OTL fixAll processes killed
========== COMMANDS ==========
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: Krystine
->Flash cache emptied: 1850 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Krystine
->Temp folder emptied: 12614504 bytes
->Temporary Internet Files folder emptied: 2750948 bytes
->Java cache emptied: 128020 bytes
->FireFox cache emptied: 92133448 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 69396 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 661859 bytes
Total Files Cleaned = 103.00 mb
OTL by OldTimer - Version 3.2.11.0 log created on 09012010_180850
Files\Folders moved on Reboot...
C:\Users\Krystine\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot...
SuperAntiSpyware logSUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 09/01/2010 at 07:00 PM
Application Version : 4.42.1000
Core Rules Database Version : 5410
Trace Rules Database Version: 3222
Scan type : Complete Scan
Total Scan Time : 00:42:49
Memory items scanned : 775
Memory threats detected : 0
Registry items scanned : 12953
Registry threats detected : 10
File items scanned : 104174
File threats detected : 79
Adware.Tracking Cookie
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][2].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\krystine@atdmt[7].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\krystine@atdmt[1].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\krystine@atdmt[2].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\krystine@atdmt[3].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\krystine@atdmt[5].txt
C:\Users\Krystine\AppData\Roaming\Microsoft\Windows\Cookies\krystine@atdmt[6].txt
.adcloudmedia.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.tribalfusion.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.bs.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.serving-sys.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.insight.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.insight.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.insight.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.insight.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.insight.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.chitika.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
bridge2.admarketplace.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.admarketplace.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.nhl.112.2o7.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.myroitracking.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.clicksor.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.clicksor.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.clicksor.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.clicksor.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.clicksor.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.kontera.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.specificclick.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.kaspersky.122.2o7.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.specificclick.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.interclick.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.interclick.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.interclick.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.advertise.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.dmtracker.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.revsci.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.revsci.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.revsci.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.revsci.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.smartadserver.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.smartadserver.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.collective-media.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.collective-media.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.collective-media.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.collective-media.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.smartadserver.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.smartadserver.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.tacoda.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.tacoda.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.tacoda.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.tacoda.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.xiti.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.at.atwola.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.at.atwola.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.invitemedia.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.invitemedia.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.adbrite.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.adbrite.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.invitemedia.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.kontera.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.kontera.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.adserver.adtechus.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.content.yieldmanager.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.stopzilla.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.stopzilla.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
.stopzilla.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
sdesapio-conversiontracker.appspot.com [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
xml.trafficengine.net [ C:\Users\Krystine\AppData\Roaming\Mozilla\Firefox\Profiles\y53eic8b.default\cookies.sqlite ]
Trojan.DNS-Changer (Hi-Jacked DNS)
(x86) HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\INTERFACES\{72B5DE34-F39A-4EF6-B01A-8D412C817851}#NAMESERVER
(x86) HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS\INTERFACES\{E39CD003-0F32-4AEB-82C9-0000B1580326}#NAMESERVER
(x86) HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{72B5DE34-F39A-4EF6-B01A-8D412C817851}#NAMESERVER
(x86) HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS\INTERFACES\{E39CD003-0F32-4AEB-82C9-0000B1580326}#NAMESERVER
(x86) HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{72B5DE34-F39A-4EF6-B01A-8D412C817851}#NAMESERVER
(x86) HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{E39CD003-0F32-4AEB-82C9-0000B1580326}#NAMESERVER
(x86) HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS#NAMESERVER
(x86) HKLM\SYSTEM\CONTROLSET001\SERVICES\TCPIP\PARAMETERS#NAMESERVER
(x86) HKLM\SYSTEM\CONTROLSET002\SERVICES\TCPIP\PARAMETERS#NAMESERVER
Malware.Trace
(x86) HKU\S-1-5-21-3969533455-2505683156-2406357703-1001\SOFTWARE\XML
I just wanted to say thank you for taking all this time to help me. I would never have been able to do it myself. I'm going to see if my symptoms are still there, and if they're gone, I'm going to do the system restore thing you said on the last page.
Edited by krystine, 01 September 2010 - 05:23 PM.