05-07-2012 02:29 AM
You are not getting it.
Go into the C:/_OTL folder
Quads
05-07-2012 02:31 AM
C:/_OTL
Not finding it.
Maybe I should run script again. I copied from your attachment.
05-07-2012 02:34 AM
DON'T!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
You go into you hard drive seen as C in Computer
Quads
05-07-2012 02:43 AM
I have it. It mentions moved files. I can''t see a log.
I did have a noterpad come up saying this though, when it restarted.
All processes killed
========== OTL ==========
Process local.exe killed successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr
Registry value HKEY_USERS\S-1-5-21-2927403198-3598784137-21093756
C:\Users\GaryandMeryl\AppData\Roaming\tmp\local.ex
Registry value HKEY_USERS\S-1-5-21-2927403198-3598784137-21093756
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E54729E
C:\Windows\SysWOW64\ezUPBHook.dll moved successfully.
C:\Users\GaryandMeryl\AppData\Roaming\tmp folder moved successfully.
C:\Users\GaryandMeryl\AppData\Roaming\PCCUStubInst
C:\Windows\msdownld.tmp folder deleted successfully.
C:\Users\GaryandMeryl\AppData\Roaming\wklnhst.dat moved successfully.
C:\Users\GaryandMeryl\Documents\You have a Sky iD!.eml moved successfully.
ADS C:\Users\GaryandMeryl\Documents\Fw_ Your ASDA Travel Booking Confirmation [AA1F4F4A].eml:OECustomProperty deleted successfully.
Unable to delete ADS C:\Users\GaryandMeryl\Documents\You have a Sky iD!.eml:OECustomProperty .
ADS C:\Users\GaryandMeryl\Documents\Ryanair Travel Itinerary Knock.eml:OECustomProperty deleted successfully.
ADS C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [ATED2361].eml:OECustomProperty deleted successfully.
ADS C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [AA1F4F4A].eml:OECustomProperty deleted successfully.
========== FILES ==========
File\Folder C:\Users\GaryandMeryl\AppData\Roaming\tmp\local.ex
C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [ATED2361].eml moved successfully.
C:\Users\GaryandMeryl\Documents\Your ASDA Travel Booking Confirmation [AA1F4F4A].eml moved successfully.
C:\Users\GaryandMeryl\AppData\LocalLow\Sun\Java\De
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41044 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: GaryandMeryl
->Temp folder emptied: 123117793 bytes
->Temporary Internet Files folder emptied: 78894664 bytes
->Java cache emptied: 1527385 bytes
->Google Chrome cache emptied: 47429032 bytes
->Flash cache emptied: 42271 bytes
User: Public
User: TEMP
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 202470 bytes
%systemroot%\sysnative\config\systemprofile\AppDat
RecycleBin emptied: 93342 bytes
Total Files Cleaned = 240.00 mb
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: GaryandMeryl
->Flash cache emptied: 0 bytes
User: Public
User: TEMP
Total Flash Files Cleaned = 0.00 mb
[EMPTYJAVA]
User: All Users
User: Default
User: Default User
User: GaryandMeryl
->Java cache emptied: 0 bytes
User: Public
User: TEMP
Total Java Files Cleaned = 0.00 mb
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.42.3 log created on 05072012_103419
Files\Folders moved on Reboot...
C:\Users\GaryandMeryl\AppData\Local\Microsoft\Wind
C:\Users\GaryandMeryl\AppData\Local\Microsoft\Wind
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Registry entries deleted on Reboot...
05-07-2012 02:45 AM
That was in a file under moved files.
05-07-2012 02:51 AM
That is the log, but you pasted it instead
You should not be getting any more alerts by Norton any more as I took the ADS's files and folders.
Quads
05-07-2012 02:51 AM
Does this appear to have solved it?
I'm sorry if our wires were crossed a few times. Obviously this is something you do a lot. But should not understanding the inner workings stop me from using a PC. I mainly use if for photography, Facebook chatting, and forums.
I'm hoping this is solved.
Why would Norton not be able to resolve it?
05-07-2012 02:53 AM
I would like to thank you for your help.
I take it the worm is now removed. I wonder how I got it in the first place. Should Norton 360 have stopped it?
05-07-2012 02:55 AM
Do I need to keep OTL and asw MBR?
05-07-2012 02:55 AM
Are you getting these any more from Norton
The details are,
System infested:Worm W32.VBNA.b Activity
Attacker Url api.ipinfodb.com
source address. 67.212.77.13
Attacking computer 27.212.77.13, 80
Attack resulted from \DEVICE\HARDDISKVOLUME\USERS\GARYANDMERYL\APPDATA\
Quads
