All processes killed
========== OTL ==========
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File C:\WINDOWS\System32\hidserv.dll File not found not found.
Service a4ouufdhfaaqoet stopped successfully!
Service a4ouufdhfaaqoet deleted successfully!
File C:\WINDOWS\System32\koocucah.exe File not found not found.
Service nodpelcl stopped successfully!
Service nodpelcl deleted successfully!
C:\WINDOWS\system32\drivers\nodpelcl.sys moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\TaskMan:C:\Documents and Settings\Administrator\Application Data\nsvb.exe deleted successfully.
C:\Documents and Settings\Administrator\Application Data\nsvb.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-854245398-113007714-1417001333-500\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Administrator\Application Data\nsvb.exe deleted successfully.
File C:\Documents and Settings\Administrator\Application Data\nsvb.exe not found.
Registry value HKEY_USERS\S-1-5-21-854245398-113007714-1417001333-500\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Administrator\Application Data\juzjf.exe deleted successfully.
C:\Documents and Settings\Administrator\Application Data\juzjf.exe moved successfully.
C:\WINDOWS\System32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot2 folder moved successfully.
C:\WINDOWS\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot folder moved successfully.
File C:\WINDOWS\System32\drivers\nodpelcl.sys not found.
C:\WINDOWS\system32\drivers\lxxy.sys moved successfully.
File C:\Documents and Settings\Administrator\Application Data\juzjf.exe not found.
File C:\Documents and Settings\Administrator\Application Data\nsvb.exe not found.
File C:\WINDOWS\System32\drivers\lxxy.sys not found.
File C:\WINDOWS\System32\drivers\nodpelcl.sys not found.
File C:\Documents and Settings\Administrator\Application Data\juzjf.exe not found.
File C:\Documents and Settings\Administrator\Application Data\nsvb.exe not found.
File C:\Documents and Settings\Administrator\Application Data\juzjf.exe not found.
ADS C:\WINDOWS\Temp:temp deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\drivers\nodpelcl.sys not found.
File\Folder C:\WINDOWS\System32\drivers\lxxy.sys not found.
C:\RECYCLER\S-1-5-21-854245398-113007714-1417001333-500 folder moved successfully.
C:\RECYCLER\S-1-5-21-2604730624-7177754492-070583459-4676 folder moved successfully.
C:\RECYCLER folder moved successfully.
D:\RECYCLER\S-1-5-21-854245398-113007714-1417001333-500 folder moved successfully.
D:\RECYCLER folder moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\System32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYFLASH]
User: Administrator
->Flash cache emptied: 849 bytes
User: All Users
User: Default User
User: LocalService
User: NetworkService
Total Flash Files Cleaned = 0,00 mb
Restore points cleared and new OTL Restore Point set!
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 11066165 bytes
->Temporary Internet Files folder emptied: 137907 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 70598218 bytes
->Flash cache emptied: 0 bytes
All processes killed
========== OTL ==========
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File C:\WINDOWS\System32\hidserv.dll File not found not found.
Service a4ouufdhfaaqoet stopped successfully!
Service a4ouufdhfaaqoet deleted successfully!
File C:\WINDOWS\System32\koocucah.exe File not found not found.
Service nodpelcl stopped successfully!
Service nodpelcl deleted successfully!
C:\WINDOWS\system32\drivers\nodpelcl.sys moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\TaskMan:C:\Documents and Settings\Administrator\Application Data\nsvb.exe deleted successfully.
C:\Documents and Settings\Administrator\Application Data\nsvb.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-854245398-113007714-1417001333-500\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Administrator\Application Data\nsvb.exe deleted successfully.
File C:\Documents and Settings\Administrator\Application Data\nsvb.exe not found.
Registry value HKEY_USERS\S-1-5-21-854245398-113007714-1417001333-500\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Documents and Settings\Administrator\Application Data\juzjf.exe deleted successfully.
C:\Documents and Settings\Administrator\Application Data\juzjf.exe moved successfully.
C:\WINDOWS\System32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot2 folder moved successfully.
C:\WINDOWS\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE} folder moved successfully.
C:\WINDOWS\System32\CatRoot folder moved successfully.
File C:\WINDOWS\System32\drivers\nodpelcl.sys not found.
C:\WINDOWS\system32\drivers\lxxy.sys moved successfully.
File C:\Documents and Settings\Administrator\Application Data\juzjf.exe not found.
File C:\Documents and Settings\Administrator\Application Data\nsvb.exe not found.
File C:\WINDOWS\System32\drivers\lxxy.sys not found.
File C:\WINDOWS\System32\drivers\nodpelcl.sys not found.
File C:\Documents and Settings\Administrator\Application Data\juzjf.exe not found.
File C:\Documents and Settings\Administrator\Application Data\nsvb.exe not found.
File C:\Documents and Settings\Administrator\Application Data\juzjf.exe not found.
ADS C:\WINDOWS\Temp:temp deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\drivers\nodpelcl.sys not found.
File\Folder C:\WINDOWS\System32\drivers\lxxy.sys not found.
C:\RECYCLER\S-1-5-21-854245398-113007714-1417001333-500 folder moved successfully.
C:\RECYCLER\S-1-5-21-2604730624-7177754492-070583459-4676 folder moved successfully.
C:\RECYCLER folder moved successfully.
D:\RECYCLER\S-1-5-21-854245398-113007714-1417001333-500 folder moved successfully.
D:\RECYCLER folder moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Administrator\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Administrator\Desktop\cmd.txt deleted successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\System32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYFLASH]
User: Administrator
->Flash cache emptied: 849 bytes
User: All Users
User: Default User
User: LocalService
User: NetworkService
Total Flash Files Cleaned = 0,00 mb
Restore points cleared and new OTL Restore Point set!
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 11066165 bytes
->Temporary Internet Files folder emptied: 137907 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 70598218 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 36515 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 78,00 mb
OTL by OldTimer - Version 3.2.17.3 log created on 12112010_125415
Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...