Solved

spyware rootkit Windows XP home

Posted on 2010-09-18
12
577 Views
Last Modified: 2013-12-06
I have spyware on on windows XP home sp3 computer I can't seem to remove. HJT and Combofix logs attached. Each time I run combofix it detects a rootkit and restarts the machine before running but fails to remove the malware. I have read the log file but don't recognize the problem.
hijackthis.log
ComboFix.txt
0
Comment
Question by:rettif9
  • 5
  • 3
  • 2
  • +1
12 Comments
 
LVL 23

Expert Comment

by:edbedb
Comment Utility
I would boot from a live CD like UBCD and replace these files with known good copies.  CLASSPNP.SYS, ACPI.sys, atapi.sys, ntkrnlpa.exe, NDIS.sys
0
 
LVL 65

Expert Comment

by:rockiroads
Comment Utility
probably trying to remove before windows kicks in.

have u tried running this in safe mode? you got malware bytes also so give that a go.

some people here mention hitman pro maybe give that a go

did u also try the other tools like tddskiler http://support.kaspersky.com/viruses/solutions?qid=208280684 and rootalyzer http://forums.spybot.info/showthread.php?t=24185
0
 
LVL 7

Author Comment

by:rettif9
Comment Utility
@ edbedb - this is the only Home machine I have access to at the moment. Would it be ok to copy those files from an XP pro workstation?
@ rockiroads - I should have mentioned I have already run Spybot S&D, Malwarebytes, and Superantispyware. I have run combofix normally and in safemode with the same result each time. I'll try the other tools you mentioned.
0
 
LVL 23

Expert Comment

by:edbedb
Comment Utility
Xp Pro should be fine as long as it is SP3
0
 
LVL 22

Accepted Solution

by:
optoma earned 500 total points
Comment Utility
0
 
LVL 7

Author Comment

by:rettif9
Comment Utility
@ edbedb - I copied the listed files to the folders I found them in but it had no effect.

@ all - I followed the instructions in KB article 971058 two of the dll files could not be found. I checked another machine (working) and it didn't have them either. wucltux.dll and wuwebv.dll FYI

@ optoma installed and ran hitmanpro and it did it. It found another rootkit in the MBR sorry guys I forgot to write down the name of the little bugger but the machine is running MS updates as I type.

Thanks to everyone for their efforts.
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 7

Author Comment

by:rettif9
Comment Utility
the instructions in the KB article had no effect....
0
 
LVL 65

Expert Comment

by:rockiroads
Comment Utility
glad your all sorted. big relief. so did you try all the tools I suggested then? even hitman pro which is what I also suggested? maybe should of given you the link then
0
 
LVL 22

Expert Comment

by:optoma
Comment Utility
@ Rockiroads. Sorry. I overlooked that you mentioned Hitmanpro :(
0
 
LVL 7

Author Comment

by:rettif9
Comment Utility
@ rockiroads - My apologies, you did mention hitmanpro first and I should have at least shared the  points. I simply overlooked it.

rettif9
0
 
LVL 7

Author Comment

by:rettif9
Comment Utility
@ rockiroads - just FYI I did try rootalyzer and tddskiler without success.
0
 
LVL 65

Expert Comment

by:rockiroads
Comment Utility
no probs, good idea to keep note of all the tools mentioned in case you get something again.
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

UPDATE - 6/15/2011 Added support for Release Update 6 Maintenance Patch 2 Point Patch 1 (RU6 MP2 PP1). Fixed a defect in the username field that was hard-coded to look for a specific domain (left over code from testing). This release will be the …
By the time you finish reading this article, you may have already lost all your money because you don't know the simple steps to securing your BitCoin wallet. BitCoin is an incredible invention. It is a decentralized currency system, which is the…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now