1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Google Redirect Virus

Discussion in 'Malware and Virus Removal Archive' started by Action Hero, 2010/10/30.

  1. 2010/11/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Unfortunately, McAfee is know from false positive regarding some tools, we're using.
    Disable McAfee and try the download again.
     
  2. 2010/11/06
    Action Hero

    Action Hero Inactive Thread Starter

    Joined:
    2010/10/30
    Messages:
    52
    Likes Received:
    0
    All processes killed
    Error: Unable to interpret <Code:> in the current context!
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Gerry
    ->Temp folder emptied: 2697457 bytes
    ->Temporary Internet Files folder emptied: 3191586 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 456 bytes

    User: Lisa
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Lynne
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public

    User: SYSTEM

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 83153 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes
    RecycleBin emptied: 1369379 bytes

    Total Files Cleaned = 7.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default

    User: Default User

    User: Gerry
    ->Flash cache emptied: 0 bytes

    User: Lisa
    ->Flash cache emptied: 0 bytes

    User: Lynne
    ->Flash cache emptied: 0 bytes

    User: Public

    User: SYSTEM

    Total Flash Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.17.2 log created on 11062010_202412

    Files\Folders moved on Reboot...
    C:\Users\Gerry\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF01FB54085D781AC2.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF0434B65F2A7C008E.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF2528E13620C35DE8.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF364B8D617B3646B8.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF4417C806E81F45FC.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF4CEF79CAE4BB0D6A.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF5540BB7D06A72385.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DF805C6757D58F1669.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DFAEE78447DE7C8D0B.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DFB91C3759D3B7F0AA.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DFF282E61E2C45447C.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DFF63887FFC0731F5C.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DFF6E0A4B434555C76.TMP not found!
    File\Folder C:\Users\Gerry\AppData\Local\Temp\~DFFCDDB31CA73E1BEA.TMP not found!
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZTIBW8QH\audmeasure[1].gif moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZTIBW8QH\L[2].htm moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZTIBW8QH\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\R5JXOXTN\96006-active-google-redirect-virus[1].html moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\R5JXOXTN\ads[1].htm moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\R5JXOXTN\audmeasure[1].gif moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\R5JXOXTN\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FMOD5ID\iframescript[1].htm moved successfully.
    C:\Users\Gerry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3FMOD5ID\L[1].htm moved successfully.
    File\Folder C:\Windows\temp\mcmsc_6ir5cLwNuGwpKwp not found!
    File\Folder C:\Windows\temp\mcmsc_ybM1aKVAOfxhe3R not found!

    Registry entries deleted on Reboot...
     

  3. to hide this advert.

  4. 2010/11/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Ok.....
     
  5. 2010/11/06
    Action Hero

    Action Hero Inactive Thread Starter

    Joined:
    2010/10/30
    Messages:
    52
    Likes Received:
    0
    I'd like to post this thread resolved but I don't see the option on thread tools to do so. Is there something else I'm supposed to do?

    Thanks for all your help. Now I have to go fix my e-mail ....:)
     
  6. 2010/11/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm glad to see, we "broke" only one item during cleaning process and your computer is doing fine.

    In this forum, only I can mark a topic as resolved, which I'll gladly do.

    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.