also @ TechSpot: Facebook headhunts Apple engineers for 3rd smartphone attempt

TechSpot

Help with command service and outer info removal

Discussion in 'Virus and Malware Removal' started by DarbyG, Mar 30, 2008.

Thread Status:
Not open for further replies.
  1. Blind Dragon Newcomer, in training

    Click on my name and select send an email to blind dragon, then attach it there.

    make sure the subject is DarbyG Kaspersky scan
  2. Blind Dragon Newcomer, in training

    The user account kelsey is extremely cluttered and is the reason for the size of the kaspersky log. Music, games, pictures, and a ton of temporary data, more that I think I have ever seen in an online scan. It also appears to be the source of your infections.

    Are you sure you followed the ATF cleaner instructions properly a lot of this should have been cleared out.

    In addition to running ATF cleaner again and insuring that the appropriate boxes are checked.


    Crap Cleaner
    • Download from HERE
    • Close all browsers.
    • Run the programme and make sure all the boxes are ticked under the Windows and Applications tabs, Also check All Advanced tabs(except for the Old prefetch Data option, this should be unticked)
    • Click the run cleaner button. Do this several times


    Afterwards scan again with Kaspersky and see if you can attach the log here if not email it to me again
  3. DarbyG Newcomer, in training

    I've done all the previous scanning with ATF and the other tools under the username Kathy. I figured it should get all the files on the computer. Do I need to redo the tools under the username Kelsey also?

    I'm emailing the kaspersky scan. I think it came out as 3 MB.
  4. Blind Dragon Newcomer, in training

    Do this top part for kathy and kelsey ;)

    Navigate to C:\Windows\Temp
    Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

    Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
    Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

    Clean out your Temporary Internet files. Proceed like this:

    For Internet Explorer 7

    * Click Start, click Control Panel, and then double-click Internet Options.
    * On the General tab, click Delete... under Browsing History.
    * Next to Temporary Internet Files, click Delete files, and then click OK.
    * Next to Cookies, click Delete cookies, and then click OK.
    * Next to History, click Delete history, and then click OK.
    * Click the Close button.
    * Click OK.

    For Mozilla 1.x and Up

    * Click Edit from the Mozilla menubar.
    * Click Preferences... from the Edit menu.
    * Expand the Advanced menu by clicking the plus sign.
    * Click Cache.
    * Click the Clear Cache button.

    For Opera

    * Click File from the Opera menubar.
    * Click Preferences... from the File menu.
    * Click the History and Cache menu.
    * Click the two Clear buttons next to Typed in addresses and Visited addresses (history) and click the Empty now button to clear the Disk cache.
    * Click Ok to close the Preferences menu.

    Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

    Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
    -----------------------------------------------------------------------------------------------------------

    Manually clear cache

    • Open an Explorer folder window (for example, double-click My Computer).
    • From the Explorer menu select Tools | Folder Options | View. Make sure that you have checked the box next to "Show hidden files and folders" and uncheck "Hide protected operating system files".
    • Start Internet Explorer and click Tools | Internet Options | General tab | Settings | View Files.
    • IE should have opened up a folder window, typically viewing a folder with the name of C:\Windows\Temporary Internet Files. Put your cursor in the Address area of the folder window and add the name \content.ie5 to the name, so in our example the Address bar would now read c:\Windows\Temporary Internet Files\content.ie5.
    • You should see a series of folders with random eight-character names like ADOZMZS1. Delete each of these randomly named folders. You may get an error that some files are in use, this is normal if you are currently at a web site since those files are in the cache. Hold down the Shift key when deleting the files so they do not go to the Recycle Bin.

    ---------------------------------------------------------------------------------------------------------


    CFScript

    Open notepad and copy/paste the text in the code box below into it:
    NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
    Also ..

    Pay particular attention to this :-

    Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
    Save this as CFScript.txt

    Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

    [IMG]

    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.

    -----------------------------------------------------------------------------------------------------

    Try kaspersky again
  5. DarbyG Newcomer, in training

    I went ahead and reran all the tools that I had used previously again in the kelsey username (before I got your latest post.)

    The tools cleaned out alot of the temp files so most of the temp folders were empty. When I went to the content.ie5 folder I was able to delete all but 1 of the temp folders under kathy and kelsey. It kept telling me the files were in use. I even tried deleting in safe mode, but kept getting the same warning.

    Fresh HJT and combofix logs are included.
  6. Blind Dragon Newcomer, in training

    Looking better. It appears you picked up clickspring/purityscan infection

    Malwarebytes' Anti-Malware

    • click on the update tab -> search for updates
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply
      • If you accidently close it, the log file is saved here and will be named like this:
      • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

    Afterwards lets try Kaspersky again and see how it looks
  7. DarbyG Newcomer, in training

    Ran Kaspersky and it found more stuff...

    I'm emailing the kaspersky scan, it was over a meg.
  8. Blind Dragon Newcomer, in training

    Actually the only thing kaspersky found was in your old restore points and a false positive on one of the tools.

    Still quite a bit of clutter on there it appears, but we have removed a few MB of text off the logs.

    Crap Cleaner
    • Download from HERE
    • Close all browsers.
    • Run the programme and make sure all the boxes are ticked under the Windows and Applications tabs, Also check All Advanced tabs(except for the Old prefetch Data option, this should be unticked)
    • Click the run cleaner button. Do this several times



    Uninstall Combofix
    * Click START then RUN
    * Now type Combofix /u in the runbox
    * Make sure there's a space between Combofix and /u
    * Then hit Enter.

    * The above procedure will:
    * Delete the following:
    * ComboFix and its associated files and folders.
    * Reset the clock settings.
    * Hide file extensions, if required.
    * Hide System/Hidden files, if required.
    * Set a new, clean Restore Point.

    -----------------------------------------------------------------------
    Cleanup using OTMoveit2 by OldTimer
    Now we can clear out the rest of the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally.

    Download OTMoveIt2 by OldTimer OTMoveIt2.exe and place it on your desktop.

    1. Double click OTMoveIt2.exe to launch it.
    If using Vista Right-Click OTMoveIt and choose Run As Administrator
    2. Click on the CleanUp! button.
    3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
    4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)

    * When finished exit out of OTMoveIt2

    ---------------------------------------------------------------------------
    I recommend you keep
    1 anti virus program
    1 firewall
    Combo of Anti-Spyware (Spybot S&D and MBAM, or your choice)

    For Spybot you can download the latest version from HERE.

    keep them updated.

    You can also turn on tea timer in Spybot:
    • Click on Mode at the top and make sure that Advanced is checked
    • Expand the Tools tab in the left pane
    • Single click on the Resident Icon also in the left pane
    • check Resident "TeaTimer" (Protection of over-all system settings) Active
    • Close spybot

    Also under Tools you can double-click System Startup in the right pane and disable programs from running at startup. This will free up system resources. For example if you don't use MSN Messenger everytime you run your computer you can disable it, then when you want to use it you can launch it through Start -> all programs, or make a shortcut on the desktop for it. That way it doesn't use resources when you aren't using it. Don't disable any entries in green though.

    And just to be sure
    Set correct settings for files
    • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
    • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
    • If unchecked please check Hide protected operating system files (Recommended)
    • If necessary check "Display content of system folders"
    • If necessary Uncheck Hide file extensions for known file types.
    • Click OK

    clear system restore points

    • This is a good time to clear your existing system restore points and establish a new clean restore point:
      • Go to Start > All Programs > Accessories > System Tools > System Restore
      • Select Create a restore point, and Ok it.
      • Next, go to Start > Run and type in cleanmgr
      • Select the More options tab
      • Choose the option to clean up system restore and OK it.
      This will remove all restore points except the new one you just created.
  9. DarbyG Newcomer, in training

    Thank you Blind Dragon for all your help. This wasn't something that I could've ever managed on my own. The computer is working better than it has in a long, long time.

    My thanks go to Kritius and Jobeard too!
  10. Blind Dragon Newcomer, in training

    Glad everything is working good for you. Make sure to run ATF cleaner or CCleaner on a regular basis to prevent the build up of temporary files.

    And if you have any more problems you know where to find us

    Regards,

    BD
Thread Status:
Not open for further replies.