Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

file extraction prompt virus? [Solved]


  • This topic is locked This topic is locked

#31
jr chambers

jr chambers

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 124 posts
here is the OTL txt file
OTL logfile created on: 1/20/2014 5:54:55 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\joel c\Desktop\computer clean up files logs
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16476)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.27 Gb Available Physical Memory | 69.81% Memory free
6.50 Gb Paging File | 4.61 Gb Available in Paging File | 70.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 755.73 Gb Total Space | 437.29 Gb Free Space | 57.86% Space Free | Partition Type: NTFS
Drive D: | 465.75 Gb Total Space | 302.23 Gb Free Space | 64.89% Space Free | Partition Type: NTFS
Drive E: | 175.78 Gb Total Space | 162.18 Gb Free Space | 92.26% Space Free | Partition Type: NTFS
Drive F: | 3.82 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: ASUS32BITMAINPC | User Name: joel c | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Custom Scans ==========

< C:\|j1wo7ccj.;true;true;true /FP >
[2014/01/06 17:19:27 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default
[2014/01/06 06:48:52 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\bookmarkbackups
[2010/03/20 12:51:12 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\chrome
[2014/01/06 17:19:27 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\extensions
[2014/01/06 17:03:25 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\healthreport
[2012/11/20 20:11:53 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\ImTranslator
[2013/12/14 08:22:38 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\minidumps
[2010/03/22 19:37:18 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\searchplugins
[2014/01/06 17:19:25 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\storage
[2014/01/06 17:19:25 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\weave
[2014/01/06 17:02:20 | 000,000,000 | ---D | M] -- C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\webapps
[2014/01/05 08:42:37 | 000,000,000 | ---D | M] -- C:\AdwCleaner\Backup\C\Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default

< End of report >
Joel
  • 0

Advertisements


#32
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
Well there they are still in quarantine, the report showed the move as successful, clearly not.

My next post involves a change to the system and needs to be cleared by my instructor so this will be tomorrow. At least we know that your Bookmarks are safe....a little to safe :)

As far as the clean is concerned, we are done. There are a few tools to remove which clears all the quarantined items which is why I want these Bookmarks back. We may do this manually by simply right clicking that Mozilla folder and overwriting the present one :)

Speak soon :thumbsup:
  • 0

#33
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
Ok the scan results show there is another backup of that folder in ADWcleaner which is easier to recover from so we will use this :)

However I'm not 100% sure what happens to the Mozilla folder that is now present in the Roaming folder. If you have new Bookmarks these may be lost so make a copy of that Mozilla folder and store it on your desktop. Simply right click the Mozilla folder and Paste to your Desktop or USB. If your not bothered then carry on with the following.


1. Folder Options

  • Click Start and in the search box type Folder Options and press Enter
  • Click the View tab and check the Show hidden files, folders and drives box.
  • Click Apply then O.K
  • All done, now ADWcleaner :)


2. ADWcleaner

  • Right click ADWcleaner and Run as Administrator
  • Top of the screen click Tools then Quarantine manager
  • In the window that opens locate the C\Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default entry and check the box.
  • Now click Restore. A log file will open to show if restored. I do not need to see this.
  • Close the log then click Exit and close ADWcleaner

3. Firefox Bookmarks

The j1wo7ccj folder should now be present.

  • 2 ways to do this step depending on your display - 1. Click the Display Your Bookmarks button and select Show All Bookmarks OR 2. Click the Orange Firefox button then Bookmarks then Show All Bookmarks
  • In the window that opens click the Import and Backup button and then select Restore.
  • This time instead of a date select Choose file
  • We now need to locate the JSON file in the j1wo7ccj.default profiles folder.
  • In the left hand pane click Local Disk (C:)
  • In the right hand window scroll down and double click the Users folder.
  • Double click your users folder (joel)
  • Double click AppData Double click Roaming Double click Mozilla Double click Firefox
  • Double click Profiles Double click j1wo7ccj.default Double click Bookmarkbackups
  • Double click the JSON file you need to restore bookmarks (5th of January or before) and click O.K at the prompt.
  • Close and restart Firefox. If the Bookmarks are still not there then follow step 4 in my previous Bookmark post.

4. Set Folder Options to Default

  • Click Start and in the search box type Folder Options and press Enter
  • Click the View tab and check the Don't Show hidden files, folders and drives box.
  • Click Apply then O.K

  • 0

#34
jr chambers

jr chambers

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 124 posts
Problem,
not sure how but ADWcleaner was removed/moved from my system, I'd put every program and file in a folder on my desktop for easy access and only the log files for ADWcleaner are there now, the program is gone. i downloaded it again and run it, but using the tools function i do not find the quarantine manager containing anything. what happen with that??? :smashcomp:
Joel
  • 0

#35
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
The only way for ADWcleaner to disappear is to click Uninstall when open but this clears the logfiles and the backup folder. The folder was there on the 20th did you delete the ADWcleaner icon by mistake?

Check the folowing location:

C:\AdwCleaner\Backup - Check this folder for me. Is that folder empty or present?

The folder is still in OTL quarantine so we can try moving that again if all else fails. Firefox does some peculiar things regarding users profiles, the mind boggles :wacko:

Will get my post cleared and get back to you JR :thumbsup:
  • 0

#36
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
Forget my last post JR I have figured out what the problem is.

Your Username is joel c - The space then c threw me, In the fix I have you as joel :whistling: My apologies!

We have to repeat the folder move which will now be succesfull. The following folders will be overwritten so if you have new information in them copy the new info. to another location and replace after the move:

Mozilla
A.C.E. Misfire Detective
Canneverbe Limited
com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
Epson
Identities
InstallShield
Intuit
Leader Technologies
Macromedia
Malwarebytes
Microsoft
motorola
OverDrive
Windows Live Writer
USB Optical Mouse


Any of these folders you don't want replaced?
  • 0

#37
jr chambers

jr chambers

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 124 posts
i don't have anything new that has been added to those folders, so no, i do not have problem with replacing these folders.
Joel
  • 0

#38
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
Hi there JR........c :wacko: this post should put things straight finally.

1. Move the folders back.

2. Delete 3 items.

3. Then restore Bookmarks.

Follow in order


1. First OTL Fix

  • Right click the OTL icon and select Run as Administrator.
  • Copy the entire text in the Quote box below, do not include the word QUOTE and Paste into the Custom Scans/Fixes box in OTL.

    :FILES
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\A.C.E. Misfire Detective, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Adobe, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Canneverbe Limited, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Epson, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Identities, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Intuit, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Leader Technologies, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Macromedia, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Malwarebytes, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Microsoft, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\motorola, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\OverDrive, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Windows Live Writer, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\USB Optical Mouse, C:\Users\joel c\AppData\Roaming /c
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\InstallShield, C:\Users\joel c\AppData\Roaming /c

  • Then click Run Fix
  • Click O.K and an OTL.txt file will open. Copy and Paste the Fix Log in your next reply.
  • The OTL fix log will also be saved in the following location: C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log - Where mmddyyy _hhmmss is the date and time of fix.

2. Second OTL Fix

  • Right click the OTL icon and select Run as Administrator.
  • Copy the entire text in the Quote box below, do not include the word QUOTE and Paste into the Custom Scans/Fixes box in OTL.

    :OTL
    C:\Users\joel c\Documents\downloads from g drive\Babylon7_setup.exe
    C:\Users\joel c\Downloads\AESannowave.exe
    C:\Users\joel c\AppData\Roaming\Mozilla\Firefox\Profiles\j1wo7ccj.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
    :COMMANDS
    [EMPTYTEMP]

  • Then click Run Fix
  • Click O.K if asked to Reboot.
  • An OTL fix log will be saved in the following location: C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log - Where mmddyyy _hhmmss is the date and time of fix.
  • Copy and Paste the Fix Log in your next reply.


3. Folder Options

  • Click Start and in the search box type Folder Options and press Enter
  • Click the View tab and check the Show hidden files, folders and drives box.
  • Click Apply then O.K
  • All done, now those Bookmarks finally :)


4. Firefox Bookmarks

The j1wo7ccj folder should now be present.

  • 2 ways to do this step depending on your display - 1. Click the Display Your Bookmarks button and select Show All Bookmarks OR 2. Click the Orange Firefox button then Bookmarks then Show All Bookmarks
  • In the window that opens click the Import and Backup button and then select Restore.
  • This time instead of a date select Choose file
  • We now need to locate the JSON file in the j1wo7ccj.default profiles folder.
  • In the left hand pane click Local Disk (C:)
  • In the right hand window scroll down and double click the Users folder.
  • Double click your users folder (joel)
  • Double click AppData Double click Roaming Double click Mozilla Double click Firefox
  • Double click Profiles Double click j1wo7ccj.default Double click Bookmarkbackups
  • Double click the JSON file you need to restore bookmarks (5th of January or before) and click O.K at the prompt.
  • Close and restart Firefox. If the Bookmarks are still not there then follow step 4 in my previous Bookmark post.

5. Set Folder Options to Default

  • Click Start and in the search box type Folder Options and press Enter
  • Click the View tab and check the Don't Show hidden files, folders and drives box.
  • Click Apply then O.K


Things I want to see in your next post.

  • OTL fix 1
  • OTL fix 2
  • Bookmarks?

  • 0

#39
jr chambers

jr chambers

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 124 posts
WOW! never seen anything be such a task. when i run OTL as admin and then copy paste the text, click run, i got a prompt "cannot create file c:\users\joel c\Desktop\computercleanupfileslogs\cmd.bat. then i click ok, and nothing happens with OTL, thought maybe i should wait awhile to see if it was running but that wasn't helpful, then try copying the text a few different ways, no help either. is there another option? :confused:
Joel
  • 0

#40
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
O.k no problem try this fix first, It's just the Mozilla folder.


OTL Fix
  • Right click the OTL icon and select Run as Administrator.
  • Copy the entire text in the Quote box below, do not include the word QUOTE and Paste into the Custom Scans/Fixes box in OTL.

    :FILES
    MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla, C:\Users\joel c\AppData\Roaming /c

  • Then click Run Fix
  • Click O.K if asked to Reboot.
  • An OTL fix log will be saved in the following location: C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log - Where mmddyyy _hhmmss is the date and time of fix.
  • Copy and Paste the Fix Log in your next reply.

  • 0

Advertisements


#41
jr chambers

jr chambers

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 124 posts
OK, run fix, here is the text log
========== FILES ==========
< MOVE /-y C:\_OTL\MovedFiles\01062014_171545\C_Users\joel c\AppData\Roaming\Mozilla, C:\Users\joel c\AppData\Roaming /c >
C:\Users\joel c\Desktop\computer clean up files logs\cmd.bat deleted successfully.
C:\Users\joel c\Desktop\computer clean up files logs\cmd.txt deleted successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 01252014_175522
Joel
  • 0

#42
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
Awesome!!

Now follow steps 2, 3,4 and 5 for the 2nd OTL fix and the Bookmarks :)
  • 0

#43
jr chambers

jr chambers

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 124 posts
Well friend, this isn't working, still only show this folder c50ggzci.default and not the jrw07ccj.default not sure what you may be able to do from this point. :surrender:
Joel
  • 0

#44
Nutloaf

Nutloaf

    Trusted Helper

  • Malware Removal
  • 1,790 posts
well, this is Bizarre! Can you tell me if the following folder exists on your local disk:

C:\_OTL

There is one method left we could use. :)
  • 0

#45
jr chambers

jr chambers

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 124 posts
yes these are what is in it..13 folders and 7 text docs
Joel
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP