0 Members and 1 Guest are viewing this topic.
:OTLIE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 97 55 DA 01 56 1C 31 4D BF A2 5A A9 6B A4 FE 29 [binary data]IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 97 55 DA 01 56 1C 31 4D BF A2 5A A9 6B A4 FE 29 [binary data]IE - HKU\S-1-5-21-4162686938-2645483614-3529793939-1000\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 97 55 DA 01 56 1C 31 4D BF A2 5A A9 6B A4 FE 29 [binary data][2011/12/18 17:17:00 | 000,009,074 | -HS- | M] () -- C:\Users\Eric\AppData\Local\evmleo8d3rmy2idp7gyy6i865k5d[2011/12/18 17:17:00 | 000,009,074 | -HS- | M] () -- C:\ProgramData\evmleo8d3rmy2idp7gyy6i865k5d[2011/12/18 01:56:23 | 000,009,582 | -HS- | M] () -- C:\Users\Eric\AppData\Local\0q61ci1o46h636[2011/12/18 01:56:23 | 000,009,582 | -HS- | M] () -- C:\ProgramData\0q61ci1o46h636[2011/01/16 15:55:21 | 000,255,488 | ---- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 -- C:\Users\Eric\AppData\Local\Temp\RarSFX0\procs\explorer.exe[2009/05/26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Eric\AppData\Local\Temp\RarSFX0\userinit.exe[2009/05/26 18:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Users\Eric\AppData\Local\Temp\RarSFX0\winlogon.exe:Reg[HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]XMLHTTP_UUID_Default=-[HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]XMLHTTP_UUID_Default=-[HKU\S-1-5-21-4162686938-2645483614-3529793939-1000\SOFTWARE\Microsoft\Internet Explorer\Main]XMLHTTP_UUID_Default=- :Filesipconfig /flushdns /c:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]
Just Open OTL and hit the cleanup buttonThis will remove all the tools essexboy used...further recommendations will come from essexboy soon..Copy paste the above in OTL custom scan box and hit run fix.