Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Department of Justice Virus - Help plz
Message
<blockquote data-quote="ionizer" data-source="post: 144509" data-attributes="member: 14933"><p>Thanks Kuttus,</p><p></p><p>that was like magic <img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite109" alt=":)" title="Smile :)" loading="lazy" data-shortname=":)" /> here is the new log</p><p></p><p>All processes killed</p><p>========== OTL ==========</p><p>C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\js folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\html folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0 folder moved successfully.</p><p>64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully.</p><p>64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully.</p><p>C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll moved successfully.</p><p>64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.</p><p>64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully.</p><p>C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll moved successfully.</p><p>Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\ deleted successfully.</p><p>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\ deleted successfully.</p><p>C:\Program Files (x86)\Microsoft Lync\OCHelper.dll moved successfully.</p><p>Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully.</p><p>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully.</p><p>C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli.dll moved successfully.</p><p>Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DirexcX deleted successfully.</p><p>C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Templates\DircxtX.exe moved successfully.</p><p>64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll deleted successfully.</p><p>C:\Users\sjacobs\AppData\Local\SearchProtect\SearchProtect\rep folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\SearchProtect\SearchProtect folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\SearchProtect\Logs folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\SearchProtect folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\Wajam\Chrome folder moved successfully.</p><p>C:\Users\sjacobs\AppData\Local\Wajam folder moved successfully.</p><p>File ptytemp] not found.</p><p>File boot] not found.</p><p> </p><p>OTL by OldTimer - Version 3.2.69.0 log created on 11152013_204623</p><p></p><p>Files\Folders moved on Reboot...</p><p></p><p>PendingFileRenameOperations files...</p><p></p><p>Registry entries deleted on Reboot...</p></blockquote><p></p>
[QUOTE="ionizer, post: 144509, member: 14933"] Thanks Kuttus, that was like magic :-) here is the new log All processes killed ========== OTL ========== C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins folder moved successfully. C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\js folder moved successfully. C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\html folder moved successfully. C:\Users\sjacobs\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0 folder moved successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully. C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll moved successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\ deleted successfully. C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\ deleted successfully. C:\Program Files (x86)\Microsoft Lync\OCHelper.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7}\ deleted successfully. C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli.dll moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DirexcX deleted successfully. C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Templates\DircxtX.exe moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll deleted successfully. C:\Users\sjacobs\AppData\Local\SearchProtect\SearchProtect\rep folder moved successfully. C:\Users\sjacobs\AppData\Local\SearchProtect\SearchProtect folder moved successfully. C:\Users\sjacobs\AppData\Local\SearchProtect\Logs folder moved successfully. C:\Users\sjacobs\AppData\Local\SearchProtect folder moved successfully. C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam folder moved successfully. C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping folder moved successfully. C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search folder moved successfully. C:\Users\sjacobs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam folder moved successfully. C:\Users\sjacobs\AppData\Local\Wajam\Chrome folder moved successfully. C:\Users\sjacobs\AppData\Local\Wajam folder moved successfully. File ptytemp] not found. File boot] not found. OTL by OldTimer - Version 3.2.69.0 log created on 11152013_204623 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... [/QUOTE]
Insert quotes…
Verification
Post reply
Top