1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Google redirect / rootkit suspected

Discussion in 'Malware and Virus Removal Archive' started by MattC, 2011/01/05.

  1. 2011/01/19
    MattC

    MattC Inactive Thread Starter

    Joined:
    2011/01/05
    Messages:
    18
    Likes Received:
    0
    Ok, now my free disk space has gone down from 50 so gigs at the start when i was infected to 16 gigs? Is that a bug?

    OTL system restore point fix log:
    All processes killed
    Error: Unable to interpret <[emptytemp]> in the current context!
    Error: Unable to interpret <[EMPTYFLASH]> in the current context!
    Error: Unable to interpret <[CLEARALLRESTOREPOINTS]> in the current context!
    Error: Unable to interpret <[Reboot]> in the current context!

    OTL by OldTimer - Version 3.2.20.1 log created on 01192011_222831

    Files\Folders moved on Reboot...
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A4BIG7KE\97174-active-google-redirect-rootkit-suspected-2[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A4BIG7KE\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A4BIG7KE\p-01-0VIaSjnOLg[2].gif moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4ONYLZQ0\00b42e3a-b809-49b2-b433-cc45b2bc89d33rd_party_BBS[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4ONYLZQ0\cm[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\085PU7MW\ads[3].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\085PU7MW\private[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.
    File\Folder C:\Windows\temp\mcmsc_ejHKQdqLXJxCLUP not found!
    C:\Windows\temp\sqlite_dSoQg8myAypMOj9 moved successfully.

    Registry entries deleted on Reboot...
     
  2. 2011/01/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It looks like you ran the last OTL script incorrectly.
    Most likely, you didn't copy a whole script, especially a "colon" in front of "OTL" (1st line).
    Please, redo.
    Resetting restore points is very important.
     

  3. to hide this advert.

  4. 2011/01/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    The issue seems to be resolved.
     
  5. 2011/01/27
    MattC

    MattC Inactive Thread Starter

    Joined:
    2011/01/05
    Messages:
    18
    Likes Received:
    0
    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: freenet
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Guest
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Lyndon
    ->Temp folder emptied: 183902 bytes
    ->Temporary Internet Files folder emptied: 4151202 bytes
    ->Java cache emptied: 7929 bytes
    ->FireFox cache emptied: 277317377 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 32281 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 12158 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 269.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: freenet

    User: Guest
    ->Flash cache emptied: 0 bytes

    User: Lyndon
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.20.1 log created on 01272011_210724

    Files\Folders moved on Reboot...
    File\Folder C:\Users\Lyndon\AppData\Local\Temp\~DF6834.tmp not found!
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Z8WO94SW\00b42e3a-b809-49b2-b433-cc45b2bc89d33rd_party_BBS[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Z8WO94SW\drts[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Z8WO94SW\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ENGT31GP\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DXMBKKXS\97174-resolved-google-redirect-rootkit-suspected-2[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DXMBKKXS\ads[2].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DXMBKKXS\cm[1].htm moved successfully.
    C:\Users\Lyndon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.
    File\Folder C:\Windows\temp\mcafee_YuNrnoSSN4fEW2p not found!
    File\Folder C:\Windows\temp\mcmsc_BizNAuJEGq8ta0S not found!
    File\Folder C:\Windows\temp\mcmsc_egQiQDowZ2BDCNm not found!
    C:\Windows\temp\sqlite_6BeN82YxVz43LPf moved successfully.
    C:\Windows\temp\sqlite_b8fPzI4YDTTXwEr moved successfully.
    File\Folder C:\Windows\temp\sqlite_M6hwOMmRb7k7udr not found!

    Registry entries deleted on Reboot...
     
  6. 2011/01/27
    MattC

    MattC Inactive Thread Starter

    Joined:
    2011/01/05
    Messages:
    18
    Likes Received:
    0
    Sorry, I was busy - I ran the OTL script again, not sure if it worked?
     
  7. 2011/01/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  8. 2011/01/30
    MattC

    MattC Inactive Thread Starter

    Joined:
    2011/01/05
    Messages:
    18
    Likes Received:
    0
    Ok, I've done that and run the OTL cleanup.

    Thanks very much for your help - much appreciated :)
     
  9. 2011/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.