1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved javascript exploit and rootkit

Discussion in 'Malware and Virus Removal Archive' started by Oh Great, 2011/09/05.

  1. 2011/09/11
    Oh Great

    Oh Great Inactive Thread Starter

    Joined:
    2006/06/04
    Messages:
    50
    Likes Received:
    0
    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: All Users

    User: Compaq_Owner
    ->Temp folder emptied: 2257231 bytes
    ->Temporary Internet Files folder emptied: 46694470 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 71454643 bytes
    ->Flash cache emptied: 1400 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 1062312 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: NetworkService
    ->Temp folder emptied: 994744 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1083460 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 103030417 bytes

    Total Files Cleaned = 216.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Compaq_Owner
    ->Flash cache emptied: 0 bytes

    User: Default User

    User: LocalService

    User: NetworkService

    Total Flash Files Cleaned = 0.00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.27.0 log created on 09122011_070253

    Files\Folders moved on Reboot...
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DF139F.tmp moved successfully.
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\RP1LYESB\ads[3].htm moved successfully.
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\L9MEJ84O\00b42e3a-b809-49b2-b433-cc45b2bc89d33rd_party_BBS[2].htm moved successfully.
    File\Folder C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\L9MEJ84O\like[1].htm not found!
    File\Folder C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\L9MEJ84O\p-01-0VIaSjnOLg[1].gif not found!
    File\Folder C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\AAOUGBDG\100208-active-javascript-exploit-rootkit-3[1].html not found!
    File\Folder C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\AAOUGBDG\p-01-0VIaSjnOLg[1].gif not found!
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
    File\Folder C:\WINDOWS\temp\ZLT00a03.TMP not found!

    Registry entries deleted on Reboot...
     
  2. 2011/09/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Whenever ready....
     

  3. to hide this advert.

  4. 2011/09/11
    Oh Great

    Oh Great Inactive Thread Starter

    Joined:
    2006/06/04
    Messages:
    50
    Likes Received:
    0
    Sorry broni, in a rush this morning

    Computer seems to be running well, not sure about windows update. There are two updates that always fail, been there for a while.

    Some apps now won't run because Java not there so will need to sort that out asap.

    Was going to start a new thread re Java as it seemed the right thing to do...not really malware problem. Just waiting for your confirmation. Should it be in the Windows XP area? seems the right place to me, might resolve the update problem at the same time

    Thanks for all your help
     
  5. 2011/09/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome [​IMG]

    Yes.

    Good luck!
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.