also @ TechSpot: Intel confirms a smartwatch is in the pipeline

Random audio clips and random pop-ups

Discussion in 'Virus and Malware Removal' started by AKFH, Jul 28, 2010.

  1. AKFH Newcomer, in training Posts: 106

    Which would you prefer to be used on my XP Professional?
  2. AKFH Newcomer, in training Posts: 106

    I will post the OLT log once more after I am done downloading and installing Avira. I will leave for the Movie Theatres. Thanks for the help, and please leave a last post with anything else I need to do so when I get back I will complete it!
  3. Broni Malware Annihilator Posts: 40,051   +187

    Installing AV, updating Java and posting new OTL log, it's all I need from you.

    Have fun at the movies :)
  4. AKFH Newcomer, in training Posts: 106

    Thanks, 'The Other Guy' was a great movie, haha.

    I updated Java, and I installed Avira. For the AHeAD level setting, what would you suggest?

    Low, Medium, or High? It said Medium was the recommended choice but it never stated any bad side-effects of the High level AHeAD detection level.

    OTL log is coming up

    Attached Files:

    • OTL.Txt
      File size:
      90.9 KB
      Views:
      1
  5. Broni Malware Annihilator Posts: 40,051   +187

    Shut up...LOL...I'm going to see it on Sunday....

    "Medium" will be fine.

    Let me check your log...
  6. Broni Malware Annihilator Posts: 40,051   +187

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab (Reg Error: Key error.)
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
      O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
      [2010/05/12 16:23:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ant\Application Data\AVG9
      [3 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
      [3 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
      [2010/08/04 19:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
      @Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.
     
  7. AKFH Newcomer, in training Posts: 106

    Haha, alright I'll re-post when I am done and I get the log.

    You better see it, it was a good movie. Worth enjoying (at least to me and my friends it was :p)
  8. Broni Malware Annihilator Posts: 40,051   +187

    Cool :).....
  9. AKFH Newcomer, in training Posts: 106

    All processes killed
    Error: Unable to interpret <OTL> in the current context!
    Error: Unable to interpret <O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.> in the current context!
    Error: Unable to interpret <O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab (Reg Error: Key error.)> in the current context!
    Error: Unable to interpret <O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)> in the current context!
    Error: Unable to interpret <O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)> in the current context!
    Error: Unable to interpret <O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)> in the current context!
    Error: Unable to interpret <O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)> in the current context!
    Error: Unable to interpret <[2010/05/12 16:23:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Ant\Application Data\AVG9> in the current context!
    Error: Unable to interpret <[3 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]> in the current context!
    Error: Unable to interpret <[3 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]> in the current context!
    Error: Unable to interpret <[2010/08/04 19:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9> in the current context!
    Error: Unable to interpret <@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9> in the current context!
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Ant
    ->Temp folder emptied: 10349603 bytes
    ->Temporary Internet Files folder emptied: 34137118 bytes
    ->Java cache emptied: 8114974 bytes
    ->FireFox cache emptied: 86322388 bytes
    ->Google Chrome cache emptied: 352696488 bytes
    ->Apple Safari cache emptied: 5252096 bytes
    ->Opera cache emptied: 229707 bytes
    ->Flash cache emptied: 108956 bytes

    User: Christopher
    ->Temp folder emptied: 706 bytes
    ->Temporary Internet Files folder emptied: 77607877 bytes
    ->Google Chrome cache emptied: 6623600 bytes
    ->Flash cache emptied: 924 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Guest
    ->Temp folder emptied: 477158 bytes
    ->Temporary Internet Files folder emptied: 345626 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 9204946 bytes
    ->Flash cache emptied: 3261 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 112094 bytes
    ->Flash cache emptied: 434 bytes

    User: Tony
    ->Temp folder emptied: 282 bytes
    ->Temporary Internet Files folder emptied: 489577 bytes

    User: User Data

    User: Veronica
    ->Temp folder emptied: 225025 bytes
    ->Temporary Internet Files folder emptied: 34978829 bytes
    ->Flash cache emptied: 434 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 1119359 bytes
    %systemroot%\System32 .tmp files removed: 2675729 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 185340 bytes
    RecycleBin emptied: 44089904 bytes

    Total Files Cleaned = 644.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Ant
    ->Flash cache emptied: 0 bytes

    User: Christopher
    ->Flash cache emptied: 0 bytes

    User: Default User

    User: Guest

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: Tony

    User: User Data

    User: Veronica
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.9.1 log created on 08062010_225352

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...




    Odd...

    EDIT: Is it suppose to say all that...?
  10. Broni Malware Annihilator Posts: 40,051   +187

    It didn't work.
    It looks like you didn't copy a whole script, especially a "colon" in front of "OTL" (1st line).
    Please, retry.
  11. AKFH Newcomer, in training Posts: 106

    All processes killed
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
    Starting removal of ActiveX control {40F576AD-8680-4F9E-9490-99D069CD665F}
    C:\WINDOWS\Downloaded Program Files\sysreqlabdetect.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{40F576AD-8680-4F9E-9490-99D069CD665F}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40F576AD-8680-4F9E-9490-99D069CD665F}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{40F576AD-8680-4F9E-9490-99D069CD665F}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{40F576AD-8680-4F9E-9490-99D069CD665F}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{40F576AD-8680-4F9E-9490-99D069CD665F}\ not found.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\WINDOWS\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found.
    Starting removal of ActiveX control DirectAnimation Java Classes
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found.
    File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
    Starting removal of ActiveX control Microsoft XML Parser for Java
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
    C:\Documents and Settings\Ant\Application Data\AVG9\cfgall folder moved successfully.
    C:\Documents and Settings\Ant\Application Data\AVG9 folder moved successfully.
    File/Folder C:\windows\System32\*.tmp not found.
    File/Folder C:\windows\*.tmp not found.
    C:\Documents and Settings\All Users\Application Data\avg9\update\prepare\temp folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\update\prepare folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\update\backup folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\update folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\Temp folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\scanlogs folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\Log folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\emc\Queue\TEMP folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\emc\Queue\OUT folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\emc\Queue\ACTIVE folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\emc\Queue folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\emc\Log folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\emc folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\Dumps folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\cfgall folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\cfg folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\AvgApi folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\AvgAm folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9\admincli folder moved successfully.
    C:\Documents and Settings\All Users\Application Data\avg9 folder moved successfully.
    ADS C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9 deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Ant
    ->Temp folder emptied: 1140 bytes
    ->Temporary Internet Files folder emptied: 46269 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 28925804 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Apple Safari cache emptied: 0 bytes
    ->Opera cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Christopher
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Guest
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Tony
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: User Data

    User: Veronica
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 483 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 875296 bytes

    Total Files Cleaned = 28.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Ant
    ->Flash cache emptied: 0 bytes

    User: Christopher
    ->Flash cache emptied: 0 bytes

    User: Default User

    User: Guest

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: Tony

    User: User Data

    User: Veronica
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.9.1 log created on 08062010_232420

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  12. Broni Malware Annihilator Posts: 40,051   +187

    Now, you're talking :)

    Last scans...

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Go to Kaspersky website and perform an online antivirus scan.

    • Disable your active antivirus program.
    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
      • Archives
      • Mail databases
    • Click on My Computer under Scan.
    • Once the scan is complete, it will display the results. Click on View Scan Report.
    • You will see a list of infected items there. Click on Save Report As....
    • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
  13. AKFH Newcomer, in training Posts: 106

    Results of screen317's Security Check version 0.99.5
    Windows XP Service Pack 3
    Internet Explorer 7 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    Avira AntiVir Personal - Free Antivirus
    ESET Online Scanner v3
    Antivirus up to date!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner (remove only)
    Java(TM) 6 Update 21
    Adobe Flash Player 10.1.53.64
    Adobe Reader 9.1.2
    Chinese Traditional Fonts Support For Adobe Reader 9
    Mozilla Firefox (3.6.8)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Avira Antivir avgnt.exe
    Avira Antivir avguard.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````



    QUESTION: Why does Mozilla Fire Fox continue to have a pop-up after every download saying No Anti-Virus detected. When I do? It didn't happen when I had AVG
  14. Broni Malware Annihilator Posts: 40,051   +187

    I'm not sure about that Firefox issue.
    Try to restart computer, when you're done with Kaspersky.
  15. AKFH Newcomer, in training Posts: 106

    It's taking awfully long for Kaspersky to update that Databse of theirs...... Its been almost 30 minutes
  16. AKFH Newcomer, in training Posts: 106

    Its database total collct kjeeps increasing, so after this 30+ mminutes, it kept lowering the percentage done down, (right now it's 16% again when it was 20 a few seconds ago.)
  17. Broni Malware Annihilator Posts: 40,051   +187

    Stop Kaspersky...

    Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • IMPORTANT! UN-check Remove found threats
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Push Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  18. AKFH Newcomer, in training Posts: 106

    Alright thank God. I have that one already. This one seemed like it had never-ending database.. Wow... i'll have that text file in a few minutes :)Thanks again Broni
  19. Broni Malware Annihilator Posts: 40,051   +187

    Sure thing :)
  20. AKFH Newcomer, in training Posts: 106

    It did not produce a text, but there were no threats. nothing found.