<snip>
Also, Swarnava Sengupta (a Junior Member) sent me a PM saying the following:
"please reply me back..i will tell you the solution"
I cannot reply back to him being relatively a newb on here. Few posts and whatnot.
Registry Defender Platinum is a rogue registry cleaning program that is advertised via malware such as the Vundo Trojan. When infected with Vundo, pop-ups will be displayed that state your Windows Registry is corrupted and that you should download and install Registry Defender Platinum. If you decide to download and install the program it will be configured to start automatically when your computer turns on. When running, the program will perform a scan and state that you have numerous Windows Registry problems. It will not, though, allow you to fix these problems until you purchase the program. Even if the program was actually describing legitimate problems, we would never know. This is because it does not explicitly state what the problems are. Instead it just states you have a problem and asks you to spend money to fix it. Legitimate programs in this category, on the other hand, would provide specific details as to each problem that has been detected.
And secondly, I can't access Avast forums from my computer anymoreForum Down http://forum.avast.com/index.php?topic=65645.0
Webroot Desktop FirewallMy favorit Outpost free, almost fully automatic and that is why i like it http://free.agnitum.com/
And as far as I can tell I have not installed Regestry Defender.It is just that one of your images (viruspopup1) has registry defender displayed on it, it would normally first start as a driveby download, trying to get you download and install, etc.
:OTL
IE - HKU\S-1-5-21-3942227701-1679884542-3315011257-1006\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {2804caed-1d99-4a3d-833c-c552f986b75c} - No CLSID value found.
O2 - BHO: (no name) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - No CLSID value found.
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\system32\bae.dll (Gateway Inc.)
O2 - BHO: (no name) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - No CLSID value found.
O2 - BHO: (no name) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-3942227701-1679884542-3315011257-1006\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-3942227701-1679884542-3315011257-1006\..\Toolbar\WebBrowser: (no name) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No CLSID value found.
O3 - HKU\S-1-5-21-3942227701-1679884542-3315011257-1006\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKU\S-1-5-21-3942227701-1679884542-3315011257-1006\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Reg Error: Key error.)
[2010/06/12 23:50:07 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\jesterss.dll
:Files
ipconfig /flushdns /c
:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]
Windows Explorer is a file manager application that is included with releases of the Microsoft Windows operating system from Windows 95 onwards. It provides a graphical user interface for accessing the file systems. It is also the component of the operating system that presents many user interface items on the monitor such as the taskbar and desktop. Controlling the computer is possible without Windows Explorer running (for example, the File | Run command in Task Manager on NT-derived versions of Windows will function without it, as will commands typed in a command prompt window). It is sometimes referred to as the Windows Shell, explorer.exe, or simply “Explorer”.http://en.wikipedia.org/wiki/Windows_Explorer