Author Topic: [Resolved K] Virus/rookit? redirecting searches, change file attributes,  (Read 1690 times)

0 Members and 1 Guest are viewing this topic.

Offline OzLK

  • Bronze Member
  • Posts: 12
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #15 on: February 04, 2012, 06:43:03 PM »
Hi Kevinf80
Completed OTMoveit process. Log below.
Do I now restore the boot flags I changed before (when I booted with the CD)?

Completed Java update
Upgraded to IE9 (still getting use to it partic the text)  :l
So far so good. :)1
However, there is one issue I don't know whether its related - my desktop gadgets disappeared at the time my system was playing up. I cannot get them back. The instructions say to right click on desktop to "view" and tick gadgets but I do not have a "gadgets" option there. Can you help or point me in the right direction please?

Are we done?
 :ty THANK YOU VERY MUCH FOR YOUR HELP. ITS BEEN A LONG PROCESS  :p

All processes killed
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Lily\Desktop\cmd.bat deleted successfully.
C:\Users\Lily\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Lily
->Temp folder emptied: 836321030 bytes
->Temporary Internet Files folder emptied: 36923241 bytes
->Java cache emptied: 188793 bytes
->Flash cache emptied: 19174 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 373490458 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 71971 bytes
RecycleBin emptied: 362334143 bytes
 
Total Files Cleaned = 1,535.00 mb
 
 
Restore point Set: OTM Restore Point
 
OTM by OldTimer - Version 3.1.19.0 log created on 02052012_092541

Files moved on Reboot...
C:\Users\Lily\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot...

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6343
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #16 on: February 05, 2012, 03:05:37 AM »
Hiya OzLK,

The fix takes a long time because we are online at different times, that is unfortunte. Regarding the boot flags, I already told you they are correct now and must be left alone. (Reply #12) If you alter them your system will not boot!

OK we can clean up what we have used:

Step 1

  • Download OTC by OldTimer and save it to your desktop. Alternative mirror
  • Double click icon to start the program.
    If you are using Vista or Windows 7, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
  • This will remove tools we have used and itself. Any tools/logs remaining on the Desktop can be deleted.
If any of the following remain on your Desktop either delete or drag to the recycle bin:

RogueKiller
RKQuarantine folder
RKReport.txt
Security Checks
Checkup.txt


Step 2

Remove ESET online scanner:

  • Click Start, type Uninstall a Program into the Search programs and files box, and then press ENTER.
  • Click to select ESET Online Scanner from the listing of installed products, and then click Uninstall/Change from the bar that displays the available tasks. Uninstall ESETonline Scanner, only re-boot if prompted.
Step 3

Download TFC  to your desktop, from either of the following links
 Link 1
 Link 2
  • Save any open work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program. Vista or Windows 7 users right click and select “Run as Administartor”
  • If prompted, click "Yes" to reboot.
TFC will automatically close any open programs, including your Desktop. Let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds.  TFC may re-boot your system, if not Re-boot it yourself to  complete cleaning process <---- Very Important

Keep TFC it is an excellent utility to keep your system optimized, it empties all user temp folders, Java cache etc etc.  Always remember to re-boot after a run, even if not prompted

Let me know if those steps complete OK.

Regarding your Gadgets, do this:

Select > Start > Control Panel > Programs > "Turn Windows Features On or OFF" > Scroll to "Windows Gadget Platform" make sure that item is check marked (ticked) > Select OK. Reboot if prompted.

Go back to your Desktop > Right click in an open area > select "View" make sure "Show Desktop Gadgets" is ticked. Right click on the Desktop again > Select "Gadgets" double click on each chosen gadget to show on your Desktop.

OK if all of the above completed OK we can now delete the small rogue partition, it is quite safe and will not harm your system in any way.

  • Re-boot with the GParted Live CD again.
  • Follow the previous instructions until you are at the main GUI as below:



  • Select the small rogue partion, click the trash can icon to delete and then click Apply. Then confirm your actions:



  • Double click on the Button.

  • At the next window select "Reboot" then "OK" Boot into Normal Windows.


Let me know if you have any remaining issues or concerns....

Kevin  :t


Offline OzLK

  • Bronze Member
  • Posts: 12
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #17 on: February 05, 2012, 07:47:09 AM »
Hi Kevinf80
I wasn't complaining about the timing before - it was simply a comment. I really appreciate how quickly you respond.

All done  :t but with a few issues I don't know whether are serious or not :sd:

1. OTC will not download. Comes up with message "OTC.exe might have been moved or deleted". Also got a popup from McAfee saying Trojan Quarrantined. BTW when I right click it does not have an option to run as administrator (perhaps I am logged in as administrator?). Tried it several times and also tried to click on Alternative mirror and got the same result.
HOWEVER, I assume this is the same program that I downloaded this morning so I ran the CleanUp process using the previous downloaded file.

2. Ditto with TFC. HOWEVER, with this file it gave me the option of "RUN" (which I did not get with OTC). I clicked on RUN and it seem to work - at least I can see the script saying deleting various items.

Other processes seemed to be OK.
Searches seem OK and I am not being redirected now, USB ports seem OK (forgot to mention before but they were intermittant)  :p

THANK YOU THANK YOU THANK YOU VERY MUCH   :ty

If the problems reoccur over the next week or so do I add to this post or start a new one?

« Last Edit: February 05, 2012, 07:50:57 AM by OzLK »

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6343
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #18 on: February 05, 2012, 09:12:57 AM »
TFC is a temporary file cleaner, it is worth keeping for that purpose. Always re-boot when finished, even if not prompted.

OTC is a different application, this removes tools we have used and itself, the instructions included two links. Did you try both?

EDIT....

Try these links....

http://www.itxassociates.com/OT-Tools/OTL.exe
http://www.itxassociates.com/OT-Tools/OTL.com
http://www.itxassociates.com/OT-Tools/OTL.scr
« Last Edit: February 05, 2012, 10:02:43 AM by kevinf80 »

Offline OzLK

  • Bronze Member
  • Posts: 12
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #19 on: February 05, 2012, 10:47:22 AM »
Hi Kevinf80

Yes, I tried both links but neither worked.
However, your new links downloaded (at least the first one, did not try the rest).
Ran both processes again.
Seem OK

Thanks  :t

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6343
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #20 on: February 05, 2012, 11:02:10 AM »
Your latest logs are clean and you say that your system is running well, it would be an excellent idea to keep it that way. The following advice will go along way to keeping you secure so that you can enjoy safe and happy surfing.

Here are some tips to reduce the potential for malware infection in the future:

Make proper use of your antivirus and firewall

Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.

You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.

Install and use WinPatrol  This will inform you of any attempted unauthorized changes to your system.

WinPatrol features explained Here

You will have several programs installed, these maybe outdated and vulnerable to exploits also. To be certain, please run the free online scan by Secunia, available Here   Before clicking the Start scan  button, please check the box for the option Enable thorough system inspection. Just below the "Scan Options:" section, you'll see the status of what's currently processing....
...when the scan completes, the message "Detection completed successfully" will appear in the Programs/Result section. For each problem detected, Secunia will offer a "Solution" option. Please follow those instructions to download updated versions of the programs as recommended by Secunia.

Use a safer web browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
 
Firefox,

Opera, and

Chrome.
 
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.

These browser add-ons will help to make your browser safer:

Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:

Available for Firefox and Internet Explorer.

Green to go,
Yellow for caution, and
Red to stop.


Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.

These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.

Here a couple of links by two security experts that will give some excellent tips and advice.

So how did I get infected in the first place by Tony Klein

How to prevent Malware by Miekiemoes

Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.

Don`t forget, the best form of defense is common sense. If you don`t recognize it, don`t open it. If something looks to good to be true, then it aint.

Let me know when you`re OK to close out your thread,

Take care,

Kevin  :t

Offline OzLK

  • Bronze Member
  • Posts: 12
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #21 on: February 06, 2012, 06:32:14 AM »
Hi Kevinf80
Can we leave this thread open for a few more days please?  :b
I want to try out a new browser and may have questions.

Thanks

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6343
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #22 on: February 06, 2012, 12:06:10 PM »
OK, I`ll leave it open for you, let me know when you`re ready to close...

Kevin :t

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6343
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #23 on: February 10, 2012, 01:55:13 AM »
Are you still around OzLK, I usually close out if no activity after 3 days..  :)1

Offline OzLK

  • Bronze Member
  • Posts: 12
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #24 on: February 10, 2012, 06:34:53 AM »
Hi Kevinf80,

So far so good. I have been using Google Chrome and it seems to be working well.  :t
I think you can close the thread now.
Hopefully, its all fixed.
Thank you very much for your help. Until this happened I did not know there were good people like you doing such good work.
 :ty

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6343
Re: [In Progress K] Virus/rookit? redirecting searches, change file attributes,
« Reply #25 on: February 10, 2012, 11:59:14 AM »
Since this issue appears to be resolved the topic has been closed. Glad we could help.  :t

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

The fixes and advice in this thread are for this System only. Do not apply the instructions from this thread to your own System. Please start a new thread describing your issue and someone will be along to assist you.