1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Excessive Hardware Interrupts caused by malware?

Discussion in 'Malware and Virus Removal Archive' started by flamingo, 2011/07/07.

  1. 2011/07/08
    flamingo

    flamingo Well-Known Member Thread Starter

    Joined:
    2011/07/06
    Messages:
    82
    Likes Received:
    0
    ESET ran for a couple of hours and ended with no threats detected. No logfile produced.

    ..Paul..
     
  2. 2011/07/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     

  3. to hide this advert.

  4. 2011/07/09
    flamingo

    flamingo Well-Known Member Thread Starter

    Joined:
    2011/07/06
    Messages:
    82
    Likes Received:
    0
    Did the run fix with the code you provided. However, when OLT attempted to reboot, the system said "shutting down ..." for six hours till I forced a reboot with the power switch. Machine booted OK and the log below was open. I haven't done anything else.

    ..Paul..

    =================

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: IUSR_NMPR
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Paul
    ->Temp folder emptied: 31832 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 56896397 bytes
    ->Flash cache emptied: 1081 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 149 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 54.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: IUSR_NMPR

    User: Paul
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.26.1 log created on 07082011_184011

    Files\Folders moved on Reboot...
    File move failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be moved on reboot.

    Registry entries deleted on Reboot...
     
  5. 2011/07/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go ahead with other steps...
     
  6. 2011/07/09
    flamingo

    flamingo Well-Known Member Thread Starter

    Joined:
    2011/07/06
    Messages:
    82
    Likes Received:
    0
    >Clean up with OTL:
    >
    > Double-click OTL.exe to start the program.
    > Close all other programs apart from OTL as this step will require a reboot
    > On the OTL main screen, press the CLEANUP button
    > Say Yes to the prompt and then allow the program to reboot your computer.

    I pressed CLEANUP. There was no prompt. The message at the bottom of the window was "Processing [deleteself]..... ". After about an hour nothing had changed. There was no evidence of disk activity or anything else. All of the scanner and log icons were unchanged. I forced a shutdown. On reboot, the OLT application was gone. I manually uninstalled or deleted the 8+ scan applications.

    My Time Warner cable connection died and would not reboot as I was about to post this. Time Warner was "aware of a problem in the area" so I crossed my fingers. It came up a couple hours later.

    I guess I am done. I don't know what the various logs meant. I didn't notice anything that looked like a virus/trojan/malware. The original problem of reported excessive hardware interrupts occurred infrequently (e.g., once a week or so) so it's hard to know if anything we did affected that. I guess I'll go back to the hardware forum to pursue questions about that issue.

    My machine seems to be working fine. Thanks very much for shepherding me through all the scanning and cleaning processes. I'll install or reinstall the various tools recommended above and see how that goes.

    Again, thanks a lot for the expert advice and assistance.

    ..Paul..
     
  7. 2011/07/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome [​IMG]

    This topic will remain open, so feel free to post back in case of any problems.

    Good luck!
     
  8. 2011/07/12
    flamingo

    flamingo Well-Known Member Thread Starter

    Joined:
    2011/07/06
    Messages:
    82
    Likes Received:
    0
    Things are fine. I installed the Secunia PSI product and was favorably impressed. Easy to install and understand. I found quite a few programs that needed updates or that were redundant. The program made it quite easy to find, fix, update, remove the programs that needed attention.

    The Web of Trust is pretty straightforward too. It seems to coexist with the Norton feature that does the same thing. I'll compare them for a while and then probably turn off the Norton feature.

    Sure glad I found this website. I have years of pent up questions that I'll post as they come up and seem to still be useful.

    ..Paul..
     
  9. 2011/07/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Way to go!! [​IMG]
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.