1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved malware from oovoo

Discussion in 'Malware and Virus Removal Archive' started by molsonrn, 2011/02/02.

  1. 2011/02/12
    molsonrn

    molsonrn Inactive Thread Starter

    Joined:
    2010/02/08
    Messages:
    121
    Likes Received:
    0
    :)

    things are really good and i'm afraid to do anything now!
     
  2. 2011/02/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Proceed with my reply #31.
     

  3. to hide this advert.

  4. 2011/02/13
    molsonrn

    molsonrn Inactive Thread Starter

    Joined:
    2010/02/08
    Messages:
    121
    Likes Received:
    0
    otl

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 65748 bytes
    ->Temporary Internet Files folder emptied: 1278086 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 4079 bytes

    User: Melanie
    ->Temp folder emptied: 837320 bytes
    ->Temporary Internet Files folder emptied: 98528687 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 45007709 bytes
    ->Flash cache emptied: 2126 bytes

    User: NetworkService
    ->Temp folder emptied: 2968 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 49454 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 86610 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 53960022 bytes

    Total Files Cleaned = 191.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default User

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: Melanie
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.20.6 log created on 02132011_155634

    Files\Folders moved on Reboot...
    C:\Documents and Settings\Melanie\Local Settings\Temp\IadHide4.dll moved successfully.
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DF2F82.tmp not found!
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DF2F94.tmp not found!
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DF6AF2.tmp not found!
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DF6B06.tmp not found!
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DF712.tmp not found!
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DF76E.tmp not found!
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DFEF9.tmp not found!
    File\Folder C:\Documents and Settings\Melanie\Local Settings\Temp\~DFF22.tmp not found!
    C:\Documents and Settings\Melanie\Local Settings\Temporary Internet Files\Content.IE5\5689GZ6Z\iframescript[1].htm moved successfully.
    C:\Documents and Settings\Melanie\Local Settings\Temporary Internet Files\Content.IE5\5689GZ6Z\iframescript[3].htm moved successfully.
    C:\Documents and Settings\Melanie\Local Settings\Temporary Internet Files\Content.IE5\3CKJDQUL\97636-active-malware-oovoo-3[1].html moved successfully.
    C:\Documents and Settings\Melanie\Local Settings\Temporary Internet Files\Content.IE5\3CKJDQUL\vmus39814_iframe[1].htm moved successfully.
    C:\Documents and Settings\Melanie\Local Settings\Temporary Internet Files\Content.IE5\3CKJDQUL\vmus39814_iframe_control[1].htm moved successfully.
    C:\Documents and Settings\Melanie\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
    C:\Documents and Settings\Melanie\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully.
    File\Folder C:\WINDOWS\temp\_avast5_\Webshlock.txt not found!
    File\Folder C:\WINDOWS\temp\Perflib_Perfdata_5f8.dat not found!

    Registry entries deleted on Reboot...
     
  5. 2011/02/13
    molsonrn

    molsonrn Inactive Thread Starter

    Joined:
    2010/02/08
    Messages:
    121
    Likes Received:
    0
    today

    Things seem pretty good now...thank you once again.
     
  6. 2011/02/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)

    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.