also @ TechSpot: Xbox One: Entertainment Hub First, Gaming Console Second -- But Could It Disrupt TV?

Win32/Medfos.DC trojan

Discussion in 'Virus and Malware Removal' started by Byeung, Sep 26, 2012.

Post New Reply
  1. Byeung Newcomer, in training Posts: 39

    OTL LOG:

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Bernard
    ->Temp folder emptied: 78663 bytes
    ->Temporary Internet Files folder emptied: 10458012 bytes
    ->Java cache emptied: 1878 bytes
    ->Flash cache emptied: 492 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 608 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 10.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Bernard
    ->Flash cache emptied: 0 bytes

    User: Default

    User: Default User

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Bernard
    ->Java cache emptied: 0 bytes

    User: Default

    User: Default User

    User: Public

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.69.0 log created on 09282012_001134
    Files\Folders moved on Reboot...
    C:\Users\Bernard\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Y7VQNXMW\bizo_multi[1].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Y7VQNXMW\partner[1].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Y7VQNXMW\r[2].js moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FDWN3TKN\load[1].js moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FDWN3TKN\partner[1].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FDWN3TKN\partner[2].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FDWN3TKN\win32-medfos-dc-trojan[1].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9XPQIUV8\918[1].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9XPQIUV8\ping[3].js moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1TW2RWG6\adids[1].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1TW2RWG6\ads[8].htm moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Bernard\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
  2. Byeung Newcomer, in training Posts: 39

    Whenever the computer restarts, there's no longer a popup from my antivirus saying the trojan has been detected,..does this mean the computer is clean now?,..also there's some items I downloaded to clean the computer (java setup, GMER, security check et.), I can delete all those now right?
  3. Broni Malware Annihilator Posts: 39,349   +175

    Yes, you're clean :)

    Yes.

    Good luck and stay safe :)
  4. Byeung Newcomer, in training Posts: 39

    The laptop is running a lot faster and no more popups with any trojan detected,..just wanted to say thanks again Broni, you've been a great help and it's very much appreciated!!!
  5. Broni Malware Annihilator Posts: 39,349   +175

    Way to go!! [IMG]
    Good luck and stay safe :)