Bob Hobart
Posts: 81 +0
Trying again after removing some strange characters found in OTL.txt file
*** OTL.txt
All processes killed
========== OTL ==========
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
File %SystemRoot%\System32\appmgmts.dll not found.
Service WDICA stopped successfully!
Service WDICA deleted successfully!
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
Service Changer stopped successfully!
Service Changer deleted successfully!
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\BILLHE~1\LOCALS~1\Temp\catchme.sys not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\\\\{825e1174-a405-eeb0-f6ca-438f3ffa937f} folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\\\ folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\\ folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f} folder moved successfully.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ \\{825e1174-a405-eeb0-f6ca-438f3ffa937f} scheduled to be moved on reboot.
C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ \ folder moved successfully.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f} scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install\Install scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine scheduled to be moved on reboot.
C:\FRST\Logs folder moved successfully.
C:\FRST\Hives\Users\00000002 folder moved successfully.
C:\FRST\Hives\Users\00000001 folder moved successfully.
C:\FRST\Hives\Users folder moved successfully.
C:\FRST\Hives folder moved successfully.
C:\FRST folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Google Chrome cache emptied: 8629336 bytes
User: All Users
User: Bill Hebert
->Temp folder emptied: 4273173 bytes
->Temporary Internet Files folder emptied: 19530233 bytes
->Java cache emptied: 25277 bytes
->Google Chrome cache emptied: 72904501 bytes
->Flash cache emptied: 15761019 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Guest User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 9568390 bytes
->Flash cache emptied: 42072 bytes
User: NetworkService
->Temp folder emptied: 60835990 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2176856 bytes
%systemroot%\System32 .tmp files removed: 374671 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2585921 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 19225962 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 2569130 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 208.00 mb
[EMPTYJAVA]
User: Administrator
User: All Users
User: Bill Hebert
->Java cache emptied: 0 bytes
User: Default User
User: Guest User
->Java cache emptied: 0 bytes
User: LocalService
User: NetworkService
Total Java Files Cleaned = 0.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Bill Hebert
->Flash cache emptied: 0 bytes
User: Default User
User: Guest User
User: LocalService
->Flash cache emptied: 0 bytes
User: NetworkService
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 10152013_183206
Files\Folders moved on Reboot...
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ \\{825e1174-a405-eeb0-f6ca-438f3ffa937f} not found!
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ not found!
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ not found!
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f} not found!
File\Folder C:\FRST\Quarantine\Install\Install not found!
File\Folder C:\FRST\Quarantine\Install not found!
File\Folder C:\FRST\Quarantine not found!
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
*** checkup.txt
Results of screen317's Security Check version 0.99.74
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 17
Java version out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Google Chrome 30.0.1599.66
Google Chrome 30.0.1599.69
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 24% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
*** fss.txt
Farbar Service Scanner Version: 13-09-2013
Ran by Bill Hebert (administrator) on 15-10-2013 at 18:41:12
Running from "C:\Documents and Settings\Bill Hebert\Desktop"
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Other Services:
==============
Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
Extra List:
=======
Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x0700000005000000010000000200000003000000040000000600000007000000
IpSec Tag value is correct.
**** End of log ****
*** eset.txt
C:\System Volume Information\_restore{A922DAD0-5883-4DEF-A7EC-C4C1492A8F91}\RP905\A0065786.exe a variant of Win32/Kryptik.BLXE trojan cleaned by deleting - quarantined
E:\My Downloads\YouTube Downloader\FFDShow_Setup.exe a variant of Win32/Adware.iBryte.C application cleaned by deleting - quarantined
*** OTL.txt
All processes killed
========== OTL ==========
Service AppMgmt stopped successfully!
Service AppMgmt deleted successfully!
File %SystemRoot%\System32\appmgmts.dll not found.
Service WDICA stopped successfully!
Service WDICA deleted successfully!
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
Service Changer stopped successfully!
Service Changer deleted successfully!
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\BILLHE~1\LOCALS~1\Temp\catchme.sys not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\\\\{825e1174-a405-eeb0-f6ca-438f3ffa937f} folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\\\ folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\\ folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ folder moved successfully.
C:\FRST\Quarantine\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f} folder moved successfully.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ \\{825e1174-a405-eeb0-f6ca-438f3ffa937f} scheduled to be moved on reboot.
C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ \ folder moved successfully.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f} scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install\Install scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine\Install scheduled to be moved on reboot.
Folder move failed. C:\FRST\Quarantine scheduled to be moved on reboot.
C:\FRST\Logs folder moved successfully.
C:\FRST\Hives\Users\00000002 folder moved successfully.
C:\FRST\Hives\Users\00000001 folder moved successfully.
C:\FRST\Hives\Users folder moved successfully.
C:\FRST\Hives folder moved successfully.
C:\FRST folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Google Chrome cache emptied: 8629336 bytes
User: All Users
User: Bill Hebert
->Temp folder emptied: 4273173 bytes
->Temporary Internet Files folder emptied: 19530233 bytes
->Java cache emptied: 25277 bytes
->Google Chrome cache emptied: 72904501 bytes
->Flash cache emptied: 15761019 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Guest User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 9568390 bytes
->Flash cache emptied: 42072 bytes
User: NetworkService
->Temp folder emptied: 60835990 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2176856 bytes
%systemroot%\System32 .tmp files removed: 374671 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2585921 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 19225962 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 2569130 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 208.00 mb
[EMPTYJAVA]
User: Administrator
User: All Users
User: Bill Hebert
->Java cache emptied: 0 bytes
User: Default User
User: Guest User
->Java cache emptied: 0 bytes
User: LocalService
User: NetworkService
Total Java Files Cleaned = 0.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Bill Hebert
->Flash cache emptied: 0 bytes
User: Default User
User: Guest User
User: LocalService
->Flash cache emptied: 0 bytes
User: NetworkService
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 10152013_183206
Files\Folders moved on Reboot...
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ \\{825e1174-a405-eeb0-f6ca-438f3ffa937f} not found!
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ \ not found!
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f}\ not found!
File\Folder C:\FRST\Quarantine\Install\Install\{825e1174-a405-eeb0-f6ca-438f3ffa937f} not found!
File\Folder C:\FRST\Quarantine\Install\Install not found!
File\Folder C:\FRST\Quarantine\Install not found!
File\Folder C:\FRST\Quarantine not found!
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
*** checkup.txt
Results of screen317's Security Check version 0.99.74
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
`````````Anti-malware/Other Utilities Check:`````````
MVPS Hosts File
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 17
Java version out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Google Chrome 30.0.1599.66
Google Chrome 30.0.1599.69
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 24% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
*** fss.txt
Farbar Service Scanner Version: 13-09-2013
Ran by Bill Hebert (administrator) on 15-10-2013 at 18:41:12
Running from "C:\Documents and Settings\Bill Hebert\Desktop"
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Other Services:
==============
Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
Extra List:
=======
Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x0700000005000000010000000200000003000000040000000600000007000000
IpSec Tag value is correct.
**** End of log ****
*** eset.txt
C:\System Volume Information\_restore{A922DAD0-5883-4DEF-A7EC-C4C1492A8F91}\RP905\A0065786.exe a variant of Win32/Kryptik.BLXE trojan cleaned by deleting - quarantined
E:\My Downloads\YouTube Downloader\FFDShow_Setup.exe a variant of Win32/Adware.iBryte.C application cleaned by deleting - quarantined