1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved spam, spyware, ...

Discussion in 'Malware and Virus Removal Archive' started by janwin7, 2011/04/07.

  1. 2011/04/11
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    last log

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Jan Rijken
    ->Temp folder emptied: 133643 bytes
    ->Temporary Internet Files folder emptied: 4025047 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 456 bytes

    User: LocalService
    ->Temp folder emptied: 285458393 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: software

    User: vreemde
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 483 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 276,00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default User

    User: Jan Rijken
    ->Flash cache emptied: 0 bytes

    User: LocalService

    User: NetworkService

    User: software

    User: vreemde

    Total Flash Files Cleaned = 0,00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.22.3 log created on 04112011_081846

    Files\Folders moved on Reboot...
    File\Folder C:\Documents and Settings\Jan Rijken\Local Settings\Temp\~DF857D.tmp not found!
    File\Folder C:\Documents and Settings\Jan Rijken\Local Settings\Temp\~DF8644.tmp not found!
    File\Folder C:\Documents and Settings\Jan Rijken\Local Settings\Temp\~DF8A8A.tmp not found!
    File\Folder C:\Documents and Settings\Jan Rijken\Local Settings\Temp\~DF8AC6.tmp not found!
    File\Folder C:\Documents and Settings\Jan Rijken\Local Settings\Temp\~DF8DB6.tmp not found!
    File\Folder C:\Documents and Settings\Jan Rijken\Local Settings\Temp\~DF8F37.tmp not found!
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\HKH7970Z\98577-active-spam-spyware-2[1].html moved successfully.
    File\Folder C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\HKH7970Z\ADSAdClient31[1].txt not found!
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\HKH7970Z\messengerscripttracking[1].aspx moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\E6TPCC6P\default[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\E6TPCC6P\HistoryFrame[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\E6TPCC6P\resourcespreload[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\E6TPCC6P\xmlProxy[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\6QBB59S6\InboxLight[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\0Y0K2OFG\adloader[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\0Y0K2OFG\LocalStorage[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\0Y0K2OFG\Messenger[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\0Y0K2OFG\WebIMPop[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\Content.IE5\0Y0K2OFG\xmlProxy[1].htm moved successfully.
    C:\Documents and Settings\Jan Rijken\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
    File\Folder C:\Documents and Settings\LocalService\Local Settings\Temp\nvcbin.def.6659469d.tmp not found!

    Registry entries deleted on Reboot...


    Thank you very much Broni!!!!:):)
    I go to work now.
     
  2. 2011/04/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)

    Good luck and stay safe :)
     

  3. to hide this advert.

  4. 2011/04/12
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    blocking and responding

    Hi Broni,

    My pc's are blocking continuously. I don't know if it has something to do with removing the spyware, ... Or is it messenger? Before removing the spyware my last pc was very fast but now he is slowing down. What can be done about it? For the netbook i ordered a new memorycard that i will receive on thursday. But he is also slowing down. The all are blocking most of the time. They didn't have it before. On the netbook sometimes i am still logged in on the web. Still spyware? Or again?
    Sorry to say.:mad:
     
  5. 2011/04/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    What do you mean by "blocking "?
     
  6. 2011/04/13
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    blocking

    Well, when i click on something it starts but it takes almost a minute to see the new page. It happens with messenger but also when i go to my startpage of the internet. With this pc i use XP and often i have to send microsoft a message about the problem. Maybe it has nothing to do with cleaning my pc. Since a week i have these problems. I don't know! Sorry.:confused:
     
  7. 2011/04/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Which browser does it?
     
  8. 2011/04/13
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    responding

    I use the internet explorer 8. This evening it took me almost 15 minutes before i could read your message. Norman was updating but in the past that was no prob. I could use the pc but now nothing happened at all. I also got a message on my screen that ... 'within jusched.exe an error occured and the program has to shut off. Send report'...Does it have something to do with java?
    When i wanna close down my screen it takes much time to close the page. Sometimes 5 minutes. I don't know what is really going on now.:mad:
     
  9. 2011/04/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  10. 2011/04/13
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    Ie 8

    Yes we are talking about IE 8. I think it's working for the XP. It seems speeding up already.
    Thank you. I will see for the windows 7 too. I let you know.:):)
     
  11. 2011/04/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very well :)
     
  12. 2011/04/14
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    secunia PSI

    Hi Broni, when i run secunia PSI it says that i have to update the microsoft visual C ++2005 redistributable package (x86). When i update it says: "The feature you want to use is on a network resource that is unavailable." I also have the microsoft visual C ++2008 redistributable package. The last one is up to date. What do i have to do about it? Ignore it or delete it?
    An other thing is that some of the icons on my taskbar aren't what they should be. They look like a very small white desktop with micro icons on it and a blue bar on top. It happened when i used sequoia view. Someone told me that i had to delete all of installer. So i did, but i think i deleted too much. Can we fix that too? Thanks!:)
     
  13. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It's not always easy to make Secunia 100% happy, so leave that "Visual C" alone.

    Did you do it after resetting system restore with OTL, or before?
     
  14. 2011/04/14
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    before:(
     
  15. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Can you post a screenshot of your taskbar?
     
  16. 2011/04/14
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    How do i have to do that? With a shedule?:confused:
     
  17. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    With the window open that you want to take the Screenshot of, press the Print Screen/SysRq Key (next to F12 on the keyboard).
    If you only want a screenshot of an active window within the main window press ALT+Print Screen/SysRq.

    Now open Microsoft Paint by pressing Start > All Programs > Accessories > Paint.

    This will open the Paint window.
    On the menu bar at the top left, click on Edit and select Paste. This will put your screenshot in the Paint window.

    Next, click File on the menu bar and click Save As.

    In the drop-down box that appears, where it shows File name replace the highlighted Untitled with a suitable name.
    In the Save as type box press the down arrow and select JPEG from the list of options.
    In the Save in box at the top press the down arrow and navigate to Desktop and select it then press Save at the bottom.

    Upload the file here: http://www.filedropper.com/
    Post download link.
     
  18. 2011/04/14
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    windows 7

    Is it different with windows 7? I guess!:confused:
     
  19. 2011/04/14
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    print screen

    The link is : http://www.filedropper.com/naamloos

    the embed code is: <a href=http://www.filedropper.com/naamloos><img src=http://www.filedropper.com/download_button.png width=127 height=145 border=0/></a><br /><div style=font-size:9px;font-family:Arial, Helvetica, sans-serif;width:127px;font-color:#44a854;> <a href=http://www.filedropper.com >share files free</a></div>

    :)
     
  20. 2011/04/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It looks like just some broken shortcuts.
    Right click on each one, click "Properties" and it should tell you what program they belong to.
    Let me know.
     
  21. 2011/04/15
    janwin7

    janwin7 Inactive Thread Starter

    Joined:
    2011/04/02
    Messages:
    154
    Likes Received:
    0
    icons

    it should be messenger, power point, excel and ovi suit from nokia. For now.:)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.