Infection + otshot

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Klepton, Feb 11, 2013.

  1. Klepton

    Klepton Private E-2

    Hello. I am trying to clean a friend's daughter's mini laptop and was not able to get rid of a program called "otshot". When I first started working on the computer, I noticed some strange behavior typical of spyware/malware. Additionally, after the first reboot I noticed that this program called "otshot" would try to do something with Outlook and would popup a few windows. I removed it from the taskbar (exit), but was unable to uninstall it via "Control Panel->Uninstall a Program" because it does not show up on the list of installed programs. I then proceeded to update the computer and run some anti-spyware/malware programs on my own. I ran CCleaner, Malwarebytes' Anti-Malware, SUPERAntiSpyware, Spybot - Search & Destroy and TDSSkiller. However, I hadn't gone through the steps in the "READ & RUN ME FIRST" guide nor disabled UAC. Each time I would reboot, this program would popup and do its thing. I eventually emoved "otshot" from the Startup via CCleaner so it wouldn't startup automatically at windows startup. I kept its files in all its locations in hopes that one of these programs would remove it, but none of these scans even detected "otshot". Once I was done with all these scans, I kept getting an error with the McAfee VirusScan Plus program that was installed on the computer. It said it needed to be updated, but after updating and rebooting, it kept saying the same thing. Additionally, when I tried to run a virus scan I got an error that prevented me from doing so. I ended up uninstalling it and installing AVG Anti-Virus FREE 2013 instead. I ran a virus scan with AVG and it did not find anything. So I came here and followed the instructions for malware removal. Since I can only attach 5 files at a time, I'll post the old logs in this post followed by the new ones in a post immediately following this one. Attached here are only the OLD logs for the two programs, which are recommended in the guide, out of all the programs I ran before.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Klepton

    Klepton Private E-2

    Attached here are the NEW logs for the same 2 programs I had run before that are recommended to run here as well as the logs for the other 3.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See post #2.
     
  5. Klepton

    Klepton Private E-2

    I did see it. You posted it while I was posting my second reply (post #3). The problem is that Revo Uninstaller only seems to work on programs that are also listed by "Add/Remove Programs" or "Uninstall a Program". As I mentioned in my first post, "otshot" does not show up in the "Uninstall a Program" list in Windows. Therefore, this program is not showing up on the list of programs Revo Uninstaller can run on. In an effort to re-enable/re-install "otshot" (by running *otshot*.exe files found in the different locations) so that Revo Uninstaller can pick it up and completely uninstall it, AVG picked up a security threat. It got rid of it, but I hope I didn't get re-infected.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only place it shows up in your logs is in the program files. Can you delete it?
     
  7. Klepton

    Klepton Private E-2

    Well, I ran the executable files I could find for this program and I was able to re-enable it to the point where Revo Uninstaller picked it up. I then proceeded to successfully delete it. A Windows search did find traces of it in places other than c:/Program Files, so I deleted those as well. Is everything else fine? What about the other things found by the newest scans?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run Hitman and have it remove all those PUP;s. Then:

    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  9. Klepton

    Klepton Private E-2

    I successfully ran Hitman Pro and let it delete the 18 PUPs that were ignored before. I then ran JRT and am attaching its log file.
     

    Attached Files:

    • JRT.txt
      File size:
      5.8 KB
      Views:
      4
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having, if any?
     
  11. Klepton

    Klepton Private E-2

    I can't say one way or the other, as I haven't been using the computer while I was waiting for a reply. Is there a quick/easy way to find out?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just use it for a while and let me know.
     
  13. Klepton

    Klepton Private E-2

    It does seem fine. The internet browsers work good and it is fairly speedy now.
     
  14. Klepton

    Klepton Private E-2

    UPDATE: The computer was working fine yesterday as I mentioned previously.
    I left it on overnight with one browser window open to this forum. Apparently, it automatically installed some Windows Updates and rebooted. I logged in and after windows loaded, I read the notice that Windows had installed updates, but my touchpad was not working. I accessed the Start Menu with the keyboard button and restarted, but am having the same problem. My touchpad no longer works!
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am afraid you will have to pursue that in the software forum.
     
  16. Klepton

    Klepton Private E-2

    Ok, so I got my touchpad working again. I had to "Enable" it in Control Panel->Hardware and Sound->Devices and Printers->Mouse Properties->Device Settings, although I don't know how it got disabled in the first place. Especially since I did nothing to it overnight and it was working fine before. As I mentioned previously, the only thing that happened overnight is several Windows Updates were installed. However, everything that was downloaded on 02/13 was a Security Update.

    Anyhow, the pc seems to be working good. Can we move to the next steps or are there other program scans I should run?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  18. Klepton

    Klepton Private E-2

    Well, I am not having any typical easily identifiable problems with malware, so I would've assumed things were fine now. However, I ran an ESET Online Scan and it found two entries with multiple threats each. The only reason I ran it is because it was recommended to me for another computer in another thread. I figured it wouldn't hurt anything if I did, but I was surprised it found something that all previous scans didn't? Anyhow, since I didn't want to change anything until I heard from you, I unchecked the "Remove found threats" option. I wasn't sure if you'd simply have me run it again, but this time leaving that option checked so it can get rid of them, or whether you'd have me use something else to get rid of them. I have attached the ESET scan log.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can have it fix those items. But then you need to recycle your restore folder. That's the only way to remove any infections in your system restore.
     
  20. Klepton

    Klepton Private E-2

    Ok, I ran ESET and fixed the items it found. However, this time I selected "Scan for potentially unwanted applications" and "Scan for potentially unsafe applications" and it found a lot more threats. Since I selected "Remove found threats", it deleted all of them. I've attached the log.
     

    Attached Files:

  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since it found a few items in your recycle bin, have you emptied it? What issues are you having?
     
  22. Klepton

    Klepton Private E-2

    Yes, I ran CCleaner. I don't seem to be having issues anymore
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  24. Klepton

    Klepton Private E-2

    Final steps completed. Thank you very much!
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds