also @ TechSpot: Blizzard talks Diablo 3 facts, nerfing and buffs for legendary items

TechSpot

[Solved] Removed Windows XP 2012 antivirus but infected with ping.exe

Discussion in 'Virus and Malware Removal' started by forumNewbie, Jan 6, 2012.

  1. forumNewbie Newcomer, in training

    Hi Broni,

    I could not find Java(TM) 6 Update 7 in the add/remove programs list. How do I uninstall it?

    Also, what about threats reported by the eset online scanner. Are they all false positives?
  2. Broni Malware Annihilator

    That's fine.

    My Eset scan instruction do NOT say anything about changing any settings.
    If you didn't all those items would have been removed.

    You're lucky because all those items (except for one) are located in your restore point, which you'll reset by performing steps from my previous reply.
    The last item you can delete manually:
    E:\Softwares\Downloads\cnet2_STOPzilla_Setup_exe.exe

    Go on....
  3. forumNewbie Newcomer, in training

    Thanks. I don't remember changing any of the default settings. The "fix" option was uncheked and I didn't check it since you didn't want me to change the default settings.

    My computer seems to be running fine now. Thanks much for your help! You really saved my day from this nasty virus.I will follow your recommendations about being safe online. Really appreciate your time!!

    -SB

    Here is the OTL clean up. Let me know if you want me to do anything else.

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: SB
    ->Temp folder emptied: 489916 bytes
    ->Temporary Internet Files folder emptied: 10772179 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 36380 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 125464 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 11.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default User

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    User: SB
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.31.0 log created on 01082012_153351

    Files\Folders moved on Reboot...
    File\Folder C:\Documents and Settings\SB\Local Settings\Temp\~DFCE9.tmp not found!
    File\Folder C:\Documents and Settings\SB\Local Settings\Temp\~DFD24.tmp not found!
    File\Folder C:\Documents and Settings\SB\Local Settings\Temp\~DFE14.tmp not found!
    File\Folder C:\Documents and Settings\SB\Local Settings\Temp\~DFE55.tmp not found!
    C:\Documents and Settings\SB\Local Settings\Temporary Internet Files\Content.IE5\P00BEAS8\BebasNeue-webfont[1].eot moved successfully.
    C:\Documents and Settings\SB\Local Settings\Temporary Internet Files\Content.IE5\P00BEAS8\League_Gothic-webfont[1].eot moved successfully.
    C:\Documents and Settings\SB\Local Settings\Temporary Internet Files\Content.IE5\J0A1NNUJ\topic175808[1].html moved successfully.
    C:\Documents and Settings\SB\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

    Registry entries deleted on Reboot...
  4. Broni Malware Annihilator

    Way to go!! [IMG]
    Good luck and stay safe :)