Copy the text between the dotted lines below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy): ------------------------------------------------------------------- :Files ipconfig /flushdns /c :Commands [EmptyFlash] [EmptyTemp] [ResetHosts] [CreateRestorePoint] [Reboot]
Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
Click the red button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes.
If the machine reboots, the Results log can be found here:
c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log
Where mmddyyyy_hhmmss is the date of the tool run.
I`m not 100% sure but am suspicious that your system may still be infected, I know the logs indicate otherwise but symptoms still give me some concern. I want to run a scan from outside of windows and see if it picks anything up.
Avira rescue system is the best tool for the job. One stipulation that must be followed. The CD must be created on a known clean PC, from the same PC print off the instruction, they really are very easy to follow. All you need is a blank writable CD, everything else is included in the tutorial. Obviously the PC must have a burner.
All instructions are available here
Avira Rescue System Read through the instructions a couple of times to familiarize yourself with them, create the CD and print off the instruction. It will be to your advantage to have the instructions available during the process.
When complete post back to this thread in the forum..
I would like you to remove the Zonealarm Firewall and see if OTM will run, you can use the Removal Utility available
Here save the Utility to your Desktop, right click and select "Run as Administartor" ensure you enable Windows Firewall.
Try OTM again, let me see the log if successful. Also let me see the log you mention from Avira..
RTitans
20 Posts
0
July 20th, 2011 16:00
It recommended, and I update, adobe flash player.
Ross.
kevinf80_1d0ac6
1.1K Posts
0
July 20th, 2011 17:00
Are your pages loading any better
RTitans
20 Posts
0
July 20th, 2011 21:00
No, it has stayed the same.
Ross
kevinf80_1d0ac6
1.1K Posts
0
July 21st, 2011 03:00
Please download OTM by OldTimer.
Alternative Mirror 1
Alternative Mirror 2
Save it to your desktop.
Double click OTM.exe to start the tool. Vista or Windows 7 users right click and select Run as Administrator
-------------------------------------------------------------------
:Files
ipconfig /flushdns /c
:Commands
[EmptyFlash]
[EmptyTemp]
[ResetHosts]
[CreateRestorePoint]
[Reboot]
---------------------------------------------------------------------
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If the machine reboots, the Results log can be found here:
c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log
Where mmddyyyy_hhmmss is the date of the tool run.
Let me see the log from OTM, also give update...
Kevin
RTitans
20 Posts
0
July 21st, 2011 04:00
I am unable to run the program, whenever I open it it says 'OM.exe has stopped working' followed by a box saying
'The application failed to initialize properly (0xc0000005).
Thanks for continuing to help me by the way,
Ross.
kevinf80_1d0ac6
1.1K Posts
0
July 21st, 2011 05:00
Turn off all security and try again, you can disconnect from the internet whilst security is off
RTitans
20 Posts
0
July 21st, 2011 07:00
I still get the same error.
Ross.
kevinf80_1d0ac6
1.1K Posts
0
July 21st, 2011 15:00
Run it from Safe Mode.....
RTitans
20 Posts
0
July 22nd, 2011 07:00
still didn't work...
kevinf80_1d0ac6
1.1K Posts
0
July 22nd, 2011 09:00
I`m not 100% sure but am suspicious that your system may still be infected, I know the logs indicate otherwise but symptoms still give me some concern. I want to run a scan from outside of windows and see if it picks anything up.
Avira rescue system is the best tool for the job. One stipulation that must be followed. The CD must be created on a known clean PC, from the same PC print off the instruction, they really are very easy to follow. All you need is a blank writable CD, everything else is included in the tutorial. Obviously the PC must have a burner.
All instructions are available here Avira Rescue System Read through the instructions a couple of times to familiarize yourself with them, create the CD and print off the instruction. It will be to your advantage to have the instructions available during the process.
When complete post back to this thread in the forum..
Kevin
RTitans
20 Posts
0
July 23rd, 2011 11:00
I am going to be able to do it, but it is going take a day or so. I have to get to a clean computer.
Thanks,
Ross.
kevinf80_1d0ac6
1.1K Posts
0
July 23rd, 2011 16:00
Thats OK Ross,just post back when you`re ready.....
Kevin
RTitans
20 Posts
0
July 26th, 2011 09:00
Just finished scan, no detections were found, but there were 13 alerts saying either 'Error reading file' or 'Bad Archive Header'
do you need me to post the list of these files?
Thanks,
Ross.
kevinf80_1d0ac6
1.1K Posts
0
July 26th, 2011 14:00
Hiya Ross,
Try OTM again, let me see the log if successful. Also let me see the log you mention from Avira..
Kevin
RTitans
20 Posts
0
July 26th, 2011 16:00
Got OM to work, Just tried a few pages and already seems a lot better, no problems at all so far!
Here is the OM log:
All processes killed
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Ross\Desktop\cmd.bat deleted successfully.
C:\Users\Ross\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: AppData
->Temp folder emptied: 0 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
User: Ross
->Temp folder emptied: 158832308 bytes
->Temporary Internet Files folder emptied: 134434224 bytes
->Java cache emptied: 119746 bytes
->Google Chrome cache emptied: 354361656 bytes
->Flash cache emptied: 8723 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 149379 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33109 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 522752 bytes
Total Files Cleaned = 618.00 mb
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
Restore point Set: OTM Restore Point
OTM by OldTimer - Version 3.1.18.0 log created on 07262011_232601
Files moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Registry entries deleted on Reboot...