browser hijacked?

  1. #11
    JesusGotCaught2 is offline Full Member

    thanks for the help!
    how important is it really to change my passwords?
    Are these things I had really going to steal them?

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: Rob's Computer
    ->Temp folder emptied: 168205 bytes
    ->Temporary Internet Files folder emptied: 8829254 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 53858890 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 689 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 287712 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 60.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Public

    User: Rob's Computer
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.31.0 log created on 12172011_152620

    Files\Folders moved on Reboot...
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DF0FD7E85479A4DF6C.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DF5D9F54CFDBD43EA5.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFA87AB45717E2CD62.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFB344597B8032A2BE.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFB54B6B007A3427F6.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFB9ED397566E5392C.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFD26FB896460ADC38.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFE255B72AC4C6B9A5.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFE67F4D0CDAF1D22E.TM P not found!
    File\Folder C:\Users\Rob's Computer\AppData\Local\Temp\~DFFD5FDE1E89A753A4.TM P not found!
    C:\Users\Rob's Computer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B8E54BCB-3EE4-4ECE-9B59-12FCBADB6FB5}.tmp moved successfully.
    File\Folder C:\Users\Rob's Computer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C272448C-B186-4046-856D-965FAA1C15CE}.tmp not found!
    C:\Users\Rob's Computer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{DBC2B113-8124-479D-AD35-F86820A853BA}.tmp moved successfully.
    C:\Users\Rob's Computer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FF23679B-EC2E-4512-A3C4-E22C6BA06AFB}.tmp moved successfully.

    Registry entries deleted on Reboot...

  2. #12
    broni is offline Senior Member
    how important is it really to change my passwords?
    Crucial. You had a bunch of trojans there.

    Are these things I had really going to steal them?
    They possibly did already.

    Any current issues?

  3. #13
    JesusGotCaught2 is offline Full Member
    How likely are they to actually use my passwords/log into my bank account etc?
    Nope no issues right now! Thanks for the help!

  4. #14
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    How likely are they to actually use my passwords/log into my bank account etc?
    Check your bank statements, call your bank about any suspicious activities.

    Good luck and stay safe

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2