1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Persistent Bloodhound.PDF.28 infections

Discussion in 'Malware and Virus Removal Archive' started by unsmiley, 2011/06/19.

  1. 2011/06/20
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Guest
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: RR
    ->Temp folder emptied: 144896 bytes
    ->Temporary Internet Files folder emptied: 16791273 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 6185643 bytes
    ->Flash cache emptied: 656 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 66472 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 22.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Guest

    User: Public

    User: RR
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.24.1 log created on 06202011_205555

    Files\Folders moved on Reboot...
    C:\Users\RR\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File\Folder C:\Users\RR\AppData\Local\Temp\~DF07C4F7AD4692663C.TMP not found!
    File\Folder C:\Users\RR\AppData\Local\Temp\~DF1C764073176B2D2B.TMP not found!
    File\Folder C:\Users\RR\AppData\Local\Temp\~DF4B34F3755EF42D79.TMP not found!
    File\Folder C:\Users\RR\AppData\Local\Temp\~DFD92BE73D70E3659C.TMP not found!
    File\Folder C:\Users\RR\AppData\Local\Temp\~DFEE15C87C203BE971.TMP not found!
    File\Folder C:\Users\RR\AppData\Local\Temp\~DFFE7C3B9C945E810A.TMP not found!
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T5ZT523B\ads[5].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T5ZT523B\like[1].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T5ZT523B\L[1].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IF03DHWZ\99393-active-persistent-bloodhound-pdf-28-infections-2[1].html moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IF03DHWZ\drts[1].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IF03DHWZ\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C8EXFLK0\ads[3].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C8EXFLK0\audmeasure[1].gif moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C8EXFLK0\audmeasure[2].gif moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C8EXFLK0\download_foxit[2].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C8EXFLK0\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C8EXFLK0\sh44[1].html moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B9CN342S\;ord=1229916983[1].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B9CN342S\iframescript[1].htm moved successfully.
    C:\Users\RR\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
    File\Folder C:\windows\temp\hsperfdata_RR-PC$\2236 not found!

    Registry entries deleted on Reboot...
     
  2. 2011/06/20
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    Was able to delete Adobe reader. But even after opting out of most of the other garbage choices, installation of Foxit reader requires their toolbar. I don't see anyway out of it - and I don't want it. So I think I will just go with updated Adobe reader.

    Should I remove Java Ra files? Security Check? These icons are still on my desktop.

    I'm getting a message in Firefox: "1 new add on installed. Java console 6.0.26
    Java console 6.0.22 - and next to the second one there are choices to disable and to (I think) uninstall. Should I do either?
     

  3. to hide this advert.

  4. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    There is a trick to install FoxIt without that toolbar (I hate those people)...

    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or other garbage.
    On this page:

    [​IMG]

    make sure, you have both boxes UN-checked AND (important!) click on Decline button

    Yes.

    You need it. Leave it alone.

    Anything else?
     
  5. 2011/06/20
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    The Foxit reader installation wizard box appears to have changed since your version. There is no choice on the bottom to decline; you can uncheck those two boxes, but it says beneath them if you click NEXT you are agreeing to install that toolbar.
     
  6. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm at loss then :)
    Another option would be to simply uninstall Ask Toolbar after FoxIt installation.
     
  7. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm at loss then :)
    Another option would be to simply uninstall Ask Toolbar after FoxIt installation.
     
  8. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  9. 2011/06/20
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    FYI: The only one of the choice listed in your useful link that works is the softpedia one, then one must choose the softpedia mirror. Downloading from Foxit site doesn't impose the toolbar, but forces you to change your default search provider to Ask.com (yes I know it is easy to change it back, but...) BTW the installation wizard asks if you want to install PDF viewer (of course) and windows shells (or something like that). I checked only the PDF viewer. Is that correct?
     
  10. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It depends. The second option will add an option to right click menu.

    Anything else?
     
  11. 2011/06/20
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    Nope. I think that's it. Everything looks good, and the computer is also faster. I really appreciate your help. Thank you very much.
     
  12. 2011/06/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Way to go!! [​IMG]
    Good luck and stay safe :)
     
  13. 2011/06/22
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    I thought everything was OK, but upon going online today, Norton is again picking up numerous Bloodhound.PDF.28 infected files, analyzing them, then quarantining them.
     
  14. 2011/06/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'd need more info, including "infected" file names and locations.
     
  15. 2011/06/22
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    How can I copy the list of files from Symantec Endpoint Protection and paste them here? Highlighting them and copy and paste don't work. A typical file name is:

    DWHT18.temp Bloodhound.PDF.28

    They are all "DWHT.....tmp" files.

    Location of all of these files:
    C:\Users\RR\AppData\Local\Temp\
     
    Last edited: 2011/06/22
  16. 2011/06/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try to type couple of them manually.
    What's the location of those files?
     
  17. 2011/06/22
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    Original location of all of these files (before being quarantined by Symantec):
    C:\Users\RR\AppData\Local\Temp\

    Names of these files all start with DWH followed by some numbers and/or letters.tmp;

    example name of one of the dozens of these files is: DWHA99.tmp
     
  18. 2011/06/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  19. 2011/06/22
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    Is this something to worry about?

    From reading some of the posts you suggested, it appears that Symantec scans the files in quarantine each time, which multiplies the number of "infected" files. So I deleted the quarantined files, even though I know that won't solve the problem.

    Anything else can you suggest?
     
  20. 2011/06/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm not sure, what to tell you short of switching to some other product.
    It looks like some Norton glitch.
    Your computer is definitely clean.
     
  21. 2011/06/22
    unsmiley

    unsmiley Inactive Thread Starter

    Joined:
    2011/06/19
    Messages:
    23
    Likes Received:
    0
    What about this:

    http://www.symantec.com/connect/downloads/squash-symtmps-mikes-tool-set

    According to the author, "This utility is really for MR4, RU5 or RU6 or machines that have been UPGRADED to RU6 MP1...if you have a fresh install of RU6 MP1 or later...then the problem should have already been resolved and this utility will do you no good. In fact, directories may have changed in later versions of SEP and you may actually break something. "

    I have a fresh installation of Symantec Endpoint Protection 11.0.6005.562. Would that be one of the versions not suitable for this tool?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.