Still having issues with the DOS commands -
The first one returns "The directory is not empty" while the second one returns "The filename, directory name or volume label syntax is incorrect."
Below are the command prompt results
C:\windows\system32>cmd /c rd "c:\users\Jason\AppData\Local\ca017659
The directory is not empty.
C:\windows\system32>cmd /c del /a/f/q "<file.path>"C:\Windows\winsxs\x86_microso
ft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_603b1e855897bcd6\netbt.sys
"
The filename, directory name, or volume label syntax is incorrect.
-----
I also tried w/ and w/o closing " for both commands- all return same error messages.
Thanks!
Rootkit.0Access) won't cure Google redirect virus - don't know how to remove
#17
Posted 04 February 2012 - 12:42 AM
Time for a better hammer:
Please download OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
- Save it to your desktop.
- Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:Files c:\users\Jason\AppData\Local\ca017659 C:\Windows\winsxs\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_603b1e855897bcd6\netbt.sys
- Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTM and reboot your PC.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
#18
Posted 05 February 2012 - 11:01 PM
Looks like the OTM strategy worked. Here's the result from the s/w -
#############
c:\users\Jason\AppData\Local\ca017659\U folder moved successfully.
c:\users\Jason\AppData\Local\ca017659 folder moved successfully.
C:\Windows\winsxs\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_603b1e855897bcd6\netbt.sys moved successfully.
OTM by OldTimer - Version 3.1.19.0 log created on 02052012_195102
################
Should I continue w/ the Adobe upgrade and deletion of the s/w recommended in previous post?
Thanks!
#############
c:\users\Jason\AppData\Local\ca017659\U folder moved successfully.
c:\users\Jason\AppData\Local\ca017659 folder moved successfully.
C:\Windows\winsxs\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_603b1e855897bcd6\netbt.sys moved successfully.
OTM by OldTimer - Version 3.1.19.0 log created on 02052012_195102
################
Should I continue w/ the Adobe upgrade and deletion of the s/w recommended in previous post?
Thanks!
#19
Posted 05 February 2012 - 11:02 PM
Looks like the OTM strategy worked. Here's the result from the s/w -
#############
c:\users\Jason\AppData\Local\ca017659\U folder moved successfully.
c:\users\Jason\AppData\Local\ca017659 folder moved successfully.
C:\Windows\winsxs\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_603b1e855897bcd6\netbt.sys moved successfully.
OTM by OldTimer - Version 3.1.19.0 log created on 02052012_195102
################
Should I continue w/ the Adobe upgrade and deletion of the s/w recommended in previous post?
Thanks!
#############
c:\users\Jason\AppData\Local\ca017659\U folder moved successfully.
c:\users\Jason\AppData\Local\ca017659 folder moved successfully.
C:\Windows\winsxs\x86_microsoft-windows-netbt_31bf3856ad364e35_6.1.7600.16385_none_603b1e855897bcd6\netbt.sys moved successfully.
OTM by OldTimer - Version 3.1.19.0 log created on 02052012_195102
################
Should I continue w/ the Adobe upgrade and deletion of the s/w recommended in previous post?
Thanks!
#20
Posted 05 February 2012 - 11:24 PM
Great! Please continue on with those other instructions now adding this one after you uninstall ComboFix:
Cleanup with OTM
- Double-click OTM.exe to start the program.
- Close all other programs apart from OTM as this step will require a reboot
- On the OTM main screen, press the CLEANUP button
- Say Yes to the prompt and then allow the program to reboot your computer.
- Manually delete any remaining tools or logs from our work
#21
Posted 06 February 2012 - 10:40 PM
Thanks!
I've removed all the tools and logs from our work.
I also re-enabled MBAB and performed a full scan.
Everything's clean and there is no more re-direction of search results.
Thanks for everything! Much appreciated.
I've removed all the tools and logs from our work.
I also re-enabled MBAB and performed a full scan.
Everything's clean and there is no more re-direction of search results.
Thanks for everything! Much appreciated.
#22
Posted 06 February 2012 - 11:24 PM

Help
This topic is locked

Back to top










