SpyWare BeWare! ASAP
February 28, 2015, 01:46:21 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
   Home   Help Search Calendar Donations Login Register Chat  



Google It!
Pages: 1 ... 8 9 [10]
 91 
 on: December 13, 2013, 05:02:33 PM 
Started by amjohns - Last post by melboy
Yes the logs look good. With no malware related symptoms, and neither MSE or MBAM detecting anything I don't see any reason to do any further scans if you're happy.

I would consider using an alternative browser to IE8.

OTL by OldTimer


  • Double-click OTL.exe
  • Click the CleanUp! button
  • Select Yes when the Begin cleanup Process? Prompt appears
  • If you are prompted to Reboot during the cleanup, select Yes
  • The tool will delete itself once it finishes, if not delete it by yourself

 92 
 on: December 13, 2013, 04:55:08 PM 
Started by amjohns - Last post by amjohns
IE is a little delayed but seems normal for the spedd processor in it.
I appreciate the help. THis laptop is for an underprivilidged high school student. Im doing all the work for free. Wanted to make sure its as tight as I can get it. (to minimize my re-involvement! If possible.)

If you're happy with the logs then I surely am!

 93 
 on: December 13, 2013, 04:51:43 PM 
Started by amjohns - Last post by melboy
Good. What's it running like now?

 94 
 on: December 13, 2013, 04:49:47 PM 
Started by amjohns - Last post by amjohns
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2D51D869-C36B-42BD-AE68-0A81BC771FA5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D51D869-C36B-42BD-AE68-0A81BC771FA5}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7BED0340-176B-44BC-915E-C21C1DD6F617} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7BED0340-176B-44BC-915E-C21C1DD6F617}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Alcmtr deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AzMixerSel deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ISBMgr.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Mouse Suite 98 Daemon deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NvCplDaemon deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\RealTray deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\TVTunerLib deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\VAIO Update 2 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\VZRemoteCommander deleted successfully.
========== FILES ==========
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 416 bytes
->Temporary Internet Files folder emptied: 1249152 bytes
->Java cache emptied: 968103 bytes
->Flash cache emptied: 348 bytes
 
User: All Users
 
User: Bruce Hartman
->Temp folder emptied: 3133699 bytes
->Temporary Internet Files folder emptied: 34988241 bytes
->Java cache emptied: 2150650 bytes
->FireFox cache emptied: 2573629 bytes
->Flash cache emptied: 1113274 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49152 bytes
 
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: NetworkService
->Temp folder emptied: 491476 bytes
->Temporary Internet Files folder emptied: 155602 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 4375057 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 263707 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 67792 bytes
 
Total Files Cleaned = 49.00 mb
 
Restore point Set: OTL Restore Point
 
OTL by OldTimer - Version 3.2.69.0 log created on 12132013_164323

Files\Folders moved on Reboot...
C:\Documents and Settings\Bruce Hartman\Local Settings\Temp\JavaDeployReg.log moved successfully.
File\Folder C:\Documents and Settings\Bruce Hartman\Local Settings\Temp\~DF3D25.tmp not found!
File\Folder C:\Documents and Settings\Bruce Hartman\Local Settings\Temp\~DF3E2B.tmp not found!
File\Folder C:\Documents and Settings\Bruce Hartman\Local Settings\Temp\~DF3EDB.tmp not found!
File\Folder C:\Documents and Settings\Bruce Hartman\Local Settings\Temp\~DF3EEA.tmp not found!
File\Folder C:\Documents and Settings\Bruce Hartman\Local Settings\Temporary Internet Files\Content.IE5\L9M8VVFQ\aclk[2].htm not found!
C:\Documents and Settings\Bruce Hartman\Local Settings\Temporary Internet Files\Content.IE5\L9M8VVFQ\adsCAH3PHES.htm moved successfully.
C:\Documents and Settings\Bruce Hartman\Local Settings\Temporary Internet Files\Content.IE5\HJ5UC93M\cleardot[8].gif moved successfully.
C:\Documents and Settings\Bruce Hartman\Local Settings\Temporary Internet Files\Content.IE5\HJ5UC93M\indexCAM4XUH6.htm moved successfully.
C:\Documents and Settings\Bruce Hartman\Local Settings\Temporary Internet Files\Content.IE5\AUQSNJCV\zrt_lookup[1].html moved successfully.
C:\Documents and Settings\Bruce Hartman\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Documents and Settings\Bruce Hartman\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_48c.dat not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

 95 
 on: December 13, 2013, 04:49:18 PM 
Started by amjohns - Last post by melboy
If otl asks, click ok and allow otl to reboot the machine rather than you doing it manually.

 96 
 on: December 13, 2013, 04:46:46 PM 
Started by amjohns - Last post by amjohns
I think I have it now...rebooting again.
yep i got it now. logs coming.

 97 
 on: December 13, 2013, 04:29:20 PM 
Started by amjohns - Last post by melboy
OTL wont be able to shut down mbamservice if it was running - Did you uncheck start with windows?

See if you can start Task Manager (CTRL + ALT + DELETE) & shut down.

 98 
 on: December 13, 2013, 04:26:14 PM 
Started by amjohns - Last post by amjohns
I think its locked up...

 99 
 on: December 13, 2013, 04:22:48 PM 
Started by amjohns - Last post by amjohns
When i rebooted it the two mbam real time protections were re-enabled. So I unchecked them again pasted the code and ran it. Lost the task bar and desktop icons and OTL says Killing processes Do not inturrupt...

 100 
 on: December 13, 2013, 03:03:06 PM 
Started by amjohns - Last post by melboy
Hi

Disable Malwarebytes' Anti-malware (mbam)
 
We need to disable mbam's realtime protection so it doesn't interfere with any fixes.

  • Right click the mbam system tray icon
  • Uncheck Filesystem Protection & Website Blocking
  • Uncheck Start with windows
  • Reboot your computer for the changes to take effect.
.

We need to run an OTL Fix

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the textbox. Do not include the word Code
Code:
:commands
[CREATERESTOREPOINT]

:otl
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2D51D869-C36B-42BD-AE68-0A81BC771FA5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7BED0340-176B-44BC-915E-C21C1DD6F617} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alcmtr"=-
"AzMixerSel"=-
"ISBMgr.exe"=-
"Mouse Suite 98 Daemon"=-
"NvCplDaemon"=-
"RealTray"=-
"TVTunerLib"=-
"VAIO Update 2"=-
"VZRemoteCommander"=-

:files
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

:commands
[EMPTYTEMP]
[CREATERESTOREPOINT]
  • Then click the Run Fix button at the top.
  • Click .
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

Pages: 1 ... 8 9 [10]

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!