1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Possible TDL3 Infection and other Infections for sure

Discussion in 'Malware and Virus Removal Archive' started by DCHammer, 2011/01/09.

  1. 2011/01/11
    DCHammer

    DCHammer Well-Known Member Thread Starter

    Joined:
    2010/06/28
    Messages:
    224
    Likes Received:
    0
    Step 1 complete, here is the log.
    Immediately after posting this I'll run the cleanup.

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: admdswlb
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: dcarlson
    ->Temp folder emptied: 25926 bytes
    ->Temporary Internet Files folder emptied: 109038 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 65252776 bytes
    ->Flash cache emptied: 952 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: IT_Admin
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: wbrownin
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 66751 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 6127875 bytes

    Total Files Cleaned = 68.00 mb


    [EMPTYFLASH]

    User: admdswlb
    ->Flash cache emptied: 0 bytes

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: dcarlson
    ->Flash cache emptied: 0 bytes

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: IT_Admin
    ->Flash cache emptied: 0 bytes

    User: Public

    User: wbrownin

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.20.1 log created on 01112011_001129

    Files\Folders moved on Reboot...
    C:\Users\dcarlson\AppData\Local\Temp\ExchangePerflog_8484fa313ab9df6cdcd6c672.dat moved successfully.
    C:\Users\dcarlson\AppData\Local\Temp\~DF6F27EF677574DD4D.TMP moved successfully.
    C:\Users\dcarlson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{5968D62C-0738-433B-85BD-9F3F2EFFE07E}.tmp moved successfully.
    C:\Users\dcarlson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{0C986CE3-CFED-4700-A47C-53475B6F9340}.tmp moved successfully.
    C:\Users\dcarlson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{2059CA70-4CB5-4454-8E14-8C55EDB38D97}.tmp moved successfully.
    C:\Users\dcarlson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{41807072-DCE8-4319-9414-7765690718D6}.tmp moved successfully.
    File\Folder C:\Users\dcarlson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{75B92CA0-BE5F-4434-8670-77ADA70E6773}.tmp not found!

    Registry entries deleted on Reboot...
     
  2. 2011/01/11
    DCHammer

    DCHammer Well-Known Member Thread Starter

    Joined:
    2010/06/28
    Messages:
    224
    Likes Received:
    0
    Ok, everything is done except for changing ALL of my online passwords.
    I've done the critical ones tonight and the rest I'll work my way through tomorrow.
    Man I hope we've got it.
    If this thing is clean for the rest of the week and doesn't reinfect itself, I'll be making a $100 donation.
     

  3. to hide this advert.

  4. 2011/01/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  5. 2011/01/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I assume, you're not experiencing any visible issues right now?
     
  6. 2011/01/11
    DCHammer

    DCHammer Well-Known Member Thread Starter

    Joined:
    2010/06/28
    Messages:
    224
    Likes Received:
    0
    No visible issues at all. I just wiped out the restore points. I'll reboot and turn them back on. They were disabled, I just needed to Delete what was there.
     
  7. 2011/01/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    In that case, I'll mark this thread as resolved.
    We don't close topics, so if anything comes up, post back here.

    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.