also @ TechSpot: AMD A4-5000 Review: the affordable ultraportable APU

Windows XP, can't open Windows Explorer and associated programs.

Discussion in 'Virus and Malware Removal' started by temir, Nov 3, 2010.

  1. temir Newcomer, in training Posts: 87

    i've just restarted and tried windows explorer again, but nothing...
  2. Broni Malware Annihilator Posts: 39,394   +177

    OK, let's leave this issue alone for now and let's finish cleaning process first.

    Any other current issues?
    Would you mind switching from McAfee to something else?

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • IMPORTANT! UN-check Remove found threats
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  3. temir Newcomer, in training Posts: 87

    These are the current issues: Adobe Fireworks CS5, Flash CS5, Dreamweaver CS5 won't run.

    No, no, i don't mind to change antivirus. I even asked you before which Security Program do you suggest me.
  4. temir Newcomer, in training Posts: 87

    And another issue: Mozilla Firefox hangs when i try to download something.
  5. temir Newcomer, in training Posts: 87

    Security Check hangs? I am waiting for the report. It says in the black box: "Preparing Done!"
  6. Broni Malware Annihilator Posts: 39,394   +177

    You may need to reinstall them, but don't do it yet.
    Those issue may be connected to possible system files issues.

    Give SecurityCheck little bit more time.
    If still stuck, stop it, retry.
    If still no go, proceed with next steps.
     
  7. temir Newcomer, in training Posts: 87

    Security Check is still not going... I think i gave it enough time - 30 minutes.
  8. temir Newcomer, in training Posts: 87

    i've done TFC cleaning. Now i'm going to start with ESET scanning
  9. Broni Malware Annihilator Posts: 39,394   +177

    OK..............
  10. temir Newcomer, in training Posts: 87

    BTW, IE won't open. I didn't check it before because i don't use IE, but now I decided to open IE because in ESET i read "You are trying to launch ESET Online Scanner in a different browser than Internet Explorer. (...)".
    I am running ESET from Opera. It made me download a little program, i launched it, but i think that it hangs...
  11. temir Newcomer, in training Posts: 87

    It says in this mini ESET program: "Downloading Components", "Downloading ESET online Scanner". But nothing happens. The progress bar is empty.
  12. Broni Malware Annihilator Posts: 39,394   +177

    That's fine.
  13. Broni Malware Annihilator Posts: 39,394   +177

    Please run a BitDefender Online Scan

    • Disable your antivirus program.
    • Click Start Scanner button.
    • Click Start scan button
    • Allow browser plug-in to be installed when prompted.
    • Click I Agree to agree to the EULA.
    • Please refrain from using the computer until the scan is finished.
    • When the scan is finished, click on View log.
    • Notepad will open with scan results.
    • Save the report to your desktop and post its content in your next reply.
  14. temir Newcomer, in training Posts: 87

    You were talkin g about the Quick 60 seconds scan right?
    Report:


    QuickScan Beta 32-bit v0.9.9.50
    -------------------------------
    Scan date: Sun Nov 07 20:09:08 2010
    Machine ID: E0165A64

    C:/Program Files/Common Files/Akamai/rswin_3653.dll - could not be accessed


    No infection found.
    -------------------



    Processes
    ---------
    AcroTray - Adobe Acrobat Distiller help 352 D:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    Apple Mobile Device Service 980 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    Bonjour 992 C:\Program Files\Bonjour\mDNSResponder.exe
    Firefox 276 C:\Program Files\Mozilla Firefox\firefox.exe
    HP PML 1816 C:\WINDOWS\system32\HPZipm12.exe
    HP Software Update Application 176 D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    iTunes 2272 C:\Program Files\iPod\bin\iPodService.exe
    iTunes 400 D:\Program Files\iTunes\iTunesHelper.exe
    Java(TM) Platform SE 6 U22 1468 D:\Program Files\Java\jre6\bin\jqs.exe
    Java(TM) Platform SE Auto Updater 2 0 432 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    Microsoft Application Error Reporting 460 C:\WINDOWS\system32\dwwin.exe
    Microsoft Application Error Reporting 2216 C:\WINDOWS\system32\dwwin.exe
    Microsoft® Windows® Operating System 232 C:\WINDOWS\ehome\ehmsas.exe
    Microsoft® Windows® Operating System 1052 C:\WINDOWS\ehome\ehRecvr.exe
    Microsoft® Windows® Operating System 1472 C:\WINDOWS\ehome\ehSched.exe
    Microsoft® Windows® Operating System 2040 C:\WINDOWS\ehome\ehtray.exe
    Microsoft® Windows® Operating System 1912 C:\WINDOWS\explorer.exe
    Microsoft® Windows® Operating System 2664 C:\WINDOWS\system32\alg.exe
    Microsoft® Windows® Operating System 552 C:\WINDOWS\system32\csrss.exe
    Microsoft® Windows® Operating System 3192 C:\WINDOWS\system32\dllhost.exe
    Microsoft® Windows® Operating System 816 C:\WINDOWS\system32\dumprep.exe
    Microsoft® Windows® Operating System 632 C:\WINDOWS\system32\lsass.exe
    Microsoft® Windows® Operating System 424 C:\WINDOWS\system32\rundll32.exe
    Microsoft® Windows® Operating System 620 C:\WINDOWS\system32\services.exe
    Microsoft® Windows® Operating System 496 C:\WINDOWS\system32\smss.exe
    Microsoft® Windows® Operating System 1732 C:\WINDOWS\system32\spoolsv.exe
    Microsoft® Windows® Operating System 532 C:\WINDOWS\system32\svchost.exe
    Microsoft® Windows® Operating System 684 C:\WINDOWS\system32\svchost.exe
    Microsoft® Windows® Operating System 916 C:\WINDOWS\system32\svchost.exe
    Microsoft® Windows® Operating System 1212 C:\WINDOWS\system32\svchost.exe
    Microsoft® Windows® Operating System 1332 C:\WINDOWS\system32\svchost.exe
    Microsoft® Windows® Operating System 1452 C:\WINDOWS\system32\svchost.exe
    Microsoft® Windows® Operating System 868 C:\WINDOWS\system32\svchost.exe
    Microsoft® Windows® Operating System 1888 C:\WINDOWS\system32\wdfmgr.exe
    Microsoft® Windows® Operating System 576 C:\WINDOWS\system32\winlogon.exe
    Microsoft® Windows® Operating System 1892 C:\WINDOWS\system32\wscntfy.exe
    NVIDIA Driver Helper Service, Version 2 776 C:\WINDOWS\system32\nvsvc32.exe
    Opera Internet Browser 3088 D:\Program Files\Opera\opera.exe


    Network activity
    ----------------
    Process firefox.exe (276) connected on port 80 (HTTP) --> 74.125.79.100
    Process firefox.exe (276) connected on port 80 (HTTP) --> 95.101.213.115
    Process firefox.exe (276) connected on port 80 (HTTP) --> 95.101.220.20
    Process firefox.exe (276) connected on port 80 (HTTP) --> 195.22.202.72
    Process opera.exe (3088) connected on port 80 (HTTP) --> 216.137.61.186
    Process opera.exe (3088) connected on port 80 (HTTP) --> 95.101.188.74
    Process opera.exe (3088) connected on port 80 (HTTP) --> 95.101.210.77
    Process opera.exe (3088) connected on port 443 (HTTP over SSL) --> 74.125.79.95
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.40
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.10
    Process opera.exe (3088) connected on port 80 (HTTP) --> 69.63.190.10
    Process opera.exe (3088) connected on port 80 (HTTP) --> 8.12.226.191
    Process opera.exe (3088) connected on port 80 (HTTP) --> 67.214.159.90
    Process opera.exe (3088) connected on port 80 (HTTP) --> 8.12.226.191
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.72
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.88
    Process opera.exe (3088) connected on port 80 (HTTP) --> 72.14.234.96
    Process opera.exe (3088) connected on port 80 (HTTP) --> 64.136.52.25
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.27
    Process opera.exe (3088) connected on port 80 (HTTP) --> 193.149.47.99
    Process opera.exe (3088) connected on port 80 (HTTP) --> 95.101.220.20
    Process opera.exe (3088) connected on port 80 (HTTP) --> 72.14.234.154
    Process opera.exe (3088) connected on port 80 (HTTP) --> 216.137.61.61
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.88
    Process opera.exe (3088) connected on port 80 (HTTP) --> 74.122.140.23
    Process opera.exe (3088) connected on port 80 (HTTP) --> 95.101.213.115
    Process opera.exe (3088) connected on port 80 (HTTP) --> 72.14.234.148
    Process opera.exe (3088) connected on port 80 (HTTP) --> 72.14.234.154
    Process opera.exe (3088) connected on port 80 (HTTP) --> 72.14.255.148
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.72
    Process opera.exe (3088) connected on port 80 (HTTP) --> 195.22.202.67
    Process opera.exe (3088) connected on port 80 (HTTP) --> 63.135.86.29
    Process opera.exe (3088) connected on port 80 (HTTP) --> 74.125.79.101

    Process svchost.exe (868) listens on ports: 3389 (Terminal Server)
    Process svchost.exe (916) listens on ports: 135 (RPC)


    Autoruns and critical files
    ---------------------------
    AcroTray - Adobe Acrobat Distiller help D:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    Adobe Acrobat D:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
    Adobe CS5 Service Manager C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
    Adobe Updater Startup Utility C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
    HP Software Update Application D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    iTunes D:\Program Files\iTunes\iTunesHelper.exe
    Java(TM) Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    Microsoft® Windows® Operating System C:\WINDOWS\ehome\ehtray.exe
    Microsoft® Windows® Operating System C:\WINDOWS\system32\browseui.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\crypt32.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe
    Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\shell32.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll
    Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
    Microsoft® Windows® Operating System C:\WINDOWS\system32\webcheck.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\wlnotify.dll
    Microsoft® Windows® Operating System K:\autorun.exe
    NVIDIA Compatible Windows 2000 Display C:\WINDOWS\system32\NvCpl.dll
    NVIDIA Media Center Library C:\WINDOWS\system32\nvmctray.dll
    QuickTime C:\Program Files\QuickTime\qttask.exe
    SBSV 2010/02/19-11:02:07 C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe


    Browser plugins
    ---------------
    2007 Microsoft Office system C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
    AcroIEHelperShim Library c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
    Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll
    Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
    Adobe PDF Toolbar for IE c:\program files\common files\adobe\acrobat\activex\acroiefavclient.dll
    Adobe® Flash® Player ActiveX C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
    BitDefender QuickScan C:\Documents and Settings\Temir.PRIVATE-A7D0BBD.000\Application Data\Mozilla\Firefox\Profiles\au9prvy0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    BitDefender QuickScan C:\Documents and Settings\Temir.PRIVATE-A7D0BBD.000\Application Data\Mozilla\Firefox\Profiles\au9prvy0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    Bonjour C:\Program Files\Bonjour\mdnsNSP.dll
    DivX Web Player C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
    HPDEXAXO C:\WINDOWS\Downloaded Program Files\HPDEXAXO.dll
    InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.dll
    InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.exe
    InstallShield Update Service C:\WINDOWS\Downloaded Program Files\isusweb.dll
    Java Deployment Toolkit 6.0.220.4 C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    Java(TM) Platform SE 6 U22 d:\program files\java\jre6\bin\jp2ssv.dll
    Java(TM) Platform SE 6 U22 D:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
    Java(TM) Platform SE 6 U22 d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    Microsoft® Windows Live Login Helper c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
    Microsoft® Windows Media Player Firefox C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\shdocvw.dll
    Microsoft® Windows® Operating System C:\WINDOWS\system32\winrnr.dll
    Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
    npitunes.dll D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    nppdf32.DEU C:\Program Files\Mozilla Firefox\plugins\nppdf32.DEU
    nppdf32.FRA C:\Program Files\Mozilla Firefox\plugins\nppdf32.FRA
    NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
    Octoshape Streaming Services C:\Documents and Settings\Temir.PRIVATE-A7D0BBD.000\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll
    QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
    QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
    QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
    QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
    QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
    QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
    QuickTime Plug-in 7.6.5 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
    RealJukebox NS Plugin C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
    RealPlayer Version Plugin C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
    RealPlayer(tm) G2 LiveConnect-Enabled P C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
    Shockwave for Director C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
    Silverlight Plug-In C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
    Skype Toolbars c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    The OpenSSL Toolkit C:\Program Files\Mozilla Firefox\plugins\libdivx.dll
    The OpenSSL Toolkit C:\Program Files\Mozilla Firefox\plugins\ssldivx.dll


    Missing files
    -------------
    File not found: C:\DOCUME~1\Temir\LOCALS~1\Temp\catchme.sys
    --> HKLM\System\ControlSet001\services\catchme\"ImagePath"

    File not found: C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
    --> HKLM\System\ControlSet001\services\McShield\"ImagePath"

    File not found: C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
    --> HKLM\System\ControlSet001\services\mfefire\"ImagePath"

    File not found: C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
    --> HKLM\System\ControlSet001\services\mcmscsvc\"ImagePath"

    File not found: C:\Program Files\McAfee\VirusScan\mcods.exe
    --> HKLM\System\ControlSet001\services\McODS\"ImagePath"

    File not found: C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
    --> HKLM\System\ControlSet001\services\NanoServiceMain\"ImagePath"

    File not found: system32\DRIVERS\mfendisk.sys
    --> HKLM\System\ControlSet001\services\mfendiskmp\"ImagePath"

    File not found: system32\drivers\mfeapfk.sys
    --> HKLM\System\ControlSet001\services\mfeapfk\"ImagePath"

    File not found: system32\drivers\mfeavfk.sys
    --> HKLM\System\ControlSet001\services\mfeavfk\"ImagePath"

    File not found: system32\drivers\mfebopk.sys
    --> HKLM\System\ControlSet001\services\mfebopk\"ImagePath"

    File not found: system32\drivers\mfefirek.sys
    --> HKLM\System\ControlSet001\services\mfefirek\"ImagePath"

    File not found: system32\drivers\mfehidk.sys
    --> HKLM\System\ControlSet001\services\mfehidk\"ImagePath"

    File not found: system32\drivers\mferkdet.sys
    --> HKLM\System\ControlSet001\services\mferkdet\"ImagePath"

    File not found: system32\drivers\mfetdi2k.sys
    --> HKLM\System\ControlSet001\services\mfetdi2k\"ImagePath"


    Scan
    ----


    No file uploaded.

    Scan finished - communication took 2 sec
    Total traffic - 0.05 MB sent, 1.80 KB recvd
    Scanned 992 files and modules - 48 seconds

    ==============================================================================
  15. Broni Malware Annihilator Posts: 39,394   +177

    Good.
    Now, we'll finish cleaning process and we'll go back to your other issues.

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current (including Service Pack 3!!!)

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    12. Please, let me know, how is your computer doing.
  16. temir Newcomer, in training Posts: 87

    Report 1:

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: admin
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Administrator.PRIVATE-A7D0BBD
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Opera cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Administrator.PRIVATE-A7D0BBD.000
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes
    ->Opera cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Administrator.PRIVATE-A7D0BBD.001
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Administrator.PRIVATE-A7D0BBD.002
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService.NT AUTHORITY.000
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: LocalService.NT AUTHORITY.001
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: NetworkService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: NetworkService.NT AUTHORITY.000
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: NetworkService.NT AUTHORITY.001
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Temir
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Temir.PRIVATE-A7D0BBD.000
    ->Temp folder emptied: 80156309 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 3063783 bytes
    ->FireFox cache emptied: 19519068 bytes
    ->Opera cache emptied: 13989110 bytes
    ->Flash cache emptied: 742 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 16384 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 111,00 mb


    [EMPTYFLASH]

    User: admin
    ->Flash cache emptied: 0 bytes

    User: Administrator

    User: Administrator.PRIVATE-A7D0BBD
    ->Flash cache emptied: 0 bytes

    User: Administrator.PRIVATE-A7D0BBD.000
    ->Flash cache emptied: 0 bytes

    User: Administrator.PRIVATE-A7D0BBD.001
    ->Flash cache emptied: 0 bytes

    User: Administrator.PRIVATE-A7D0BBD.002
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: LocalService

    User: LocalService.NT AUTHORITY

    User: LocalService.NT AUTHORITY.000

    User: LocalService.NT AUTHORITY.001

    User: NetworkService

    User: NetworkService.NT AUTHORITY

    User: NetworkService.NT AUTHORITY.000

    User: NetworkService.NT AUTHORITY.001

    User: Temir
    ->Flash cache emptied: 0 bytes

    User: Temir.PRIVATE-A7D0BBD.000
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0,00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.17.3 log created on 11072010_202215

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  17. temir Newcomer, in training Posts: 87

    Step two - done.
  18. Broni Malware Annihilator Posts: 39,394   +177

    Let me know, when you're done with all steps, including Windows updates.
  19. temir Newcomer, in training Posts: 87

    About Windows Updates:

    I can't open IE, then i realized that i can't even access Widnows Update from Start -> Programs etc... So i downloaded using Opera SP3 for Windows XP and installed it. So actually i suppose i am running SP3, i don't see any changes in Windows.

    Windows Explorer still won't open.
  20. temir Newcomer, in training Posts: 87

    i'll go ahead with the rest of the steps. There is the step nr 11, i've run rapidly through it and saw posts where people say that those procedures, programs slow down the PC.