Please analyze my free fixer log

10 views
Skip to first unread message

Grock

unread,
Jan 23, 2011, 6:59:00 PM1/23/11
to FreeFixer User Forum
FreeFixer v0.58 log
http://www.freefixer.com/
Operating system: Windows XP Service Pack 3
Log dated 2011-01-23 20:55


BootExecute
C:\WINDOWS\system32\utocheck.exe (file is missing)

Basic Internet Explorer settings
HKLM\..\Main, Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU\..\Desktop\General, Wallpaper = C:\Documents and Settings\Usuario
\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp

Registry Startups (2 whitelisted)
HKLM\..\Run, NvMediaCenter = RUNDLL32.EXE C:\WINDOWS
\system32\NvMcTray.dll,NvTaskbarInit
HKLM\..\Run, NvCplDaemon = RUNDLL32.EXE C:\WINDOWS
\system32\NvCpl.dll,NvStartup
HKLM\..\Run, IObit Security 360 = "C:\Archivos de programa\IObit\IObit
Security 360\IS360tray.exe" /autostart

Processes (18 whitelisted)
C:\Archivos de programa\IObit\IObit Security 360\IS360srv.exe
C:\Archivos de programa\TuneUp Utilities
2011\TuneUpUtilitiesService32.exe
C:\Archivos de programa\ZenOK\OnAccessAVService.exe
C:\Archivos de programa\ZenOK\zenservice.exe
C:\Archivos de programa\ZenOK\zen_wd.exe
C:\Archivos de programa\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Archivos de programa\ZenOK\zenok.exe
C:\Archivos de programa\IObit\IObit Security 360\IS360tray.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\IObit\IObit Security 360\is360.exe
C:\Archivos de programa\Pale Moon\palemoon.exe
C:\Archivos de programa\Pale Moon\plugin-container.exe
C:\Archivos de programa\FreeFixer\freefixer.exe

Application modules (65 whitelisted)
C:\Archivos de programa\IObit\IObit Security 360\IS360mon.dll
C:\WINDOWS\system32\uxtheme.dll

Services (27 whitelisted)
IS360service, IS360service, c:\archivos de programa\iobit\iobit
security 360\is360srv.exe
TuneUp.UtilitiesSvc, TuneUp Utilities Service, c:\archivos de programa
\tuneup utilities 2011\tuneuputilitiesservice32.exe
ZenOAScanner, ZenOAScanner, c:\archivos de programa\zenok
\onaccessavservice.exe
ZenService, ZenOK Service, c:\archivos de programa\zenok
\zenservice.exe
ZWD, ZWD, c:\archivos de programa\zenok\zen_wd.exe

Svchost.exe Modules (174 whitelisted)
C:\WINDOWS\system32\UxTheme.dll
C:\WINDOWS\System32\UxTheme.dll
c:\windows\system32\uxtuneup.dll

Explorer.exe Modules (113 whitelisted)
C:\WINDOWS\system32\UxTheme.dll
C:\Archivos de programa\IObit\IObit Security 360\IS360mon.dll
C:\Archivos de programa\Winrar\rarext.dll
C:\Archivos de programa\Unlocker\UnlockerCOM.dll
C:\Archivos de programa\IObit\IObit Security 360\IS360Ext.dll
C:\Archivos de programa\TuneUp Utilities 2011\SDShelEx-win32.dll
C:\Archivos de programa\ZenOK\zenshext.dll
C:\ARCHIV~1\AIMP2\System\aimp_shell.dll

Rundll Modules (25 whitelisted)
C:\WINDOWS\system32\UxTheme.dll
C:\WINDOWS\system32\NvMcTray.dll
C:\WINDOWS\system32\NVRSES.DLL

Winlogon.exe Modules (76 whitelisted)
C:\WINDOWS\system32\uxtheme.dll

Drivers (24 whitelisted)
AmdK8, AMD Processor Driver, C:\WINDOWS\system32\drivers\amdk8.sys
Tcpip, Controlador de protocolo TCP/IP, C:\WINDOWS\system32\drivers
\tcpip.sys

Windows XP Firewall authorized apps (2 whitelisted)
D:\Emule\emule.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe

Recently created/modified files (9 whitelisted)
16 hours, d:\Mz Ultimate Booster v5.0.0_Portable\Mz Ultimate Booster
\Native\STUBEXE\8.0.1135\@SYSTEM@\shutdown.exe
16 hours, d:\Mz Ultimate Booster v5.0.0_Portable\Mz Ultimate Booster
\Native\STUBEXE\8.0.1135\@SYSTEM@\defrag.exe
16 hours, d:\Mz Ultimate Booster v5.0.0_Portable\Mz Ultimate Booster
\Native\STUBEXE\8.0.1135\@SYSTEM@\sc.exe
16 hours, d:\Mz Ultimate Booster v5.0.0_Portable\Mz Ultimate Booster
\Virtual\STUBEXE\8.0.1135\@PROGRAMFILES@\Mz Ultimate Tools\Mz Ultimate
Booster\MzUltimateBooster.exe
16 hours, d:\Mz Ultimate Booster v5.0.0_Portable\Mz Ultimate Booster
\Virtual\MODIFIED\@PROGRAMFILES@\Mz Ultimate Tools\Mz Ultimate Booster
\MzUltimateBooster.exe
16 hours, d:\Mz Ultimate Booster v5.0.0_Portable\Mz Ultimate
Booster.exe
19 hours, c:\WINDOWS\Installer\{89F4137D-6C26-4A84-
BDB8-2E5A4BB71E00}\ConfigIcon.dll
2 days, c:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
2 days, c:\WINDOWS\MBR.exe
2 days, c:\WINDOWS\PEV.exe
2 days, c:\WINDOWS\SWREG.exe
2 days, c:\WINDOWS\zip.exe
2 days, c:\WINDOWS\grep.exe
2 days, c:\WINDOWS\sed.exe
2 days, c:\WINDOWS\SWSC.exe
2 days, c:\Documents and Settings\Usuario\Mis documentos\Downloads
\ComboFix.exe
6 days, c:\Documents and Settings\Usuario\Mis documentos\Downloads
\palemoon-3.6.13-installer.exe
6 days, c:\Documents and Settings\Usuario\Mis documentos\Downloads
\ZenOKSetup.exe
6 days, c:\Documents and Settings\Usuario\Mis documentos\Downloads
\elipatea.exe
6 days, c:\Documents and Settings\Usuario\Mis documentos\Downloads
\elipen.exe
6 days, c:\Documents and Settings\Usuario\Mis documentos\Downloads
\EliBaglA.exe

History
-HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser,
ITBar7Position

The following errors occurred during the scan:
An unexpected exception occurred in the AppInitDll plugin:
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Windows'.

System error message: Se está ejecutando la operación de E/S
superpuesta. Error code: 997.

End of FreeFixer log

Roger Karlsson

unread,
Jan 25, 2011, 4:07:44 PM1/25/11
to freefix...@googlegroups.com
Hello Grock

I've looked through the log and could not find anything suspicious. Does
your computer show any signs of an infection?

/Roger

End of FreeFixer log

--
You received this message because you are subscribed to the Google
Groups "FreeFixer User Forum" group. To post to this group, send email
to freefix...@googlegroups.com. To unsubscribe from this group,
send email to freefixer-for...@googlegroups.com.
For more options, visit this group at
http://groups.google.com/group/freefixer-forum?hl=en.

jerry

unread,
Jan 25, 2011, 5:41:56 AM1/25/11
to freefix...@googlegroups.com
This was sent to the wrong address:

On 1/23/2011 6:59 PM, Grock wrote:
> FreeFixer v0.58 log
> http://www.freefixer.com/
> Operating system: Windows XP Service Pack 3
> Log dated 2011-01-23 20:55
>
>
> BootExecute
> C:\WINDOWS\system32\utocheck.exe (file is missing)
>
> Basic Internet Explorer settings
> HKLM\..\Main, Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
> HKCU\..\Desktop\General, Wallpaper = C:\Documents and Settings\Usuario

> \Configuraci�n local\Datos de programa\Microsoft\Wallpaper1.bmp

> System error message: Se est� ejecutando la operaci�n de E/S

Roger Karlsson

unread,
Jan 25, 2011, 4:12:44 PM1/25/11
to freefix...@googlegroups.com
Hello Jerry,

You can edit you membership settings here:
http://groups.google.com/group/freefixer-forum/subscribe?hl=en_US

You can for example set it to "No Email - I will read this group on the
web".

Hope this helps.

/Roger

-----Original Message-----
From: freefix...@googlegroups.com
[mailto:freefix...@googlegroups.com] On Behalf Of jerry
Sent: den 25 januari 2011 11:42
To: freefix...@googlegroups.com
Subject: Re: Please analyze my free fixer log


This was sent to the wrong address:

On 1/23/2011 6:59 PM, Grock wrote:
> FreeFixer v0.58 log
> http://www.freefixer.com/
> Operating system: Windows XP Service Pack 3
> Log dated 2011-01-23 20:55
>
>
> BootExecute
> C:\WINDOWS\system32\utocheck.exe (file is missing)
>
> Basic Internet Explorer settings
> HKLM\..\Main, Default_Page_URL =
> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
> HKCU\..\Desktop\General, Wallpaper = C:\Documents and Settings\Usuario

> \Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp

> System error message: Se está ejecutando la operación de E/S

> superpuesta. Error code: 997.
>
> End of FreeFixer log
>

--

Reply all
Reply to author
Forward
0 new messages