\ISODisk.sys [2009.09.15 15:36:38 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\jmam.dll [2009.09.15 15:36:38 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\jmfjawt.dll [2009.09.15 15:36:37 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\jmutil.dll [2009.08.03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll [2009.06.24 10:53:01 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009.05.15 10:20:53 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI [2009.03.20 20:52:49 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2008.11.12 00:46:03 | 000,005,876 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\log.txt [2008.10.09 06:05:14 | 000,093,184 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008.10.09 02:23:35 | 001,975,910 | ---- | C] () -- C:\Program Files\sbsetup.exe [2008.10.08 23:41:54 | 000,013,768 | ---- | C] () -- C:\WINDOWS\System32\drivers\string.ini [2008.10.08 23:36:58 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2008.10.08 17:16:14 | 000,000,203 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log [2008.10.08 17:15:24 | 000,561,152 | R--- | C] () -- C:\WINDOWS\System32\hpotscl.dll [2008.05.08 15:30:05 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2006.11.02 15:15:23 | 000,004,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\WinIo.sys [2006.11.02 14:53:51 | 000,000,798 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2006.07.28 13:34:06 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll [2003.01.07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI ========== LOP Check ========== [2008.12.12 00:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2009.09.16 22:44:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\eMuleTV [2008.10.08 17:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mail.Ru [2009.10.31 00:19:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mra [2009.11.29 23:23:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\MSNInstaller [2009.07.26 23:30:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ooVoo Details [2009.10.13 23:12:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Opera [2009.02.26 23:55:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\QIP [2010.02.28 00:47:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\RyijyApp [2010.04.04 23:08:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SlimBrowser [2009.11.06 23:33:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Titanium Gears [2009.11.06 23:32:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\WeatherBug [2010.02.09 22:16:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2008.12.06 01:52:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSecurityShield Setup Files [2008.11.29 19:54:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity [2009.11.06 23:36:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Winferno [2009.02.14 10:20:10 | 000,000,358 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1223500795.job [2010.04.04 23:00:47 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job [2009.11.07 00:11:03 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\PCConfidential.job [2010.04.04 23:00:44 | 000,000,434 | ---- | M] () -- C:\WINDOWS\Tasks\RegPowerClean.job [2010.04.04 23:00:40 | 000,000,420 | ---- | M] () -- C:\WINDOWS\Tasks\RPCReminder.job ========== Purity Check ========== ========== Files - Unicode (All) ========== [2010.02.27 23:22:34 | 000,000,000 | ---D | M](C:\Program Files\25 Eaa?) -- C:\Program Files\25 Êàäð [2010.02.27 23:22:34 | 000,000,000 | ---D | M](C:\Program Files\25 Eaa?) -- C:\Program Files\25 Êàäð [2009.09.22 18:50:06 | 000,000,742 | ---- | M] ()(C:\Documents and Settings\Administrator\Desktop\FormatFactory (?nE??¤?§).lnk) -- C:\Documents and Settings\Administrator\Desktop\FormatFactory (¸ñʽ¹¤³§).lnk [2009.09.22 18:50:06 | 000,000,742 | ---- | C] ()(C:\Documents and Settings\Administrator\Desktop\FormatFactory (?nE??¤?§).lnk) -- C:\Documents and Settings\Administrator\Desktop\FormatFactory (¸ñʽ¹¤³§).lnk (C:\Program Files\25 Eaa?) -- C:\Program Files\25 Êàäð Quote
ExTS Admin Starbuck Posted April 5, 2010 ExTS Admin Posted April 5, 2010 Hi igrek001 Please let me have the rest of the report. Thanks. Quote Member of:UNITE
igrek001 Posted April 6, 2010 Author Posted April 6, 2010 Hello, Starbuck! I sent you the OTL report in full dividing it on three parts. Here is the end of report: ========== Purity Check ========== ========== Files - Unicode (All) ========== [2010.02.27 23:22:34 | 000,000,000 | ---D | M](C:\Program Files\25 Eaa?) -- C:\Program Files\25 Êàäð [2010.02.27 23:22:34 | 000,000,000 | ---D | M](C:\Program Files\25 Eaa?) -- C:\Program Files\25 Êàäð [2009.09.22 18:50:06 | 000,000,742 | ---- | M] ()(C:\Documents and Settings\Administrator\Desktop\FormatFactory (?nE??¤?§).lnk) -- C:\Documents and Settings\Administrator\Desktop\FormatFactory (¸ñʽ¹¤³§).lnk [2009.09.22 18:50:06 | 000,000,742 | ---- | C] ()(C:\Documents and Settings\Administrator\Desktop\FormatFactory (?nE??¤?§).lnk) -- C:\Documents and Settings\Administrator\Desktop\FormatFactory (¸ñʽ¹¤³§).lnk (C:\Program Files\25 Eaa?) -- C:\Program Files\25 Êàäð < End of report > Quote
ExTS Admin Starbuck Posted April 6, 2010 ExTS Admin Posted April 6, 2010 Can you let me have the extra.txt as well. It'll have been saved in the same location as the main.txt Thanks Quote Member of:UNITE
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.