also @ TechSpot: Asus' new lineup of Z87 Haswell motherboards revealed

Gethotresults.com hijacker....and possibly other issues

Discussion in 'Virus and Malware Removal' started by andrew ellis, Sep 21, 2012.

Post New Reply
  1. andrew ellis Newcomer, in training Posts: 36

    While using Firefox.

    Example: Just went to facebook and when I clicked in the username box so I can log in a popup came up. The popup knew my location since it said "You won something blah blah blah in Lynwood" which is a town near me.
  2. andrew ellis Newcomer, in training Posts: 36

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Admin
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: andrew
    ->Temp folder emptied: 47602 bytes
    ->Temporary Internet Files folder emptied: 4625214 bytes
    ->Java cache emptied: 1878 bytes
    ->FireFox cache emptied: 60173339 bytes
    ->Flash cache emptied: 708 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 5140 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 62.00 mb


    [EMPTYFLASH]

    User: Admin
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: andrew
    ->Flash cache emptied: 0 bytes

    User: Default

    User: Default User

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: Admin
    ->Java cache emptied: 0 bytes

    User: All Users

    User: andrew
    ->Java cache emptied: 0 bytes

    User: Default

    User: Default User

    User: Public

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.56.0 log created on 09222012_162940

    Files\Folders moved on Reboot...
    C:\Users\andrew\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File\Folder C:\Users\andrew\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso1FC3.tmp not found!
    File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Amazon Digital Video\Servicelog.adv scheduled to be moved on reboot.

    PendingFileRenameOperations files...
    File C:\Users\andrew\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
    File C:\Users\andrew\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso1FC3.tmp not found!
    [2012/09/22 16:32:55 | 000,000,000 | ---- | M] () C:\Windows\temp\_avast_\Webshlock.txt : Unable to obtain MD5
    [2012/09/22 16:33:21 | 000,006,328 | ---- | M] () C:\Windows\temp\Amazon Digital Video\Servicelog.adv : Unable to obtain MD5

    Registry entries deleted on Reboot...
  3. andrew ellis Newcomer, in training Posts: 36

  4. Broni Malware Annihilator Posts: 39,254   +175

  5. andrew ellis Newcomer, in training Posts: 36

    Also key words keep getting underlined....like in my prior post the word Congratulations is now a link to an ad. Is this something techspot does for advertisement? I have seen this in other locations also especially in game forums etc.
  6. Broni Malware Annihilator Posts: 39,254   +175

    Follow my previous reply.
     
  7. andrew ellis Newcomer, in training Posts: 36

    K all done then....no popup on facebook.
  8. andrew ellis Newcomer, in training Posts: 36

    Still getting words that are turned to links/ads.

    Seems key words are getting turned into ad links.

    Words like:
    Windows
    Files
    Shared
  9. Broni Malware Annihilator Posts: 39,254   +175

  10. andrew ellis Newcomer, in training Posts: 36

    Seems to be doing well. Thanks for all your help. Donation incoming. I may even post logs from my laptop to see if anything is wrong. I already ran the online scanner you gave me and it found 1 thing, so now that is gone.
  11. Broni Malware Annihilator Posts: 39,254   +175

    Way to go!! [IMG]
    Good luck and stay safe :)

    ...and thank you :)