also @ TechSpot: Leaked next generation iPhone casing photos validate multiple rumors

TechSpot

[Inactive] IE stops working, Data Execution Preventer closes it

Discussion in 'Virus and Malware Removal' started by brothwpj79, Oct 31, 2010.

Thread Status:
Not open for further replies.
  1. brothwpj79 Newcomer, in training

    OTL log
    ******

    All processes killed
    ========== OTL ==========
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4E7BD74F-2B8D-469E-A6FB-F862B587B57D} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-A6FB-F862B587B57D}\ not found.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Mobile Partner deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08E730A4-FB02-45BD-A900-01E4AD8016F6}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08E730A4-FB02-45BD-A900-01E4AD8016F6}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\Windows\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
    C:\Users\Nicky\Documents\Wimbledon_0005.jpg~RF25972c.TMP deleted successfully.
    ADS C:\Users\Nicky\Documents\stuff_0022.avi:TOC.WMV deleted successfully.
    ADS C:\Users\Nicky\Documents\stuff_0018.avi:TOC.WMV deleted successfully.
    ADS C:\Users\Nicky\Documents\stuff_0017.avi:TOC.WMV deleted successfully.
    ADS C:\Users\Nicky\Documents\Kefalonia_0037.avi:TOC.WMV deleted successfully.
    ADS C:\Users\Nicky\Documents\Kefalonia_0017.avi:TOC.WMV deleted successfully.
    ADS C:\Users\Nicky\Documents\Kefalonia_0016.avi:TOC.WMV deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware\\DisableMonitoring deleted successfully.
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Nicky
    ->Temp folder emptied: 1017945 bytes
    ->Temporary Internet Files folder emptied: 103890972 bytes
    ->Java cache emptied: 440629 bytes
    ->Google Chrome cache emptied: 61003421 bytes
    ->Flash cache emptied: 9481 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 223 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 875296 bytes

    Total Files Cleaned = 159.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Nicky
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.17.2 log created on 11062010_080849

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  2. brothwpj79 Newcomer, in training

    Temporary File Cleaner - complete
  3. brothwpj79 Newcomer, in training

    ESET log
    ******


    C:\Qoobox\Quarantine\C\Users\Nicky\AppData\Roaming\bbxnz.exe.vir Win32/Fbphotofake.A worm
    C:\Qoobox\Quarantine\C\Users\Nicky\AppData\Roaming\xxkmc.exe.vir Win32/Agent.RST trojan
  4. brothwpj79 Newcomer, in training

    Unable to download Security Check (web page not available)
  5. Broni Malware Annihilator

    It's working for me. Try again.
  6. brothwpj79 Newcomer, in training

    Every time I download Security Check it gets removed as a Trojan by McAffee? I'm trying to get rid of Malware, not install more!
  7. Broni Malware Annihilator

    That' because McAfee is a very dumb program :)
    Disable it and try again.
  8. Broni Malware Annihilator

    Are you still out there?
  9. brothwpj79 Newcomer, in training

    Sorry, I had a busy week and lost momentum resolving this! I still can't download Security Check:

    This web page is not available.

    The web page at http://screen317.changelog.fr/SecurityCheck.exe might be temporarily down or it may have moved permanently to a new web address.

    More information on this error
    Below is the original error message

    Error 2 (net::ERR_FAILED): Unknown error.
  10. Broni Malware Annihilator

  11. brothwpj79 Newcomer, in training

    Hi Broni

    Sorry I haven't been very active on this thread, it's a very busy time of year.

    I wasn't able to obtain Security Check from your website, although I can't remember the exact problem as it was a couple of weeks ago now.

    However in those weeks my girlfriend has been able to use Internet Explorer without any problems, so whatever was causing the problem seems to have been wiped out.

    Should I still try and get hold of Security Check or is it safe to say the issue has been resolved?
  12. Broni Malware Annihilator

    Thanks for the update :)

    Cleaning process has to be finished, or some symptoms may return.
Thread Status:
Not open for further replies.