also @ TechSpot: Bill Gates is once again the richest person in the world

Multiple iexplore.exe instances and URL:Mal infection

Discussion in 'Virus and Malware Removal' started by spiritofcat, Jan 6, 2013.

Post New Reply
  1. spiritofcat Newcomer, in training

    Okay, I'm back after the creating the new restore point with OTL.
    I noticed in the log for it that it talks about a User: matt
    My user account is Fuzzy, and I don't intend to have any other user accounts.
    Checking the list of accounts in Control Panel > User Accounts > Manage Another Account, I see Fuzzy, ASP.NET Machine Account and Guest, but Guest is listed as turned off. I see no mention there of matt and I've got no idea what the ASP.NET Machine Account is.
    Is there anything there I should be concerned about?

    Here's the OTL log:
    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Fuzzy
    ->Temp folder emptied: 43548 bytes
    ->Temporary Internet Files folder emptied: 87126 bytes
    ->Java cache emptied: 1880 bytes
    ->FireFox cache emptied: 0 bytes
    ->Google Chrome cache emptied: 83075296 bytes
    ->Flash cache emptied: 0 bytes

    User: matt
    ->Temp folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 6586 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 79.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Fuzzy
    ->Flash cache emptied: 0 bytes

    User: matt

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Fuzzy
    ->Java cache emptied: 0 bytes

    User: matt

    User: Public

    User: UpdatusUser

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.69.0 log created on 01092013_090220

    Files\Folders moved on Reboot...
    C:\Users\Fuzzy\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
  2. spiritofcat Newcomer, in training

    Okay, all done!
    I scrapped Adobe Reader and installed Foxit instead.
    I've got WOT and Secunia PSI installed now, got TFC and MBAM ready to run weekly.
    Qualys Browser Check tells me I have Internet Explorer 8, which it lists as an insecure version. I have no interest in ever using Internet Explorer, so I'd prefer to remove it completely if possible rather than wasting bandwidth downloading new versions of it.
    Is it possible to remove IE these days or is it tightly welded into the OS?
  3. Broni Malware Annihilator Posts: 39,236   +175

    ASP.NET is a valid Windows account.
    As for Matt I have no clue.
    You may want to ask at Windows forum.

    As for IE it can NOT be removed and since it's present on your computer it has to be kept up date no matter if you use it or not.

    Good luck and stay safe :)
  4. spiritofcat Newcomer, in training

    Okay, thanks for all your help!:D
  5. Broni Malware Annihilator Posts: 39,236   +175

    You're very welcome [IMG]