Antivirus Soft -- In need of help

View previous topic View next topic Go down

Antivirus Soft -- In need of help

Post by kaputski on 17th April 2010, 11:39 pm

Ok guys I've had this virus before, and other relatives have had it before as well. I was always able to get rid of it using the basic instructions with safemode and malwarebytes, however this time it's really being stingy. I need help from the pros Smile... I'll be sitting here all night if someone is willing to help.. thanks!

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 17th April 2010, 11:42 pm

Download [You must be registered and logged in to see this link.] by OldTimer to your Desktop.

  • Close all windows and double click OTL.exe
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 17th April 2010, 11:45 pm

It's not allowing me to run the program... the program runs for a brief second then disappears

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 17th April 2010, 11:49 pm

Ohh i'm sorry the virus is Antispyware Soft

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 18th April 2010, 4:38 pm

Please download exeHelper from one of the two links.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

  • Double-click on exeHelper.com or exeHelper.scr to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 18th April 2010, 10:16 pm

I can't post any logs on here?

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 18th April 2010, 10:20 pm

OTL logfile created on: 4/18/2010 6:06:37 PM - Run 1
OTL by OldTimer - Version 3.2.1.2 Folder = C:\Users\kaput\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 66.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 285.09 Gb Total Space | 209.51 Gb Free Space | 73.49% Space Free | Partition Type: NTFS
Drive D: | 50.78 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KAPUT-PC
Current User Name: kaput
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/04/17 19:43:21 | 000,562,176 | ---- | M] (OldTimer Tools) -- C:\Users\kaput\Desktop\OTL.exe
PRC - [2009/10/14 09:30:26 | 000,476,528 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2009/10/05 22:03:05 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/09/09 20:23:04 | 000,135,168 | ---- | M] (Eagletron Inc.) -- C:\Program Files\Common Files\Eagletron\TrackerPodSvcSvr.exe
PRC - [2008/10/29 02:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/07/23 14:25:32 | 006,183,456 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/06/11 14:18:30 | 000,024,576 | ---- | M] () -- C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
PRC - [2008/02/22 07:25:21 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
PRC - [2007/08/24 07:45:42 | 000,101,784 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2007/08/16 20:17:56 | 002,342,912 | ---- | M] (BigFix Inc.) -- C:\Program Files\BigFix\bigfix.exe
PRC - [2004/05/20 08:59:32 | 001,056,768 | ---- | M] (OrangeWare, Inc.) -- C:\Windows\system\wcdvtray.exe


========== Modules (SafeList) ==========

MOD - [2010/04/17 19:43:21 | 000,562,176 | ---- | M] (OldTimer Tools) -- C:\Users\kaput\Desktop\OTL.exe
MOD - [2008/01/20 22:23:44 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/12/10 11:18:21 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-110309-193829)
SRV - [2009/11/22 15:44:16 | 002,384,240 | ---- | M] (Check Point Software Technologies LTD) [Auto | Stopped] -- C:\Windows\System32\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2009/10/14 09:30:26 | 000,476,528 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe -- (IswSvc)
SRV - [2009/09/09 20:23:04 | 000,135,168 | ---- | M] (Eagletron Inc.) [Auto | Running] -- C:\Program Files\Common Files\Eagletron\TrackerPodSvcSvr.exe -- (Eagletron TrackerPod Service)
SRV - [2008/06/11 14:18:30 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe -- (ETService)
SRV - [2008/05/05 18:25:46 | 000,165,416 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


========== Driver Services (SafeList) ==========

DRV - [2010/03/26 12:26:06 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/01/12 12:03:34 | 011,586,280 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/11/22 15:44:20 | 000,446,664 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\System32\drivers\vsdatant.sys -- (Vsdatant)
DRV - [2009/10/14 09:30:02 | 000,025,208 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2009/10/09 15:08:58 | 000,035,016 | ---- | M] (Eagletron Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\dvdriver.sys -- (DVDRIVER)
DRV - [2008/08/13 18:14:34 | 000,122,368 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/07/23 14:28:32 | 002,152,344 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/06/11 14:13:24 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\int15.sys -- (int15)
DRV - [2008/01/25 08:02:02 | 000,140,832 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2008/01/20 22:23:27 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/20 22:23:27 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/20 22:23:27 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/20 22:23:26 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/20 22:23:26 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/20 22:23:26 | 000,052,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\msdv.sys -- (MSDV)
DRV - [2008/01/20 22:23:26 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/20 22:23:25 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/20 22:23:25 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/20 22:23:24 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/20 22:23:24 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)
DRV - [2008/01/20 22:23:24 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/20 22:23:23 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/20 22:23:23 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/20 22:23:23 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/20 22:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/20 22:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/20 22:23:23 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/20 22:23:23 | 000,045,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\61883.sys -- (61883)
DRV - [2008/01/20 22:23:22 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/20 22:23:21 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/20 22:23:21 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/20 22:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/20 22:23:20 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/20 22:23:20 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\avc.sys -- (Avc)
DRV - [2008/01/20 22:23:00 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/20 22:23:00 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/20 22:23:00 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/06/01 00:11:28 | 000,252,416 | ---- | M] (Belkin Corporation. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BLKWGU.sys -- (BELKIN)
DRV - [2006/11/02 05:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 05:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 05:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 05:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 05:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 05:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 05:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 05:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 05:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 05:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 05:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 04:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 04:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 04:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 04:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 04:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 04:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 03:41:50 | 000,983,552 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/02 03:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2004/05/11 06:27:32 | 000,212,608 | ---- | M] (OrangeWare, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\WebCamDV.sys -- (WebCamDV)
DRV - [2004/01/30 13:08:59 | 000,012,672 | ---- | M] (OrangeWare, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wcdvaud.sys -- (WCDV_Aud)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = [You must be registered and logged in to see this link.]
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.5.1
FF - prefs.js..extensions.enabledItems: [You must be registered and logged in to see this link.]:3.6.6.117
FF - prefs.js..extensions.enabledItems: [You must be registered and logged in to see this link.]:2.1.0.19
FF - prefs.js..extensions.enabledItems: {7f57cf46-4467-4c2d-adfa-0cba7c507e54}:0.18.1.0
FF - prefs.js..extensions.enabledItems: {F4D5E72B-D814-4EB2-B26B-41485A9269FC}:1.9.1
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.53.4
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50-ff-aim-ab-en-us&query="


FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2010/04/17 00:24:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/01 18:50:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/17 00:39:58 | 000,000,000 | ---D | M]

[2009/04/30 14:59:19 | 000,000,000 | ---D | M] -- C:\Users\kaput\AppData\Roaming\Mozilla\Extensions
[2010/04/17 19:21:46 | 000,000,000 | ---D | M] -- C:\Users\kaput\AppData\Roaming\Mozilla\Firefox\Profiles\4ssaso2q.default\extensions
[2009/04/30 15:01:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\kaput\AppData\Roaming\Mozilla\Firefox\Profiles\4ssaso2q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/25 12:28:09 | 000,000,000 | ---D | M] (Mozilla Archive Format) -- C:\Users\kaput\AppData\Roaming\Mozilla\Firefox\Profiles\4ssaso2q.default\extensions\{7f57cf46-4467-4c2d-adfa-0cba7c507e54}
[2009/10/22 01:03:01 | 000,000,000 | ---D | M] (AIM Toolbar) -- C:\Users\kaput\AppData\Roaming\Mozilla\Firefox\Profiles\4ssaso2q.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2009/12/28 04:02:59 | 000,000,000 | ---D | M] -- C:\Users\kaput\AppData\Roaming\Mozilla\Firefox\Profiles\4ssaso2q.default\extensions\npfax@microgaming.co.uk
[2010/04/16 19:45:56 | 000,000,000 | ---D | M] -- C:\Users\kaput\AppData\Roaming\Mozilla\Firefox\Profiles\4ssaso2q.default\extensions\toolbar@ask.com
[2009/10/22 01:03:09 | 000,004,554 | ---- | M] () -- C:\Users\kaput\AppData\Roaming\Mozilla\Firefox\Profiles\4ssaso2q.default\searchplugins\aim-search.xml
[2010/01/12 23:33:34 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [OWCWebCamDV] C:\Windows\system\wcdvtray.exe (OrangeWare, Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [aarhegmy] C:\Users\kaput\AppData\Local\rwhrqoroo\dqalpkwtssd.exe File not found
O4 - HKCU..\Run: [abpuahhe] C:\Users\kaput\AppData\Local\oepxokxil\dpabiurtssd.exe File not found
O4 - HKCU..\Run: [aehfalni] C:\Users\kaput\AppData\Local\rkgqqagaj\dgamcsxtssd.exe File not found
O4 - HKCU..\Run: [agfsvmin] C:\Users\kaput\AppData\Local\prowovmth\dfadtdstssd.exe File not found
O4 - HKCU..\Run: [ajxcvqor] C:\Users\kaput\AppData\Local\ryepqkumf\dwaoobatssd.exe File not found
O4 - HKCU..\Run: [annarvpa] C:\Users\kaput\AppData\Local\smcnrvjxa\dmyqajbtssd.exe File not found
O4 - HKCU..\Run: [asam] C:\Windows\asam.exe ()
O4 - HKCU..\Run: [axtuigrs] C:\Users\kaput\AppData\Local\tpylrsluq\dryuxadtssd.exe File not found
O4 - HKCU..\Run: [bcjrelsc] C:\Users\kaput\AppData\Local\tdxkseagm\dhywkietssd.exe File not found
O4 - HKCU..\Run: [bqfjrbve] C:\Users\kaput\AppData\Roaming\utsgtlrpx\ddydughtssd.exe ()
O4 - HKCU..\Run: [cgdflbqy] C:\Users\kaput\AppData\Local\etoupqops\dmsvubgtssd.exe File not found
O4 - HKCU..\Run: [ckygccgk] C:\Users\kaput\AppData\Local\aifiliacn\djtcfvutssd.exe ()
O4 - HKCU..\Run: [cmqpcgmn] C:\Users\kaput\AppData\Local\cpuanxiul\dbsoytbtssd.exe File not found
O4 - HKCU..\Run: [cpiaclsr] C:\Windows\drsasritssd.exe File not found
O4 - HKCU..\Run: [crhnxlnw] C:\Users\kaput\AppData\Local\ddsyojwgh\dqsqkcctssd.exe File not found
O4 - HKCU..\Run: [dhwcofcv] C:\Windows\derswnstssd.exe File not found
O4 - HKCU..\Run: [dlmykkdf] C:\Users\kaput\AppData\Local\jhtftvfao\dtrujvttssd.exe File not found
O4 - HKCU..\Run: [dnkmgkxl] C:\Users\kaput\AppData\Local\hocmrrltm\dsskbhotssd.exe File not found
O4 - HKCU..\Run: [dyoutuuj] C:\Windows\dwseqiktssd.exe File not found
O4 - HKCU..\Run: [eaqxagmd] C:\Users\kaput\AppData\Local\niiilhybj\dkmrhdftssd.exe File not found
O4 - HKCU..\Run: [efguvlom] C:\Users\kaput\AppData\Local\ovghlrnme\damttlgtssd.exe File not found
O4 - HKCU..\Run: [eixfvpup] C:\Users\kaput\AppData\Local\qdwanhvfc\drmfnjntssd.exe File not found
O4 - HKCU..\Run: [fbkuekyb] C:\Users\kaput\AppData\Local\shpupacak\ddlnjqstssd.exe File not found
O4 - HKCU..\Run: [fceqiokx] C:\Windows\dukkmdftssd.exe File not found
O4 - HKCU..\Run: [fhtoetlh] C:\Users\kaput\AppData\Roaming\xuvftfskg\dkkmxlgtssd.exe ()
O4 - HKCU..\Run: [fjrcatgn] C:\Users\kaput\AppData\Local\vcelrbydd\djlcpwbtssd.exe File not found
O4 - HKCU..\Run: [fwtwifxr] C:\Users\kaput\AppData\Local\rsrvopnno\dmllxirtssd.exe File not found
O4 - HKCU..\Run: [fxntmjjo] C:\Users\kaput\AppData\Roaming\wsyhsipmp\dfkiauetssd.exe ()
O4 - HKCU..\Run: [hdfuoycr] C:\Users\kaput\AppData\Local\fqxynrjot\difwdyatssd.exe File not found
O4 - HKCU..\Run: [hivrkedb] C:\Users\kaput\AppData\Local\fevxocxbo\dxfyohbtssd.exe File not found
O4 - HKCU..\Run: [hrbmcoft] C:\Users\kaput\AppData\Local\ggsupybxf\ddedmxdtssd.exe File not found
O4 - HKCU..\Run: [hyjtwxmg] C:\Users\kaput\AppData\Local\jbhmraxcy\dkerseltssd.exe File not found
O4 - HKCU..\Run: [iqfcmych] C:\Users\kaput\AppData\Local\qjlhlbauq\drxalietssd.exe File not found
O4 - HKCU..\Run: [isujgsqq] C:\Users\kaput\AppData\Local\lgbhtsdwg\dveaokqtssd.exe File not found
O4 - HKCU..\Run: [jguqesqg] C:\Users\kaput\AppData\Roaming\wynpqcudd\dfwdxuutssd.exe ()
O4 - HKCU..\Run: [jiseasll] C:\Users\kaput\AppData\Local\ugvvoxavb\dexspfotssd.exe File not found
O4 - HKCU..\Run: [jkkoyxrp] C:\Users\kaput\AppData\Local\wmmormioy\duwfjdvtssd.exe File not found
O4 - HKCU..\Run: [jxmjiijt] C:\Users\kaput\AppData\Roaming\teayobxyk\dyxoromtssd.exe ()
O4 - HKCU..\Run: [kncxycxs] C:\Users\kaput\AppData\Local\atcgtcrgw\dmwqeadtssd.exe ()
O4 - HKCU..\Run: [kuqjqhth] C:\Users\kaput\AppData\Local\xojlrjllp\dbwjitxtssd.exe File not found
O4 - HKCU..\Run: [kyggmmuq] C:\Users\kaput\AppData\Local\ydhksuaxk\dqwktcytssd.exe File not found
O4 - HKCU..\Run: [ldatscsn] C:\Users\kaput\AppData\Roaming\jtxvphngr\duqkeubtssd.exe ()
O4 - HKCU..\Run: [loecgmpm] C:\Users\kaput\AppData\Local\hddynawwf\daqeuvxtssd.exe File not found
O4 - HKCU..\Run: [lqcpcnkr] C:\Users\kaput\AppData\Local\fklfmvcqd\dxqtmgrtssd.exe File not found
O4 - HKCU..\Run: [lxkwwwre] C:\Users\kaput\AppData\Local\ifawovyuv\dfqismatssd.exe File not found
O4 - HKCU..\Run: [metqwgfl] C:\Windows\dmpghhntssd.exe File not found
O4 - HKCU..\Run: [mgreshyq] C:\Users\kaput\AppData\Local\lannrwwyp\dlpvysitssd.exe File not found
O4 - HKCU..\Run: [mijnslgu] C:\Users\kaput\AppData\Local\ohegtmfqn\ddpispptssd.exe File not found
O4 - HKCU..\Run: [mpxxkrbj] C:\Users\kaput\AppData\Roaming\mcklstyvg\drpawjktssd.exe ()
O4 - HKCU..\Run: [mtnvfvcs] C:\Users\kaput\AppData\Local\mqjjsenhb\dhpcirltssd.exe File not found
O4 - HKCU..\Run: [mvljbwwy] C:\Users\kaput\AppData\Local\kxrqqatby\dgqsbcgtssd.exe File not found
O4 - HKCU..\Run: [nfutdrwf] C:\Users\kaput\AppData\Local\vcganxvvb\dajtwditssd.exe File not found
O4 - HKCU..\Run: [oeqdlunv] C:\Windows\dtiaifbtssd.exe File not found
O4 - HKCU..\Run: [ohnedvdi] C:\Users\kaput\AppData\Local\xjvrpneny\drjfrbptssd.exe File not found
O4 - HKCU..\Run: [omdbyber] C:\Users\kaput\AppData\Local\ywuqqysyu\dhjhdjqtssd.exe File not found
O4 - HKCU..\Run: [orsxugfa] C:\Users\kaput\AppData\Local\ylspqkhlp\dwjjprrtssd.exe File not found
O4 - HKCU..\Run: [osrlqgag] C:\Users\kaput\AppData\Local\wsbvognen\dvjahcmtssd.exe File not found
O4 - HKCU..\Run: [otliukle] C:\Users\kaput\AppData\Local\crjisapdn\dnivjoytssd.exe File not found
O4 - HKCU..\Run: [qacjwbeg] C:\Users\kaput\AppData\Local\jphynijfr\dqclmsutssd.exe File not found
O4 - HKCU..\Run: [qmannpmc] C:\Users\kaput\AppData\Local\nyuoqtuug\dncbehetssd.exe File not found
O4 - HKCU..\Run: [qoybjphi] C:\Users\kaput\AppData\Local\lgdvppboe\dmcqwrytssd.exe File not found
O4 - HKCU..\Run: [qrqljunl] C:\Users\kaput\AppData\Local\nnsnrfjhc\ddcdqpftssd.exe File not found
O4 - HKCU..\Run: [qxevbajb] C:\Users\kaput\AppData\Local\miyspmdmu\drcuuibtssd.exe File not found
O4 - HKCU..\Run: [QZAIB7KITK] C:\Windows\Hnudoa.exe File not found
O4 - HKCU..\Run: [rpsxntsf] C:\Users\kaput\AppData\Local\qfkhtjdne\debnyeltssd.exe File not found
O4 - HKCU..\Run: [rtiujyto] C:\Users\kaput\AppData\Local\qtjgturya\dtbpkmmtssd.exe File not found
O4 - HKCU..\Run: [saavlpmr] C:\Users\kaput\AppData\Local\yrhxodlbe\dxuenqitssd.exe File not found
O4 - HKCU..\Run: [sepshtnb] C:\Users\kaput\AppData\Local\yggvooany\dnugyyjtssd.exe File not found
O4 - HKCU..\Run: [sjgqdyok] C:\Users\kaput\AppData\Local\ateupaoyu\dduilhltssd.exe ()
O4 - HKCU..\Run: [ssllujqc] C:\Users\kaput\AppData\Local\avbspvrvl\diumjxntssd.exe File not found
O4 - HKCU..\Run: [sujxqkli] C:\Users\kaput\AppData\Local\xdjyorwpi\dhvcbihtssd.exe File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [sxciporl] C:\Users\kaput\AppData\Roaming\bkyqqhfig\dyuovgotssd.exe ()
O4 - HKCU..\Run: [tbtsptxo] C:\Users\kaput\AppData\Local\dqpjswoae\dpubpevtssd.exe File not found
O4 - HKCU..\Run: [tkamheah] C:\Users\kaput\AppData\Roaming\esmgtsqwu\dutfntxtssd.exe ()
O4 - HKCU..\Run: [tmxadeun] C:\Users\kaput\AppData\Local\cbunrpwqs\dtuuffrtssd.exe File not found
O4 - HKCU..\Run: [tppkdibq] C:\Users\kaput\AppData\Local\fhkftefjq\dkthacytssd.exe File not found
O4 - HKCU..\Run: [tqnxyjvw] C:\Users\kaput\AppData\Local\doslraldn\djuwrnstssd.exe ()
O4 - HKCU..\Run: [uawibeud] C:\Users\kaput\AppData\Local\nthvoxnwp\deoxoovtssd.exe File not found
O4 - HKCU..\Run: [uenfviwl] C:\Users\kaput\AppData\Local\nhgupjcil\dtnaawwtssd.exe File not found
O4 - HKCU..\Run: [ulbqnorb] C:\Users\kaput\AppData\Local\mdmynqwne\diorepstssd.exe File not found
O4 - HKCU..\Run: [upqnjtsk] C:\Users\kaput\AppData\Local\mqlxockay\dxotqxttssd.exe File not found
O4 - HKCU..\Run: [uuhlfytt] C:\Users\kaput\AppData\Local\nfjwonylu\doovcgutssd.exe File not found
O4 - HKCU..\Run: [vbqfeiha] C:\Windows\dvntqbjtssd.exe File not found
O4 - HKCU..\Run: [vjddrnxu] C:\Users\kaput\AppData\Local\ovespuqug\djncmfytssd.exe File not found
O4 - HKCU..\Run: [vmumrsex] C:\Users\kaput\AppData\Roaming\qculrkymf\danogdftssd.exe ()
O4 - HKCU..\Run: [vosansye] C:\Users\kaput\AppData\Local\ojdrqgfgc\dynexnatssd.exe File not found
O4 - HKCU..\Run: [vxyufdbw] C:\Users\kaput\AppData\Local\plypqchds\dfnivectssd.exe File not found
O4 - HKCU..\Run: [wbsilsyt] C:\Users\kaput\AppData\Roaming\acpanpvma\djhhhwetssd.exe ()
O4 - HKCU..\Run: [wybylnsq] C:\Users\kaput\AppData\Local\wvailantc\dshumywtssd.exe File not found
O4 - HKCU..\Run: [xcmfpwkq] C:\Users\kaput\AppData\Local\fcxmrixla\dbgdjkqtssd.exe File not found
O4 - HKCU..\Run: [xmraghmj] C:\Users\kaput\AppData\Roaming\geujsfbiq\dhghhbstssd.exe ()
O4 - HKCU..\Run: [xnqnchhp] C:\Users\kaput\AppData\Local\eldpqbhco\dggxylntssd.exe ()
O4 - HKCU..\Run: [xpoaxicu] C:\Users\kaput\AppData\Local\bslvowmvl\dfhnqvhtssd.exe File not found
O4 - HKCU..\Run: [xvxtxroc] C:\Users\kaput\AppData\Local\hgqhtcegh\dmglfqvtssd.exe File not found
O4 - HKCU..\Run: [xxvhtrjh] C:\Users\kaput\AppData\Local\enynrxjyf\dlgcwcptssd.exe File not found
O4 - HKCU..\Run: [yorqjsyi] C:\Users\kaput\AppData\Local\ludilymsw\dsbkpgitssd.exe File not found
O4 - Startup: C:\Users\kaput\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} [You must be registered and logged in to see this link.] (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} [You must be registered and logged in to see this link.] (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_05)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 74.214.52.68 65.175.128.47
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007/08/10 13:00:00 | 000,000,030 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{8bb9f727-38f4-11df-a0db-0025111d97a1}\Shell - "" = AutoRun
O33 - MountPoints2\{8bb9f727-38f4-11df-a0db-0025111d97a1}\Shell\AutoRun\command - "" = J:\autorun.exe -- File not found
O33 - MountPoints2\{99c58b78-3491-11de-930e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{99c58b78-3491-11de-930e-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Start.exe -- [2007/08/10 13:00:00 | 000,923,032 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 18th April 2010, 10:22 pm

not it's not letting me post the rest of log

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 18th April 2010, 10:30 pm

Hello.
Please attach the log then. Click the "Post Reply" button, and under the text box, there is the attachment management, select the log file and hit the Submit button.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 18th April 2010, 10:36 pm

it's not allowing me to attach either... saying invalid file.... OTL.txt

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 18th April 2010, 10:39 pm

Ok i had to copy and paste into a new txt file and used a diff name.. works now...

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 18th April 2010, 10:40 pm

extras file

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 18th April 2010, 10:47 pm

Please run OTL.exe.

  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :OTL
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKCU..\Run: [aarhegmy] C:\Users\kaput\AppData\Local\rwhrqoroo\dqalpkwtssd.exe File not found
    O4 - HKCU..\Run: [abpuahhe] C:\Users\kaput\AppData\Local\oepxokxil\dpabiurtssd.exe File not found
    O4 - HKCU..\Run: [aehfalni] C:\Users\kaput\AppData\Local\rkgqqagaj\dgamcsxtssd.exe File not found
    O4 - HKCU..\Run: [agfsvmin] C:\Users\kaput\AppData\Local\prowovmth\dfadtdstssd.exe File not found
    O4 - HKCU..\Run: [ajxcvqor] C:\Users\kaput\AppData\Local\ryepqkumf\dwaoobatssd.exe File not found
    O4 - HKCU..\Run: [annarvpa] C:\Users\kaput\AppData\Local\smcnrvjxa\dmyqajbtssd.exe File not found
    O4 - HKCU..\Run: [asam] C:\Windows\asam.exe ()
    O4 - HKCU..\Run: [axtuigrs] C:\Users\kaput\AppData\Local\tpylrsluq\dryuxadtssd.exe File not found
    O4 - HKCU..\Run: [bcjrelsc] C:\Users\kaput\AppData\Local\tdxkseagm\dhywkietssd.exe File not found
    O4 - HKCU..\Run: [bqfjrbve] C:\Users\kaput\AppData\Roaming\utsgtlrpx\ddydughtssd.exe ()
    O4 - HKCU..\Run: [cgdflbqy] C:\Users\kaput\AppData\Local\etoupqops\dmsvubgtssd.exe File not found
    O4 - HKCU..\Run: [ckygccgk] C:\Users\kaput\AppData\Local\aifiliacn\djtcfvutssd.exe ()
    O4 - HKCU..\Run: [cmqpcgmn] C:\Users\kaput\AppData\Local\cpuanxiul\dbsoytbtssd.exe File not found
    O4 - HKCU..\Run: [cpiaclsr] C:\Windows\drsasritssd.exe File not found
    O4 - HKCU..\Run: [crhnxlnw] C:\Users\kaput\AppData\Local\ddsyojwgh\dqsqkcctssd.exe File not found
    O4 - HKCU..\Run: [dhwcofcv] C:\Windows\derswnstssd.exe File not found
    O4 - HKCU..\Run: [dlmykkdf] C:\Users\kaput\AppData\Local\jhtftvfao\dtrujvttssd.exe File not found
    O4 - HKCU..\Run: [dnkmgkxl] C:\Users\kaput\AppData\Local\hocmrrltm\dsskbhotssd.exe File not found
    O4 - HKCU..\Run: [dyoutuuj] C:\Windows\dwseqiktssd.exe File not found
    O4 - HKCU..\Run: [eaqxagmd] C:\Users\kaput\AppData\Local\niiilhybj\dkmrhdftssd.exe File not found
    O4 - HKCU..\Run: [efguvlom] C:\Users\kaput\AppData\Local\ovghlrnme\damttlgtssd.exe File not found
    O4 - HKCU..\Run: [eixfvpup] C:\Users\kaput\AppData\Local\qdwanhvfc\drmfnjntssd.exe File not found
    O4 - HKCU..\Run: [fbkuekyb] C:\Users\kaput\AppData\Local\shpupacak\ddlnjqstssd.exe File not found
    O4 - HKCU..\Run: [fceqiokx] C:\Windows\dukkmdftssd.exe File not found
    O4 - HKCU..\Run: [fhtoetlh] C:\Users\kaput\AppData\Roaming\xuvftfskg\dkkmxlgtssd.exe ()
    O4 - HKCU..\Run: [fjrcatgn] C:\Users\kaput\AppData\Local\vcelrbydd\djlcpwbtssd.exe File not found
    O4 - HKCU..\Run: [fwtwifxr] C:\Users\kaput\AppData\Local\rsrvopnno\dmllxirtssd.exe File not found
    O4 - HKCU..\Run: [fxntmjjo] C:\Users\kaput\AppData\Roaming\wsyhsipmp\dfkiauetssd.exe ()
    O4 - HKCU..\Run: [hdfuoycr] C:\Users\kaput\AppData\Local\fqxynrjot\difwdyatssd.exe File not found
    O4 - HKCU..\Run: [hivrkedb] C:\Users\kaput\AppData\Local\fevxocxbo\dxfyohbtssd.exe File not found
    O4 - HKCU..\Run: [hrbmcoft] C:\Users\kaput\AppData\Local\ggsupybxf\ddedmxdtssd.exe File not found
    O4 - HKCU..\Run: [hyjtwxmg] C:\Users\kaput\AppData\Local\jbhmraxcy\dkerseltssd.exe File not found
    O4 - HKCU..\Run: [iqfcmych] C:\Users\kaput\AppData\Local\qjlhlbauq\drxalietssd.exe File not found
    O4 - HKCU..\Run: [isujgsqq] C:\Users\kaput\AppData\Local\lgbhtsdwg\dveaokqtssd.exe File not found
    O4 - HKCU..\Run: [jguqesqg] C:\Users\kaput\AppData\Roaming\wynpqcudd\dfwdxuutssd.exe ()
    O4 - HKCU..\Run: [jiseasll] C:\Users\kaput\AppData\Local\ugvvoxavb\dexspfotssd.exe File not found
    O4 - HKCU..\Run: [jkkoyxrp] C:\Users\kaput\AppData\Local\wmmormioy\duwfjdvtssd.exe File not found
    O4 - HKCU..\Run: [jxmjiijt] C:\Users\kaput\AppData\Roaming\teayobxyk\dyxoromtssd.exe ()
    O4 - HKCU..\Run: [kncxycxs] C:\Users\kaput\AppData\Local\atcgtcrgw\dmwqeadtssd.exe ()
    O4 - HKCU..\Run: [kuqjqhth] C:\Users\kaput\AppData\Local\xojlrjllp\dbwjitxtssd.exe File not found
    O4 - HKCU..\Run: [kyggmmuq] C:\Users\kaput\AppData\Local\ydhksuaxk\dqwktcytssd.exe File not found
    O4 - HKCU..\Run: [ldatscsn] C:\Users\kaput\AppData\Roaming\jtxvphngr\duqkeubtssd.exe ()
    O4 - HKCU..\Run: [loecgmpm] C:\Users\kaput\AppData\Local\hddynawwf\daqeuvxtssd.exe File not found
    O4 - HKCU..\Run: [lqcpcnkr] C:\Users\kaput\AppData\Local\fklfmvcqd\dxqtmgrtssd.exe File not found
    O4 - HKCU..\Run: [lxkwwwre] C:\Users\kaput\AppData\Local\ifawovyuv\dfqismatssd.exe File not found
    O4 - HKCU..\Run: [metqwgfl] C:\Windows\dmpghhntssd.exe File not found
    O4 - HKCU..\Run: [mgreshyq] C:\Users\kaput\AppData\Local\lannrwwyp\dlpvysitssd.exe File not found
    O4 - HKCU..\Run: [mijnslgu] C:\Users\kaput\AppData\Local\ohegtmfqn\ddpispptssd.exe File not found
    O4 - HKCU..\Run: [mpxxkrbj] C:\Users\kaput\AppData\Roaming\mcklstyvg\drpawjktssd.exe ()
    O4 - HKCU..\Run: [mtnvfvcs] C:\Users\kaput\AppData\Local\mqjjsenhb\dhpcirltssd.exe File not found
    O4 - HKCU..\Run: [mvljbwwy] C:\Users\kaput\AppData\Local\kxrqqatby\dgqsbcgtssd.exe File not found
    O4 - HKCU..\Run: [nfutdrwf] C:\Users\kaput\AppData\Local\vcganxvvb\dajtwditssd.exe File not found
    O4 - HKCU..\Run: [oeqdlunv] C:\Windows\dtiaifbtssd.exe File not found
    O4 - HKCU..\Run: [ohnedvdi] C:\Users\kaput\AppData\Local\xjvrpneny\drjfrbptssd.exe File not found
    O4 - HKCU..\Run: [omdbyber] C:\Users\kaput\AppData\Local\ywuqqysyu\dhjhdjqtssd.exe File not found
    O4 - HKCU..\Run: [orsxugfa] C:\Users\kaput\AppData\Local\ylspqkhlp\dwjjprrtssd.exe File not found
    O4 - HKCU..\Run: [osrlqgag] C:\Users\kaput\AppData\Local\wsbvognen\dvjahcmtssd.exe File not found
    O4 - HKCU..\Run: [otliukle] C:\Users\kaput\AppData\Local\crjisapdn\dnivjoytssd.exe File not found
    O4 - HKCU..\Run: [qacjwbeg] C:\Users\kaput\AppData\Local\jphynijfr\dqclmsutssd.exe File not found
    O4 - HKCU..\Run: [qmannpmc] C:\Users\kaput\AppData\Local\nyuoqtuug\dncbehetssd.exe File not found
    O4 - HKCU..\Run: [qoybjphi] C:\Users\kaput\AppData\Local\lgdvppboe\dmcqwrytssd.exe File not found
    O4 - HKCU..\Run: [qrqljunl] C:\Users\kaput\AppData\Local\nnsnrfjhc\ddcdqpftssd.exe File not found
    O4 - HKCU..\Run: [qxevbajb] C:\Users\kaput\AppData\Local\miyspmdmu\drcuuibtssd.exe File not found
    O4 - HKCU..\Run: [QZAIB7KITK] C:\Windows\Hnudoa.exe File not found
    O4 - HKCU..\Run: [rpsxntsf] C:\Users\kaput\AppData\Local\qfkhtjdne\debnyeltssd.exe File not found
    O4 - HKCU..\Run: [rtiujyto] C:\Users\kaput\AppData\Local\qtjgturya\dtbpkmmtssd.exe File not found
    O4 - HKCU..\Run: [saavlpmr] C:\Users\kaput\AppData\Local\yrhxodlbe\dxuenqitssd.exe File not found
    O4 - HKCU..\Run: [sepshtnb] C:\Users\kaput\AppData\Local\yggvooany\dnugyyjtssd.exe File not found
    O4 - HKCU..\Run: [sjgqdyok] C:\Users\kaput\AppData\Local\ateupaoyu\dduilhltssd.exe ()
    O4 - HKCU..\Run: [ssllujqc] C:\Users\kaput\AppData\Local\avbspvrvl\diumjxntssd.exe File not found
    O4 - HKCU..\Run: [sujxqkli] C:\Users\kaput\AppData\Local\xdjyorwpi\dhvcbihtssd.exe File not found
    O4 - HKCU..\Run: [sxciporl] C:\Users\kaput\AppData\Roaming\bkyqqhfig\dyuovgotssd.exe ()
    O4 - HKCU..\Run: [tbtsptxo] C:\Users\kaput\AppData\Local\dqpjswoae\dpubpevtssd.exe File not found
    O4 - HKCU..\Run: [tkamheah] C:\Users\kaput\AppData\Roaming\esmgtsqwu\dutfntxtssd.exe ()
    O4 - HKCU..\Run: [tmxadeun] C:\Users\kaput\AppData\Local\cbunrpwqs\dtuuffrtssd.exe File not found
    O4 - HKCU..\Run: [tppkdibq] C:\Users\kaput\AppData\Local\fhkftefjq\dkthacytssd.exe File not found
    O4 - HKCU..\Run: [tqnxyjvw] C:\Users\kaput\AppData\Local\doslraldn\djuwrnstssd.exe ()
    O4 - HKCU..\Run: [uawibeud] C:\Users\kaput\AppData\Local\nthvoxnwp\deoxoovtssd.exe File not found
    O4 - HKCU..\Run: [uenfviwl] C:\Users\kaput\AppData\Local\nhgupjcil\dtnaawwtssd.exe File not found
    O4 - HKCU..\Run: [ulbqnorb] C:\Users\kaput\AppData\Local\mdmynqwne\diorepstssd.exe File not found
    O4 - HKCU..\Run: [upqnjtsk] C:\Users\kaput\AppData\Local\mqlxockay\dxotqxttssd.exe File not found
    O4 - HKCU..\Run: [uuhlfytt] C:\Users\kaput\AppData\Local\nfjwonylu\doovcgutssd.exe File not found
    O4 - HKCU..\Run: [vbqfeiha] C:\Windows\dvntqbjtssd.exe File not found
    O4 - HKCU..\Run: [vjddrnxu] C:\Users\kaput\AppData\Local\ovespuqug\djncmfytssd.exe File not found
    O4 - HKCU..\Run: [vmumrsex] C:\Users\kaput\AppData\Roaming\qculrkymf\danogdftssd.exe ()
    O4 - HKCU..\Run: [vosansye] C:\Users\kaput\AppData\Local\ojdrqgfgc\dynexnatssd.exe File not found
    O4 - HKCU..\Run: [vxyufdbw] C:\Users\kaput\AppData\Local\plypqchds\dfnivectssd.exe File not found
    O4 - HKCU..\Run: [wbsilsyt] C:\Users\kaput\AppData\Roaming\acpanpvma\djhhhwetssd.exe ()
    O4 - HKCU..\Run: [wybylnsq] C:\Users\kaput\AppData\Local\wvailantc\dshumywtssd.exe File not found
    O4 - HKCU..\Run: [xcmfpwkq] C:\Users\kaput\AppData\Local\fcxmrixla\dbgdjkqtssd.exe File not found
    O4 - HKCU..\Run: [xmraghmj] C:\Users\kaput\AppData\Roaming\geujsfbiq\dhghhbstssd.exe ()
    O4 - HKCU..\Run: [xnqnchhp] C:\Users\kaput\AppData\Local\eldpqbhco\dggxylntssd.exe ()
    O4 - HKCU..\Run: [xpoaxicu] C:\Users\kaput\AppData\Local\bslvowmvl\dfhnqvhtssd.exe File not found
    O4 - HKCU..\Run: [xvxtxroc] C:\Users\kaput\AppData\Local\hgqhtcegh\dmglfqvtssd.exe File not found
    O4 - HKCU..\Run: [xxvhtrjh] C:\Users\kaput\AppData\Local\enynrxjyf\dlgcwcptssd.exe File not found
    O4 - HKCU..\Run: [yorqjsyi] C:\Users\kaput\AppData\Local\ludilymsw\dsbkpgitssd.exe File not found
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
    [2010/04/16 20:55:28 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\xuvftfskg
    [2010/04/16 20:55:27 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\esmgtsqwu
    [2010/04/16 20:55:25 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Local\atcgtcrgw
    [2010/04/16 20:55:23 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\wsyhsipmp
    [2010/04/16 20:55:22 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\jsvhtkqot
    [2010/04/16 20:55:21 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\xgxgttexk
    [2010/04/16 20:55:21 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\dufftvsbe
    [2010/04/16 20:55:15 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\utsgtlrpx
    [2010/04/16 20:55:14 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\ssphtrqvq
    [2010/04/16 20:55:04 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\nsfhtbqfr
    [2010/04/16 20:54:48 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\qculrkymf
    [2010/04/16 20:54:48 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Local\doslraldn
    [2010/04/16 20:54:47 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\mcklstyvg
    [2010/04/16 20:54:45 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\geujsfbiq
    [2010/04/16 20:54:44 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Local\dqpjswoae
    [2010/04/16 20:54:44 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\acpanpvma
    [2010/04/16 20:54:43 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\teayobxyk
    [2010/04/16 20:54:43 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\bkyqqhfig
    [2010/04/16 20:54:33 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\wynpqcudd
    [2010/04/16 20:54:27 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\fvkspnqmj
    [2010/04/16 20:54:25 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Local\eldpqbhco
    [2010/04/16 20:54:21 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\jtxvphngr
    [2010/04/16 20:54:18 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\gxhpqjtka
    [2010/04/16 20:54:05 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Local\ateupaoyu
    [2010/04/16 20:53:47 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Local\acpanpvma
    [2010/04/16 20:51:34 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Local\aifiliacn
    [2010/04/16 19:54:32 | 000,000,000 | -HSD | C] -- C:\Users\kaput\AppData\Roaming\lowsec
    [2010/04/16 19:53:20 | 000,000,000 | ---D | C] -- C:\Users\kaput\AppData\Roaming\6DD147B2FE126139103F76DE0EE65DCE
    [2010/04/18 01:16:11 | 000,060,672 | ---- | C] () -- C:\Windows\asam.exe
    [2010/04/18 01:15:10 | 000,060,672 | ---- | C] () -- C:\Users\kaput\AppData\Local\syssvc.exe


  • Return to OTL, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.

  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 18th April 2010, 10:49 pm

========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\aarhegmy deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\abpuahhe deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\aehfalni deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\agfsvmin deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ajxcvqor deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\annarvpa deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\asam deleted successfully.
C:\Windows\asam.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\axtuigrs deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bcjrelsc deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bqfjrbve deleted successfully.
C:\Users\kaput\AppData\Roaming\utsgtlrpx\ddydughtssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\cgdflbqy deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ckygccgk deleted successfully.
C:\Users\kaput\AppData\Local\aifiliacn\djtcfvutssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\cmqpcgmn deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\cpiaclsr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\crhnxlnw deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\dhwcofcv deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\dlmykkdf deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\dnkmgkxl deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\dyoutuuj deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\eaqxagmd deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\efguvlom deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\eixfvpup deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fbkuekyb deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fceqiokx deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fhtoetlh deleted successfully.
C:\Users\kaput\AppData\Roaming\xuvftfskg\dkkmxlgtssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fjrcatgn deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fwtwifxr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fxntmjjo deleted successfully.
C:\Users\kaput\AppData\Roaming\wsyhsipmp\dfkiauetssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hdfuoycr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hivrkedb deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hrbmcoft deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hyjtwxmg deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\iqfcmych deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\isujgsqq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jguqesqg deleted successfully.
C:\Users\kaput\AppData\Roaming\wynpqcudd\dfwdxuutssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jiseasll deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jkkoyxrp deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jxmjiijt deleted successfully.
C:\Users\kaput\AppData\Roaming\teayobxyk\dyxoromtssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\kncxycxs deleted successfully.
C:\Users\kaput\AppData\Local\atcgtcrgw\dmwqeadtssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\kuqjqhth deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\kyggmmuq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ldatscsn deleted successfully.
C:\Users\kaput\AppData\Roaming\jtxvphngr\duqkeubtssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\loecgmpm deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\lqcpcnkr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\lxkwwwre deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\metqwgfl deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mgreshyq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mijnslgu deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mpxxkrbj deleted successfully.
C:\Users\kaput\AppData\Roaming\mcklstyvg\drpawjktssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mtnvfvcs deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mvljbwwy deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\nfutdrwf deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\oeqdlunv deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ohnedvdi deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\omdbyber deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\orsxugfa deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\osrlqgag deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\otliukle deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qacjwbeg deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qmannpmc deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qoybjphi deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qrqljunl deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qxevbajb deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\QZAIB7KITK deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rpsxntsf deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rtiujyto deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\saavlpmr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sepshtnb deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sjgqdyok deleted successfully.
C:\Users\kaput\AppData\Local\ateupaoyu\dduilhltssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ssllujqc deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sujxqkli deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sxciporl deleted successfully.
C:\Users\kaput\AppData\Roaming\bkyqqhfig\dyuovgotssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tbtsptxo deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tkamheah deleted successfully.
C:\Users\kaput\AppData\Roaming\esmgtsqwu\dutfntxtssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tmxadeun deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tppkdibq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tqnxyjvw deleted successfully.
C:\Users\kaput\AppData\Local\doslraldn\djuwrnstssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uawibeud deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uenfviwl deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ulbqnorb deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\upqnjtsk deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uuhlfytt deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vbqfeiha deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vjddrnxu deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vmumrsex deleted successfully.
C:\Users\kaput\AppData\Roaming\qculrkymf\danogdftssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vosansye deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vxyufdbw deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wbsilsyt deleted successfully.
C:\Users\kaput\AppData\Roaming\acpanpvma\djhhhwetssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wybylnsq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xcmfpwkq deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xmraghmj deleted successfully.
C:\Users\kaput\AppData\Roaming\geujsfbiq\dhghhbstssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xnqnchhp deleted successfully.
C:\Users\kaput\AppData\Local\eldpqbhco\dggxylntssd.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xpoaxicu deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xvxtxroc deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xxvhtrjh deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\yorqjsyi deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
C:\Users\kaput\AppData\Roaming\xuvftfskg folder moved successfully.
C:\Users\kaput\AppData\Roaming\esmgtsqwu folder moved successfully.
C:\Users\kaput\AppData\Local\atcgtcrgw folder moved successfully.
C:\Users\kaput\AppData\Roaming\wsyhsipmp folder moved successfully.
C:\Users\kaput\AppData\Roaming\jsvhtkqot folder moved successfully.
C:\Users\kaput\AppData\Roaming\xgxgttexk folder moved successfully.
C:\Users\kaput\AppData\Roaming\dufftvsbe folder moved successfully.
C:\Users\kaput\AppData\Roaming\utsgtlrpx folder moved successfully.
C:\Users\kaput\AppData\Roaming\ssphtrqvq folder moved successfully.
C:\Users\kaput\AppData\Roaming\nsfhtbqfr folder moved successfully.
C:\Users\kaput\AppData\Roaming\qculrkymf folder moved successfully.
C:\Users\kaput\AppData\Local\doslraldn folder moved successfully.
C:\Users\kaput\AppData\Roaming\mcklstyvg folder moved successfully.
C:\Users\kaput\AppData\Roaming\geujsfbiq folder moved successfully.
C:\Users\kaput\AppData\Local\dqpjswoae folder moved successfully.
C:\Users\kaput\AppData\Roaming\acpanpvma folder moved successfully.
C:\Users\kaput\AppData\Roaming\teayobxyk folder moved successfully.
C:\Users\kaput\AppData\Roaming\bkyqqhfig folder moved successfully.
C:\Users\kaput\AppData\Roaming\wynpqcudd folder moved successfully.
C:\Users\kaput\AppData\Roaming\fvkspnqmj folder moved successfully.
C:\Users\kaput\AppData\Local\eldpqbhco folder moved successfully.
C:\Users\kaput\AppData\Roaming\jtxvphngr folder moved successfully.
C:\Users\kaput\AppData\Roaming\gxhpqjtka folder moved successfully.
C:\Users\kaput\AppData\Local\ateupaoyu folder moved successfully.
C:\Users\kaput\AppData\Local\acpanpvma folder moved successfully.
C:\Users\kaput\AppData\Local\aifiliacn folder moved successfully.
C:\Users\kaput\AppData\Roaming\lowsec folder moved successfully.
C:\Users\kaput\AppData\Roaming\6DD147B2FE126139103F76DE0EE65DCE folder moved successfully.
File C:\Windows\asam.exe not found.
C:\Users\kaput\AppData\Local\syssvc.exe moved successfully.

OTL by OldTimer - Version 3.2.1.2 log created on 04182010_184915

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 18th April 2010, 11:01 pm

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 12:28 am

Malwarebytes' Anti-Malware 1.45
[You must be registered and logged in to see this link.]

Database version: 4005

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

4/18/2010 8:27:50 PM
mbam-log-2010-04-18 (20-27-50).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Objects scanned: 253790
Time elapsed: 1 hour(s), 18 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QZAIB7KITK (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 19th April 2010, 9:31 am

Please download ComboFix by sUBs
[You must be registered and logged in to see this link.]

Please save the file to your Desktop, but rename it first:




Important information about ComboFix

Before the download:
  • Please copy and paste these instructions to Notepad and save to your Desktop, or print them - for easier access.
  • It is important to rename ComboFix before the download.
  • Please do not rename ComboFix to other names, but only the one indicated.

After the download:
  • Close any open browsers.
  • Very Important: Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". [You must be registered and logged in to see this link.] if you don't know how.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no Internet connection after running ComboFix, then restart your computer to restore back your connection.

Running ComboFix:
  • Double click on svchost.exe & follow the prompts.
  • It will attempt to install the Recovery Console:




  • When ComboFix finishes, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" in your next reply.


Troubleshooting ComboFix

Safe Mode:

If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there.

(To boot into Safe Mode, tap F8 after BIOS, and just before the Windows
logo appears. A list of options will appear, select "Safe Mode.")

Re-downloading:

If this doesn't work either, try the same method (above method), but try to download it again, except name
ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe.

Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 1:34 pm

Opppps somehow I got a wrong log file below... thought the combo fix would overwrite the existing log.txt file, i was wrong... i'll post the correct log.txt file in a few mins.

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 1:51 pm

Here's the correct log.txt file... sorry about that

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 19th April 2010, 2:46 pm

Hello.
Do you have Extras.txt that OTL made?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 2:48 pm

extras2.txt from the original scan at the beginning of this thread

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 19th April 2010, 2:54 pm

Hello.

I see that you are running BitTorrent.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.

  • Click Start >> Control Panel.
  • Under the Programs click Uninstall a Program
  • Highlight the following:

    Adobe Reader 9
    Ask Toolbar
    BitTorrent
    Java(TM) 6 Update 5

  • Click on the Uninstall/Change button at the top.

Next,

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:
    Code:

    KILLALL::

    File::
    c:\users\kaput\AppData\Local\urejesaz.dll

    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

    DDS::
    uInternet Settings,ProxyOverride = <local>
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
  4. Save this as CFscript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFscript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 3:27 pm

combofix.txt after the script run

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 19th April 2010, 3:31 pm

Thanks, this looks good now.

Run ESET Online Scan
Please do an online scan with [You must be registered and logged in to see this link.]. Please use Internet Explorer as it uses ActiveX.

  • Check (tick) this box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • When prompted to run ActiveX. click Yes.
  • You will be asked to install an ActiveX. Click Install.
  • Once installed, the scanner will be initialized.
  • After the scanner is initialized, click Start.
  • Check (tick) Remove found threats box.
  • Check (tick) Scan unwanted applications.
  • Click on Scan.
  • It will start scanning. Please be patient.
  • Once the scan is done, the log will be saved here: C:\Program Files\esetonlinescanner\log.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 5:04 pm

This is all that was in the log.txt file


ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 19th April 2010, 5:32 pm

Okay, how is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 5:37 pm

It's been running pretty good since last night... On the surface it doesn't seem that there is any viruses... but that last scan on ESET found like 27 errors/infections... So as long as it got rid of them I guess we're good Smile

Although, after the scan i click on remove infections (step 4) then it took me to a page to purchase or 30 day trial.. so not sure if it did remove them or not

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 19th April 2010, 6:12 pm

We need to make a new restore point.

To turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4. Click Yes when you receive the prompt to the turn off System Restore.

Now we need to make a new restore point.
To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by kaputski on 19th April 2010, 11:17 pm

restore point created

kaputski
Novice
Novice

Posts Posts : 18
Joined Joined : 2010-04-17
OS OS : Vista
Points Points : 24538
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus Soft -- In need of help

Post by Belahzur on 20th April 2010, 11:58 am

Okay,

Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to [You must be registered and logged in to see this link.] and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

[You must be registered and logged in to see this link.]
A tutorial on using Ad-Aware to remove spyware from your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using Spybot to remove spyware from your computer may be found [You must be registered and logged in to see this link.]. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

[You must be registered and logged in to see this link.]
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found [You must be registered and logged in to see this link.].

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
[You must be registered and logged in to see this link.]
I also recommand the following add-ons for Firefox, they will help keep you safe from malicious scripts or activeX exploits.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

To help you keep your software updated, please considering using this free software program that will check for program updates.
[You must be registered and logged in to see this link.]

5) Finally, consider maintaining a firewall. Some good free firewalls are [You must be registered and logged in to see this link.], or
[You must be registered and logged in to see this link.]
A tutorial on understanding and using firewalls may be found [You must be registered and logged in to see this link.].

Please also read Tony Klein's excellent article: [You must be registered and logged in to see this link.]

If you would take a moment to fill out our feedback form, we would appreciate it.
The link can be found [You must be registered and logged in to see this link.].

Hopefully this should take care of your problems! Good luck. Big Grin


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum