also @ TechSpot: Intel confirms a smartwatch is in the pipeline

Trying to clear out remnants of XP *** 2012 infection

Discussion in 'Virus and Malware Removal' started by rubydreamer, Feb 11, 2012.

Post New Reply
  1. Broni Malware Annihilator Posts: 40,051   +187

    Re-run TDSSKiller one more time.
  2. rubydreamer Newcomer, in training Posts: 41

    Its showing nothing for now
  3. Broni Malware Annihilator Posts: 40,051   +187

    How is computer doing?

    You still owe me Eset scan.
  4. rubydreamer Newcomer, in training Posts: 41

    Redoing Eset since i cant find the logs.

    So far its running ok, other than java issues (several java based things, arent working anymore) Waiting on the nasty surprise popup (hoping im just paranoid)

    C:\TDSSKiller_Quarantine\24.02.2012_15.13.55\rtkt0000\svc0000\tsk0000.dta
    a variant of Win32/Sirefef.DA trojan

    J:\Downloads\Torrents\Fallout.3.FinalFix.Skullptura.rar
    probably a variant of Win32/Agent.DSLWBHV trojan

    K:\CDS\[WinXP] Extreme Se7en 2010 Ultimate [Final + SP3] Created By Jcberry526 [CW OS Team].iso
    multiple threats
  5. Broni Malware Annihilator Posts: 40,051   +187

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    
    :Files
    C:\WINDOWS\tasks\At*.job
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
  6. rubydreamer Newcomer, in training Posts: 41

    Interesting note: I had a lot of "job" files in the windows tasks folder that are pointing to an odd file that doesnt exist (that I think the malware may have added, to keep itself active)

    C:\WINDOWS\system32\HJ82c.com_
    C:\WINDOWS\system32\HJ82c.com

    one task every hour for each
     
  7. Broni Malware Annihilator Posts: 40,051   +187

    Those shouldn't be there.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    64-bit users go HERE
    • Double-click SystemLook.exe to run it.
    • Vista users:: Right click on SystemLook.exe, click Run As Administrator
    • Copy the content of the following box and paste it into the main textfield:
      Code:
      :dir
      C:\WINDOWS\tasks
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
  8. rubydreamer Newcomer, in training Posts: 41

    Only reason I mentioned was since one of the security programs was asking me if i wanted to let this file run. (Note: Very good for noticing and stopping the tiny hidden under a second infection files)

    SystemLook 30.07.11 by jpshortstuff
    Log created at 19:51 on 26/02/2012 by HP_Administrator
    Administrator - Elevation successful

    ========== dir ==========

    C:\WINDOWS\tasks - Parameters: "(none)"

    ---Files---
    Ad-Aware Update (Weekly).job --a---- 486 bytes [15:40 24/06/2009] [20:46 26/02/2012]
    At1.job --a---- 344 bytes [21:27 21/02/2012] [05:30 26/02/2012]
    At10.job --a---- 346 bytes [21:27 21/02/2012] [09:30 26/02/2012]
    At11.job --a---- 344 bytes [21:27 21/02/2012] [10:30 26/02/2012]
    At12.job --a---- 346 bytes [21:27 21/02/2012] [10:30 26/02/2012]
    At13.job --a---- 344 bytes [21:27 21/02/2012] [11:30 26/02/2012]
    At14.job --a---- 346 bytes [21:27 21/02/2012] [11:30 26/02/2012]
    At15.job --a---- 344 bytes [21:27 21/02/2012] [12:30 26/02/2012]
    At16.job --a---- 346 bytes [21:27 21/02/2012] [12:30 26/02/2012]
    At17.job --a---- 344 bytes [21:27 21/02/2012] [13:30 26/02/2012]
    At18.job --a---- 346 bytes [21:27 21/02/2012] [13:30 26/02/2012]
    At19.job --a---- 344 bytes [21:27 21/02/2012] [14:30 26/02/2012]
    At2.job --a---- 346 bytes [21:27 21/02/2012] [05:30 26/02/2012]
    At20.job --a---- 346 bytes [21:27 21/02/2012] [14:30 26/02/2012]
    At21.job --a---- 344 bytes [21:27 21/02/2012] [15:30 25/02/2012]
    At22.job --a---- 346 bytes [21:27 21/02/2012] [15:30 25/02/2012]
    At23.job --a---- 344 bytes [21:27 21/02/2012] [16:30 25/02/2012]
    At24.job --a---- 346 bytes [21:27 21/02/2012] [16:30 25/02/2012]
    At25.job --a---- 344 bytes [21:27 21/02/2012] [17:30 25/02/2012]
    At26.job --a---- 346 bytes [21:27 21/02/2012] [17:30 25/02/2012]
    At27.job --a---- 344 bytes [21:27 21/02/2012] [18:30 25/02/2012]
    At28.job --a---- 346 bytes [21:27 21/02/2012] [18:30 25/02/2012]
    At29.job --a---- 344 bytes [21:27 21/02/2012] [19:30 26/02/2012]
    At3.job --a---- 344 bytes [21:27 21/02/2012] [06:30 26/02/2012]
    At30.job --a---- 346 bytes [21:27 21/02/2012] [19:30 26/02/2012]
    At31.job --a---- 344 bytes [21:27 21/02/2012] [20:30 26/02/2012]
    At32.job --a---- 346 bytes [21:27 21/02/2012] [20:30 26/02/2012]
    At33.job --a---- 344 bytes [21:27 21/02/2012] [21:30 25/02/2012]
    At34.job --a---- 346 bytes [21:27 21/02/2012] [21:30 25/02/2012]
    At35.job --a---- 344 bytes [21:27 21/02/2012] [22:30 25/02/2012]
    At36.job --a---- 346 bytes [21:27 21/02/2012] [22:30 25/02/2012]
    At37.job --a---- 344 bytes [21:27 21/02/2012] [23:30 25/02/2012]
    At38.job --a---- 346 bytes [21:27 21/02/2012] [23:30 25/02/2012]
    At39.job --a---- 344 bytes [21:27 21/02/2012] [00:30 26/02/2012]
    At4.job --a---- 346 bytes [21:27 21/02/2012] [06:30 26/02/2012]
    At40.job --a---- 346 bytes [21:27 21/02/2012] [00:30 26/02/2012]
    At41.job --a---- 344 bytes [21:27 21/02/2012] [01:30 26/02/2012]
    At42.job --a---- 346 bytes [21:27 21/02/2012] [01:30 26/02/2012]
    At43.job --a---- 344 bytes [21:27 21/02/2012] [02:30 26/02/2012]
    At44.job --a---- 346 bytes [21:27 21/02/2012] [02:30 26/02/2012]
    At45.job --a---- 344 bytes [21:27 21/02/2012] [03:30 26/02/2012]
    At46.job --a---- 346 bytes [21:27 21/02/2012] [03:30 26/02/2012]
    At47.job --a---- 344 bytes [21:27 21/02/2012] [04:30 26/02/2012]
    At48.job --a---- 346 bytes [21:27 21/02/2012] [04:30 26/02/2012]
    At5.job --a---- 344 bytes [21:27 21/02/2012] [07:30 26/02/2012]
    At6.job --a---- 346 bytes [21:27 21/02/2012] [07:30 26/02/2012]
    At7.job --a---- 344 bytes [21:27 21/02/2012] [08:30 26/02/2012]
    At8.job --a---- 346 bytes [21:27 21/02/2012] [08:30 26/02/2012]
    At9.job --a---- 344 bytes [21:27 21/02/2012] [09:30 26/02/2012]
    desktop.ini -rah--- 65 bytes [04:00 10/08/2004] [04:00 10/08/2004]
    GoogleUpdateTaskMachineCore.job --a---- 902 bytes [22:51 29/08/2010] [19:52 26/02/2012]
    GoogleUpdateTaskMachineUA.job --a---- 906 bytes [22:51 29/08/2010] [23:52 26/02/2012]
    MP Scheduled Scan.job --ah--- 330 bytes [08:45 19/08/2008] [07:18 26/02/2012]
    SA.DAT --ah--- 6 bytes [21:17 30/08/2005] [19:22 26/02/2012]
    switchShakeIcon.job --a---- 300 bytes [05:23 31/01/2011] [05:23 12/02/2011]

    ---Folders---
    None found.

    -= EOF =-
  9. Broni Malware Annihilator Posts: 40,051   +187

    I adjusted OTL fix code in my reply #65 to remove those files.
    You can proceed with my reply #65 now.
  10. rubydreamer Newcomer, in training Posts: 41

    Had copied the instructs to txt file, and ran old script accidentally, but the AT files were easily removed with windows scheduler after. (Either way, they are good and gone)

    As for the cleanup step, does it just delete certain files?

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: HP_Administrator
    ->Temp folder emptied: 22111794 bytes
    ->Temporary Internet Files folder emptied: 8459767 bytes
    ->Java cache emptied: 971143 bytes
    ->FireFox cache emptied: 95978632 bytes
    ->Google Chrome cache emptied: 49877168 bytes
    ->Flash cache emptied: 15317 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 207886 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 16560 bytes

    Total Files Cleaned = 170.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: HP_Administrator
    ->Flash cache emptied: 0 bytes

    User: LocalService
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: Administrator

    User: All Users

    User: Default User

    User: HP_Administrator
    ->Java cache emptied: 0 bytes

    User: LocalService
    ->Java cache emptied: 0 bytes

    User: NetworkService
    ->Java cache emptied: 0 bytes

    Total Java Files Cleaned = 0.00 mb

    Restore points cleared and new OTL Restore Point set!

    OTL by OldTimer - Version 3.2.32.0 log created on 02272012_033207

    Files\Folders moved on Reboot...
    File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\JET3336.tmp not found!
    File\Folder C:\WINDOWS\temp\Perflib_Perfdata_4b8.dat not found!

    Registry entries deleted on Reboot...
  11. Broni Malware Annihilator Posts: 40,051   +187

    It removes number of tools we used. Remove any leftovers manually.

  12. rubydreamer Newcomer, in training Posts: 41

    Well, as to how its doing, it was semi ok yesterday, today, it randomly reset and is now popping up a repeated "windows error" ("The system had recovered from a serious error." kind) and i have no idea why.

    Additionally, since updating Java, several things I do (that rely on java) refuse to work now.
  13. Broni Malware Annihilator Posts: 40,051   +187

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.
  14. Broni Malware Annihilator Posts: 40,051   +187

    The issue seems to be resolved.