Windows, Operating System, Security, Networking, Malware, Support, Forum, Help Site Check Our Facebook Page!
Notices
Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.


Register your FREE account to unlock additional features at WindowsBBS.com
   
 
 
LinkBack Thread Tools
Old 19th September 2010   #31
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

just completed it....

All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Starting removal of ActiveX control {7530BFB8-7293-4D34-9923-61A11451AFC5}
C:\Windows\Downloaded Program Files\OnlineScanner.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell ExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 1613012 bytes
->Temporary Internet Files folder emptied: 242293360 bytes
->Java cache emptied: 862819 bytes
->Google Chrome cache emptied: 6145559 bytes
->Flash cache emptied: 123750 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1068051 bytes
RecycleBin emptied: 629000 bytes

Total Files Cleaned = 241.00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Owner
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.14.0 log created on 09192010_134943

Files\Folders moved on Reboot...
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF7814.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF781F.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF786C.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF7877.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF78AE.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF78B9.tmp not found!
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DTHKUAJ1\95247-active-machine-possessed-2[2].html moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8NYR3QZY\ads[3].htm moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4AG7LMJ2\iframescript[1].htm moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
File\Folder C:\Windows\temp\TMP00000001D8038B0925669E97 not found!

Registry entries deleted on Reboot...


running sec check now....

Blue Star is offline  
Old 19th September 2010   #32
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 20,151
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System
OK...go on...

broni is offline  
Old 19th September 2010   #33
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

Results of screen317's Security Check version 0.99.5
Windows Vista Service Pack 2 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Microsoft Security Essentials
WMI entry may not exist for antivirus; attempting automatic update.
Microsoft Security Essentials successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java(TM) 6 Update 21
Adobe Flash Player
Adobe Reader 9.3.4
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

Blue Star is offline  
Old 19th September 2010   #34
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 20,151
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System
Looks good

broni is offline  
Old 19th September 2010   #35
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

thanks...

running kaspersky next... guessing it will take a few hours... so tty soon!

Blue Star is offline  
Old 19th September 2010   #36
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 20,151
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System
Yes, I need some break....LOL

broni is offline  
Old 19th September 2010   #37
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

Thank you soooo much, so far Broni!!!

logging off and running kaspersky now...

Blue Star is offline  
Old 19th September 2010   #38
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 20,151
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System
You're very welcome

broni is offline  
Old 20th September 2010   #39
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

kaspersky.......

KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, September 19, 2010
Operating system: Microsoft Windows Vista Enterprise Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, September 19, 2010 15:51:48
Records in database: 4225486


Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes

Scan area My Computer
C:\
D:\
E:\
G:\

Scan statistics
Objects scanned 211856
Threats found 1
Infected objects found 1
Suspicious objects found 0
Scan duration 03:39:39

File name Threat Threats count
C:\Program Files\iWonEI\Installr\1.bin\jfEZSETP.dll Infected: not-a-virus:AdWare.Win32.FunWeb.fa 1

Selected area has been scanned.

Blue Star is offline  
Old 20th September 2010   #40
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 20,151
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System
Quote:
C:\Program Files\iWonEI\Installr\1.bin\jfEZSETP.dll
If you use iWon program, just be aware, it contains some adware.
If you don't use it, uninstall it.

Other than that....


Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure, Windows Updates are current.

4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC) weekly.

8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. Run defrag at your convenience.

11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

12. Please, let me know, how is your computer doing.

broni is offline  
Old 20th September 2010   #41
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

thought I had uninstalled it... will do now.

will get the rest done as soon as I finish dinner.... thanks!

Blue Star is offline  
Old 20th September 2010   #42
Malware Analyst
 
broni's Avatar
 
Profile:
Join Date: Aug 2002
Location: Daly City, CA
Posts: 20,151
Computer Experience:
intermediate
broni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Levelbroni Reputation Level

My System
If it's not listed in Add\Remove, simply delete its folder:
- C:\Program Files\iWonEI

broni is offline  
Old 20th September 2010   #43
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

thanks, I had to go to program files...

otl..

All processes killed
========== OTL ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 108788317 bytes
->Temporary Internet Files folder emptied: 8704163 bytes
->Java cache emptied: 128101 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 766 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4516 bytes
RecycleBin emptied: 282936 bytes

Total Files Cleaned = 112.00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Owner
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb



OTL by OldTimer - Version 3.2.14.0 log created on 09192010_204403

Files\Folders moved on Reboot...
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2823.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2847.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2891.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF289D.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2955.tmp not found!
File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2977.tmp not found!
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W840BWQB\95247-active-machine-possessed-3[1].html moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RAK2AKET\ads[3].htm moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HQEXM600\iframescript[2].htm moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

Registry entries deleted on Reboot...

Blue Star is offline  
Old 20th September 2010   #44
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

I thank you a million Swedish fish, Broni!!!

Machine is fully exorcised and running smoothly....

Just wondering if these types of infections leave any "scars" on the hardware?

May be a dumb question, but just wondering!

Just as soon as I get back to a regular income, I will gladly donate! Unfortunately I have been out of steady work for 9 months. I am an architectural designer in Florida.... that's like 2 strikes against me! hahaha....

We used to rib a friend of ours back in high school who used to work 3rd shift in an obscure room full of mysterious tape winders and such... he retired at 45 and now does consulting work... the only guy from our class who is a self-made millionaire!!!

If only........ (sigh!)

Blue Star is offline  
Old 20th September 2010   #45
Senior Member
THREAD STARTER
 
Blue Star's Avatar
 
Profile:
Join Date: Mar 2010
Location: South Florida
Posts: 295
Computer Experience:
Intermediate
Blue Star Reputation Level

P.S..... thanks to the house guest who dl games and bittorrent..... next time, no access!!! lol

Blue Star is offline  


 

THIS THREAD HAS EXPIRED.

Are you having the same problem? Please post a new thread, but first you'll have to join us by Registering (FREE).



Discussion Forums
Operating Systems
Windows 10 Windows 10
Windows 8 Windows 8
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Legacy Windows OS Legacy Windows OS
Internet & Networking
Networking (Hardware & Software) Networking
Internet Explorer Internet Explorer
Microsoft Mail Microsoft Mail
Firefox, Thunderbird & SeaMonkey Firefox, Thunderbird
      & SeaMonkey

Web Applications & Cloud Web Applications & Cloud
General Internet
Security
Malware and Virus Removal Malware and Virus
     Removal

Security and Privacy Security and Privacy

Other
Other PC Software Other PC Software
Test Posts Test Posts
Hardware
PC Hardware PC Hardware
Mobile Devices Mobile Devices
Community
Introductions Introductions
General Discussions General Discussions
Site Comments & Suggestions Site Comments
      & Suggestions

News News @ WindowsBBS

Thread Tools


Find us on Facebook   Web Of Trust Rating

All times are GMT. The time now is 22:27.


Recent Discussions
Event viewer item (0)
[Advice on replacement computer - f.. (1)
spinning circle follows curser (1)
facebook problem (2)
[Upgrading Vista to Windows 7?] (7)
Choosing fonts (1)
How opt out of google search relate.. (7)
Proxy server not responding (3)
Tray Icons Resetting Themselves Aft.. (2)
How to add Malwarebytes to the Righ.. (17)
FireFox now has a mind of its own (10)
System Information scan not possibl.. (3)
Print the Screen Only (8)
HP 15-f004wm Notebook - can not cha.. (7)
Windows 10 is Just Not Enough (even.. (0)
The connection was reset (2)
Win7 change user status (2)
Windows 10 Will Be a Free Upgrade f.. (16)
IE9 crashing (44)


Donate!
Support Windows BBS!



Powered by vBulletin® Copyright ©2000 - 2015, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO
Copyright © 2002 - 2015 WindowsBBS.com. All rights reserved.
FDMA Media LLC
Terms of Use, Legal Information & Privacy Policy
Page generated in 0.19262 seconds with 7 queries