1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Tim's Vista Laptop can't access Internet

Discussion in 'Malware and Virus Removal Archive' started by tvjohns, 2011/05/12.

  1. 2011/06/11
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    Updated java and removed old Java successfully. BUT on reboot got notice Java Update not working. I checked in FireWall and did enable a new java entry. Assume this fixes updater problem.

    ALSO: I tried to run OTL with pasted in entry you listed. Clicked Run Fix but OTL locked up, ie, after a few moments what I thought was run time OTL showed program not responding or words to that effect. Rebooted anyway, no log entry appreared.

    ??? Any suggestions? Re-download fresh copy OTL and try again or what?
     
  2. 2011/06/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please do.
     

  3. to hide this advert.

  4. 2011/06/14
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    I downloaded a fresh copy of OTL. Ran it 3 times. Each time it seems to run quickly to completion, showing the phrase Killing Processes (words to that effect.) Each time after a pause the top line shows Not Responding. I reboot anyway and when desktop comes back I see no log. If it worked such a log should automatically pop right up on Desktop, right? I even opened OTL to see if there's a open log button but nothing apparent. Don't what else to say. Should there be some other settings changed on the OTL page when it opens rather that just pasting in the list you specify into Custom Scans/Fixes?

    ALSO, every time I reboot the computer this warning window comes up:
    "Java Update Scheduler has stopped working." No idea why that happens.
     
  5. 2011/06/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  6. 2011/06/16
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    Safe mode worked. Log:

    All processes killed
    ========== OTL ==========
    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
    Registry key HKEY_CURRENT_USER\Software\Classes\.com\ not found.
    Registry key HKEY_CURRENT_USER\Software\Classes\ComFile\ not found.
    HKEY_LOCAL_MACHINE\Software\Classes\.com\\|comfile /E : value set successfully!
    Registry key HKEY_CURRENT_USER\Software\Classes\.exe\ not found.
    Registry key HKEY_CURRENT_USER\Software\Classes\exefile\ not found.
    HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
    File C:\Users\Timothy\AppData\Local\s3y6i48l744h4x280ce123866cp324d301uytp1006 not found.
    File C:\ProgramData\s3y6i48l744h4x280ce123866cp324d301uytp1006 not found.
    File C:\Users\Timothy\AppData\Local\230t17d8r0p00q1761g3mnq4h8r4n7k5w62 not found.
    File C:\ProgramData\230t17d8r0p00q1761g3mnq4h8r4n7k5w62 not found.
    File C:\ProgramData\KGyGaAvL.sys not found.
    Unable to delete ADS C:\ProgramData\TEMP:DFC5A2B2 .
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: Timothy
    ->Temp folder emptied: 9780858 bytes
    ->Temporary Internet Files folder emptied: 3367055 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 152227444 bytes
    ->Flash cache emptied: 4067 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 994351 bytes
    RecycleBin emptied: 142627908 bytes

    Total Files Cleaned = 295.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Public

    User: Timothy
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.24.0 log created on 06162011_212008

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     
  7. 2011/06/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very well :)
    Go on....
     
  8. 2011/06/16
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    Checkup Text;

    Results of screen317's Security Check version 0.99.7
    Windows Vista Service Pack 1 (UAC is enabled)
    Out of date service pack!!
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    avast! Free Antivirus
    ESET Online Scanner v3
    VistaFirewallControl 2.0.0.105
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner (remove only)
    Java(TM) 6 Update 26
    Out of date Java installed!
    Adobe Flash Player 10.1.102.64
    Adobe Reader 8.1.1
    Out of date Adobe Reader installed!
    Mozilla Firefox (3.0.19) Firefox Out of Date!
    Mozilla Thunderbird (3.1.4) Thunderbird Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    VistaFirewallControl VistaFirewallService.exe
    VistaFirewallControl VistaFirewallControl.exe
    Alwil Software Avast5 AvastSvc.exe
    Alwil Software Avast5 AvastUI.exe
    ``````````End of Log````````````
     
  9. 2011/06/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Update Firefox to the latest 4.0.1 version.

    Update Thunderbird to the latest 3.1.10 version.

    Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions.
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
    It's a much smaller file to download and uses a lot less resources than Adobe Reader.
    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

    Service Pack 2 installation is long overdue, but Eset scan first....
     
  10. 2011/06/17
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    ESETScan Log:

    C:\DOWNLOADS\# ALL CODECS AND PLAYERS\# FLV CODEC PLAYERS\FLVPlayer_Setup.exe a variant of Win32/SweetIM.A application
    C:\DOWNLOADS\# ALL CODECS AND PLAYERS\## Media Player Codec Pack 3.9.6\media.player.codec.pack.v3.9.6.setup.exe Win32/Adware.Toolbar.Dealio application
    C:\SAVE\# ALL MY ESSENTIAL APPS\0 0 0 BASIC ESSENTIALS\Hamster Free Video Converter\hamsterfreevideoconverter.exe Win32/Toolbar.Zugo application
    C:\SAVE\# UTILITIES\CD-DVD BURNERS\INFRA RECORDER\InfraRecorder 0.44.1.exe a variant of Win32/Adware.MarketScore.A application
    C:\SAVE\# UTILITIES\MULTIMEDIA\FreeYouTubeDownloaderSetup.exe Win32/Toolbar.Zugo application
    C:\SAVE\## ATT DSL\registrybooster.exe a variant of Win32/RegistryBooster application
    C:\SAVE\0 0 0 PCWORLD STUFF\2010-0325\BetterPaste.exe.zip probably a variant of Win32/Agent.LEFDLPD trojan
    C:\SAVE\Portable Games\Stressed_Out.exe probably a variant of Win32/Agent.GZODBMX trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\4cb3e0c0-5d48ee53 a variant of Win32/Kryptik.OKX trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\6685d300-18f9d556 Java/Exploit.CVE-2010-4452.A trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-13d89c64 a variant of Java/TrojanDownloader.OpenStream.NCE trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-43d439b7 a variant of Java/TrojanDownloader.OpenStream.NCE trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-60f29698 a variant of Java/TrojanDownloader.OpenStream.NCE trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-6d453501 a variant of Java/TrojanDownloader.OpenStream.NCE trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-782ebc00 a variant of Java/TrojanDownloader.OpenStream.NCE trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-7be10cd1 a variant of Java/TrojanDownloader.OpenStream.NCE trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\6bd8e8d-716927b3 Java/Agent.X trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\61683fd4-38af18b3 Java/TrojanDownloader.OpenStream.NBV trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\ef1559b-7f5ba7f8 Java/TrojanDownloader.OpenStream.NCA trojan
    C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\68323a31-547d7f96 probably a variant of Win32/Injector.GJR trojan
    C:\Users\Timothy\Documents\Downloads\The Vice Busting Diet Plans Weight Loss Made Easy.exe Win32/TrojanDownloader.VB.OFT trojan
    C:\Users\Timothy\Saved Games\Shoot holes in Windows.exe probably a variant of Win32/Agent.GZODBMX trojan
    C:\Users\Timothy\Saved Games\Stressed_Out.exe probably a variant of Win32/Agent.GZODBMX trojan
    F:\MANUAL BACKUPS\Dell Desktop Critical Files\Portable Games\Stressed_Out.exe probably a variant of Win32/Agent.GZODBMX trojan
    F:\Saved Games\Shoot holes in Windows.exe probably a variant of Win32/Agent.GZODBMX trojan
    F:\Saved Games\Stressed_Out.exe probably a variant of Win32/Agent.GZODBMX trojan
    F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-13 120238\Backup files 1.zip multiple threats
    F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-20 120007\Backup files 1.zip Java/Exploit.CVE-2010-4452.A trojan
    F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-24 012029\Backup files 1.zip multiple threats
    F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-28 120012\Backup files 1.zip JS/Exploit.Pdfka.OXB.Gen trojan
    F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-06-11 120005\Backup files 2.zip multiple threats
    F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-06-15 120008\Backup files 2.zip multiple threats
     
  11. 2011/06/17
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    QUESTION: How critical is it that I update Firefox and Thunderbird. Both give me trouble with updates over the versions I use now as I have them customized with extensions I like and use very much. BUT I suppose the newer versions are safer vis-a-vis malware susceptibility Adobe Reader I have no trouble uninstalling as I really don't use it. Latest versions of Adobe are way too large and overloaded for my needs. The PDF reader I use exclusively is PDFXVwer 2.5.193.
     
  12. 2011/06/17
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    ALSO: I ran TFC, which I have used several times pervious, but last night it seemed to run OK as usual, showing all temp files scanned as 0 bytes. THEN as I clicked to exit TFC locked up with note Not Responding, just as OTL had done several times before. I shall try running again, as I note, it has run OK several times before. But if not running, should I run TFC in Safe mode also, just to be sure or how critical is it?
     
  13. 2011/06/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Browsers and email clients updates fall into "critical" category.

    ====================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      
      :Services
      
      :Reg
      
      :Files
      C:\DOWNLOADS\# ALL CODECS AND PLAYERS\# FLV CODEC PLAYERS\FLVPlayer_Setup.exe 
      C:\DOWNLOADS\# ALL CODECS AND PLAYERS\## Media Player Codec Pack 3.9.6\media.player.codec.pack.v3.9.6.setup.exe 
      C:\SAVE\# ALL MY ESSENTIAL APPS\0 0 0 BASIC ESSENTIALS\Hamster Free Video Converter\hamsterfreevideoconverter.exe 
      C:\SAVE\# UTILITIES\CD-DVD BURNERS\INFRA RECORDER\InfraRecorder 0.44.1.exe 
      C:\SAVE\# UTILITIES\MULTIMEDIA\FreeYouTubeDownloaderSetup.exe 
      C:\SAVE\## ATT DSL\registrybooster.exe 
      C:\SAVE\0 0 0 PCWORLD STUFF\2010-0325\BetterPaste.exe.zip 
      C:\SAVE\Portable Games\Stressed_Out.exe 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\4cb3e0c0-5d48ee53 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\6685d300-18f9d556 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-13d89c64 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-43d439b7 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-60f29698 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-6d453501 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-782ebc00 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-7be10cd1 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\6bd8e8d-716927b3 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\61683fd4-38af18b3 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\ef1559b-7f5ba7f8 
      C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\68323a31-547d7f96 
      C:\Users\Timothy\Documents\Downloads\The Vice Busting Diet Plans Weight Loss Made Easy.exe 
      C:\Users\Timothy\Saved Games\Shoot holes in Windows.exe 
      C:\Users\Timothy\Saved Games\Stressed_Out.exe 
      F:\MANUAL BACKUPS\Dell Desktop Critical Files\Portable Games\Stressed_Out.exe 
      F:\Saved Games\Shoot holes in Windows.exe 
      F:\Saved Games\Stressed_Out.exe 
      F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-13 120238\Backup files 1.zip 
      F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-20 120007\Backup files 1.zip 
      F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-24 012029\Backup files 1.zip 
      F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-28 120012\Backup files 1.zip 
      F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-06-11 120005\Backup files 2.zip 
      F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-06-15 120008\Backup files 2.zip
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ====================================================

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current (including Service Pack 2 installation and updating Internet Explorer to version 9!!!)

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    12. Please, let me know, how your computer is doing.
     
  14. 2011/06/20
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    OTL LOG:

    All processes killed
    ========== OTL ==========
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File\Folder C:\DOWNLOADS\# ALL CODECS AND PLAYERS\# FLV CODEC PLAYERS\FLVPlayer_Setup.exe not found.
    File\Folder C:\DOWNLOADS\# ALL CODECS AND PLAYERS\## Media Player Codec Pack 3.9.6\media.player.codec.pack.v3.9.6.setup.exe not found.
    File\Folder C:\SAVE\# ALL MY ESSENTIAL APPS\0 0 0 BASIC ESSENTIALS\Hamster Free Video Converter\hamsterfreevideoconverter.exe not found.
    File\Folder C:\SAVE\# UTILITIES\CD-DVD BURNERS\INFRA RECORDER\InfraRecorder 0.44.1.exe not found.
    File\Folder C:\SAVE\# UTILITIES\MULTIMEDIA\FreeYouTubeDownloaderSetup.exe not found.
    File\Folder C:\SAVE\## ATT DSL\registrybooster.exe not found.
    File\Folder C:\SAVE\0 0 0 PCWORLD STUFF\2010-0325\BetterPaste.exe.zip not found.
    File\Folder C:\SAVE\Portable Games\Stressed_Out.exe not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\4cb3e0c0-5d48ee53 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\6685d300-18f9d556 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-13d89c64 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-43d439b7 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-60f29698 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-6d453501 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-782ebc00 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\442f90cb-7be10cd1 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\6bd8e8d-716927b3 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20\61683fd4-38af18b3 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\ef1559b-7f5ba7f8 not found.
    File\Folder C:\Users\Timothy\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\68323a31-547d7f96 not found.
    File\Folder C:\Users\Timothy\Documents\Downloads\The Vice Busting Diet Plans Weight Loss Made Easy.exe not found.
    File\Folder C:\Users\Timothy\Saved Games\Shoot holes in Windows.exe not found.
    File\Folder C:\Users\Timothy\Saved Games\Stressed_Out.exe not found.
    File\Folder F:\MANUAL BACKUPS\Dell Desktop Critical Files\Portable Games\Stressed_Out.exe not found.
    File\Folder F:\Saved Games\Shoot holes in Windows.exe not found.
    File\Folder F:\Saved Games\Stressed_Out.exe not found.
    File\Folder F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-13 120238\Backup files 1.zip not found.
    File\Folder F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-20 120007\Backup files 1.zip not found.
    File\Folder F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-24 012029\Backup files 1.zip not found.
    File\Folder F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-05-28 120012\Backup files 1.zip not found.
    File\Folder F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-06-11 120005\Backup files 2.zip not found.
    File\Folder F:\TIMOTHY-PC\Backup Set 2011-02-01 123805\Backup Files 2011-06-15 120008\Backup files 2.zip not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: Timothy
    ->Temp folder emptied: 35828 bytes
    ->Temporary Internet Files folder emptied: 896742 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 48142286 bytes
    ->Flash cache emptied: 608 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 32768 bytes
    RecycleBin emptied: 447 bytes

    Total Files Cleaned = 47.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Public

    User: Timothy
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.24.0 log created on 06202011_214451

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     
  15. 2011/06/20
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    Create Clean Restore Point LOG:

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: Timothy
    ->Temp folder emptied: 31832 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 22127491 bytes
    ->Flash cache emptied: 482 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 21.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Public

    User: Timothy
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.24.0 log created on 06202011_221532

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     
  16. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go on....
     
  17. 2011/06/20
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    I just ran OTL in Cleanup mode (have had to do every OTL run in Safe Mode tonight) and did the reboot as instructed. When Desktop came back up I got this warning message:

    An unauthorized change has been made to Windows. You will no longer get updates???? the rest of it I don't remember, but looked like Windows updates or some sorts of Windows functioning !!! another error window just popped up while writing this Windows backup failed do to internal error Check windows configuration and try again or words to that effect. ??? Occurs to me that contaminated USB External Hard Drive backup files all removed. Maybe that was all of them. I'll have to check and see what I can do to get files backup to my USB drive functioning again. ....

    NOTE: I just tried to open Windows Backup page and got this error message:

    The backup application could not start due to an internal error: (0xC004F027)

    Please check your system configuration and try again.
     
  18. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Set Windows updates to automatic: http://windows.microsoft.com/en-US/windows-vista/Turn-automatic-updating-on-or-off

    As for backup issue, that would be a subject to another forum.
    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.

    Any other issues?
     
  19. 2011/06/20
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    I can't open Control Panel either. I click on Control Panel and nothing happens!?
     
  20. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  21. 2011/06/20
    tvjohns

    tvjohns Inactive Thread Starter

    Joined:
    2003/02/02
    Messages:
    120
    Likes Received:
    0
    Here's the bad error message:

    An unauthorized change was made to Windows

    You will no longer receive notifications, including those about your license or activation. Use the link below to find out how to fix your system. Showing Details has Error: 0xC004D401

    Description: The security processor reported a system file mismatch error.I clicked on an included link to "learn how to fix this" and that took me to Genuine Microsoft validation page when I am still stuck on for several minutes VALIDATION IN PROCESS, but doesn't look like its going through.??? I think I may be ******* trying that this late
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.