1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved This Machine is Possessed!

Discussion in 'Malware and Virus Removal Archive' started by Blue Star, 2010/09/18.

  1. 2010/09/19
    Blue Star

    Blue Star Well-Known Member Thread Starter

    Joined:
    2010/03/25
    Messages:
    454
    Likes Received:
    2
    thought I had uninstalled it... will do now.

    will get the rest done as soon as I finish dinner.... thanks!
     
  2. 2010/09/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If it's not listed in Add\Remove, simply delete its folder:
    - C:\Program Files\iWonEI
     

  3. to hide this advert.

  4. 2010/09/19
    Blue Star

    Blue Star Well-Known Member Thread Starter

    Joined:
    2010/03/25
    Messages:
    454
    Likes Received:
    2
    thanks, I had to go to program files...

    otl..

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Owner
    ->Temp folder emptied: 108788317 bytes
    ->Temporary Internet Files folder emptied: 8704163 bytes
    ->Java cache emptied: 128101 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 766 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 4516 bytes
    RecycleBin emptied: 282936 bytes

    Total Files Cleaned = 112.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Owner
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.14.0 log created on 09192010_204403

    Files\Folders moved on Reboot...
    File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2823.tmp not found!
    File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2847.tmp not found!
    File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2891.tmp not found!
    File\Folder C:\Users\Owner\AppData\Local\Temp\~DF289D.tmp not found!
    File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2955.tmp not found!
    File\Folder C:\Users\Owner\AppData\Local\Temp\~DF2977.tmp not found!
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W840BWQB\95247-active-machine-possessed-3[1].html moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RAK2AKET\ads[3].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HQEXM600\iframescript[2].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

    Registry entries deleted on Reboot...
     
  5. 2010/09/19
    Blue Star

    Blue Star Well-Known Member Thread Starter

    Joined:
    2010/03/25
    Messages:
    454
    Likes Received:
    2
    I thank you a million Swedish fish, Broni!!!

    Machine is fully exorcised and running smoothly....:D

    Just wondering if these types of infections leave any "scars" on the hardware?

    May be a dumb question, but just wondering!

    Just as soon as I get back to a regular income, I will gladly donate! Unfortunately I have been out of steady work for 9 months. I am an architectural designer in Florida.... that's like 2 strikes against me! hahaha....

    We used to rib a friend of ours back in high school who used to work 3rd shift in an obscure room full of mysterious tape winders and such... he retired at 45 and now does consulting work... the only guy from our class who is a self-made millionaire!!!

    If only........ (sigh!)
     
  6. 2010/09/19
    Blue Star

    Blue Star Well-Known Member Thread Starter

    Joined:
    2010/03/25
    Messages:
    454
    Likes Received:
    2
    P.S..... thanks to the house guest who dl games and bittorrent..... next time, no access!!! lol
     
  7. 2010/09/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    J
    Bad guys are not THAT good yet.....LOL

    Anyway....good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.