RogueKiller V6.2.4 [01/12/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
http://www.geekstogo.com/forum/files/file/413-roguekiller/Blog:
http://tigzyrk.blogspot.comOperating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Ib'nallah S. Kazi [Admin rights]
Mode: Remove -- Date : 01/12/2012 18:59:55
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 3 ¤¤¤
[SUSP PATH] HKLM\[...]\Run : sysldtray (c:\windows\ld14.exe) -> DELETED
[HJ] HKCU\[...]\Internet Settings : WarnOnHTTPSToHTTPRedirect (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 53e7b07659b93c0437ba19853a5d540f
[BSP] bf833c2b32163e0278795a9bfcde2e26 : MBR Code unknown
Partition table:
0 - [XXXXXX] FAT16 [HIDDEN!] Offset (sectors): 63 | Size: 49 Mo
1 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 96390 | Size: 71601 Mo
2 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 139958280 | Size: 22693 Mo
3 - [XXXXXX] FAT32 [HIDDEN!] Offset (sectors): 184281615 | Size: 4170 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
------------------------------------------------------------------------------
OTL FIX
All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA\ deleted successfully.
C:\Program Files\DNA\plugins\npbtdna.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3712858782-641482404-3383758800-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93}\ not found.
Registry value HKEY_USERS\S-1-5-21-3712858782-641482404-3383758800-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22}\ not found.
Registry value HKEY_USERS\S-1-5-21-3712858782-641482404-3383758800-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sysldtray deleted successfully.
Starting removal of ActiveX control {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found.
File oft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
ADS C:\WINDOWS\System32\ctfmon.exe:SummaryInformation deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\DNA\btdna.exe deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Ib'nallah S. Kazi\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Ib'nallah S. Kazi\Desktop\cmd.txt deleted successfully.
C:\Program Files\DNA\plugins folder moved successfully.
C:\Program Files\DNA folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9Plus folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\UserShell folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\Welcome\BH00 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\Welcome folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology folder moved successfully.
C:\Documents and Settings\All Users\Application Data\Viewpoint folder moved successfully.
C:\Documents and Settings\Ib'nallah S. Kazi\Application Data\uTorrent folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: Default User
->Temp folder emptied: 59964 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 41044 bytes
User: Ib'nallah S. Kazi
->Temp folder emptied: 1236660973 bytes
->Temporary Internet Files folder emptied: 85664986 bytes
->Java cache emptied: 60232282 bytes
->FireFox cache emptied: 50195531 bytes
->Google Chrome cache emptied: 66564542 bytes
->Apple Safari cache emptied: 82505728 bytes
->Flash cache emptied: 2162252 bytes
User: IB'NAL~1~KAZ
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 2888628 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 45164302 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 781476 bytes
%systemroot%\System32 .tmp files removed: 6286865 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2090859089 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 213500439 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 4893321 bytes
Total Files Cleaned = 3,766.00 mb
Restore point Set: OTL Restore Point (0)
OTL by OldTimer - Version 3.2.31.0 log created on 01132012_170857
Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{a161c2c8-7a2a-42f3-848f-30fa5997642c}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxVideoCodec.pkg\Contents\Resources\English.lproj\3ivxVideoCodec.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{a161c2c8-7a2a-42f3-848f-30fa5997642c}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxVideoCodec.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{a161c2c8-7a2a-42f3-848f-30fa5997642c}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxUninstaller.pkg\Contents\Resources\English.lproj\3ivxUninstaller.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{a161c2c8-7a2a-42f3-848f-30fa5997642c}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxUninstaller.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{a161c2c8-7a2a-42f3-848f-30fa5997642c}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\3ivxAppLinks.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{a161c2c8-7a2a-42f3-848f-30fa5997642c}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{a161c2c8-7a2a-42f3-848f-30fa5997642c}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\InstallationCheck.strings not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{6a5d8d0b-6592-4129-b1ea-19cd73d4501b}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxVideoCodec.pkg\Contents\Resources\English.lproj\3ivxVideoCodec.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{6a5d8d0b-6592-4129-b1ea-19cd73d4501b}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxVideoCodec.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{6a5d8d0b-6592-4129-b1ea-19cd73d4501b}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxUninstaller.pkg\Contents\Resources\English.lproj\3ivxUninstaller.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{6a5d8d0b-6592-4129-b1ea-19cd73d4501b}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxUninstaller.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{6a5d8d0b-6592-4129-b1ea-19cd73d4501b}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\3ivxAppLinks.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{6a5d8d0b-6592-4129-b1ea-19cd73d4501b}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{6a5d8d0b-6592-4129-b1ea-19cd73d4501b}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\InstallationCheck.strings not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{21bdd344-b291-416a-b4a3-e58a854655a6}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxVideoCodec.pkg\Contents\Resources\English.lproj\3ivxVideoCodec.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{21bdd344-b291-416a-b4a3-e58a854655a6}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxVideoCodec.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{21bdd344-b291-416a-b4a3-e58a854655a6}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxUninstaller.pkg\Contents\Resources\English.lproj\3ivxUninstaller.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{21bdd344-b291-416a-b4a3-e58a854655a6}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxUninstaller.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{21bdd344-b291-416a-b4a3-e58a854655a6}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\3ivxAppLinks.info not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{21bdd344-b291-416a-b4a3-e58a854655a6}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\Description.plist not found!
File\Folder C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\{21bdd344-b291-416a-b4a3-e58a854655a6}\Start FlipShare.app\Contents\Resources\Install 3ivx MPEG-4 Decoder.mpkg\Contents\Packages\3ivxAppLinks.pkg\Contents\Resources\English.lproj\InstallationCheck.strings not found!
C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\clclean.0001.dir.0041\~df394b.tmp moved successfully.
C:\Documents and Settings\Ib'nallah S. Kazi\Local Settings\Temp\clclean.0001.dir.0041\~efe2.tmp moved successfully.
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_864.dat not found!
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_ee8.dat not found!
Registry entries deleted on Reboot...
------------------------------------------------------------------------------------------
ESET Scan
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WildTangent55.zip Win32/Bagle.gen.zip worm
C:\Documents and Settings\Ib'nallah S. Kazi\Desktop\Folders\Unused Desktop Shortcuts\Nero-8.3.2.1_eng_trial.exe Win32/Toolbar.AskSBar application
F:\Maxtor backup\ESU\C\Documents and Settings\Ib'nallah S. Kazi\Desktop\Unused Desktop Shortcuts\Nero-8.3.2.1_eng_trial.exe Win32/Toolbar.AskSBar application
-----------------------------------------------------------------------------------------
Security Check
Results of screen317's Security Check version 0.99.30
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check: Windows Firewall Disabled!
avast! Free Antivirus
ESET Online Scanner v3
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check: Spybot - Search & Destroy
HijackThis 2.0.2
CCleaner (remove only)
Java(TM) 6 Update 29
Java 2 Runtime Environment, SE v1.4.2_03
Java version out of date! Adobe Flash Player 10.1.102.64
Flash Player out of Date! Adobe Reader 9
Adobe Reader out of date! Mozilla Firefox (9.0.1)
````````````````````````````````
Process Check:
objlist.exe by Laurent Alwil Software Avast5 AvastSvc.exe
ALWILS~1 Avast5 avastUI.exe
``````````End of Log````````````