Solved

spyware rootkit Windows XP home

Posted on 2010-09-18
12
622 Views
Last Modified: 2013-12-06
I have spyware on on windows XP home sp3 computer I can't seem to remove. HJT and Combofix logs attached. Each time I run combofix it detects a rootkit and restarts the machine before running but fails to remove the malware. I have read the log file but don't recognize the problem.
hijackthis.log
ComboFix.txt
0
Comment
Question by:rettif9
  • 5
  • 3
  • 2
  • +1
12 Comments
 
LVL 23

Expert Comment

by:edbedb
ID: 33709293
I would boot from a live CD like UBCD and replace these files with known good copies.  CLASSPNP.SYS, ACPI.sys, atapi.sys, ntkrnlpa.exe, NDIS.sys
0
 
LVL 65

Expert Comment

by:rockiroads
ID: 33709335
probably trying to remove before windows kicks in.

have u tried running this in safe mode? you got malware bytes also so give that a go.

some people here mention hitman pro maybe give that a go

did u also try the other tools like tddskiler http://support.kaspersky.com/viruses/solutions?qid=208280684 and rootalyzer http://forums.spybot.info/showthread.php?t=24185
0
 
LVL 7

Author Comment

by:rettif9
ID: 33709422
@ edbedb - this is the only Home machine I have access to at the moment. Would it be ok to copy those files from an XP pro workstation?
@ rockiroads - I should have mentioned I have already run Spybot S&D, Malwarebytes, and Superantispyware. I have run combofix normally and in safemode with the same result each time. I'll try the other tools you mentioned.
0
Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
LVL 23

Expert Comment

by:edbedb
ID: 33709489
Xp Pro should be fine as long as it is SP3
0
 
LVL 22

Accepted Solution

by:
optoma earned 500 total points
ID: 33709769
0
 
LVL 7

Author Comment

by:rettif9
ID: 33709883
@ edbedb - I copied the listed files to the folders I found them in but it had no effect.

@ all - I followed the instructions in KB article 971058 two of the dll files could not be found. I checked another machine (working) and it didn't have them either. wucltux.dll and wuwebv.dll FYI

@ optoma installed and ran hitmanpro and it did it. It found another rootkit in the MBR sorry guys I forgot to write down the name of the little bugger but the machine is running MS updates as I type.

Thanks to everyone for their efforts.
0
 
LVL 7

Author Comment

by:rettif9
ID: 33709886
the instructions in the KB article had no effect....
0
 
LVL 65

Expert Comment

by:rockiroads
ID: 33710101
glad your all sorted. big relief. so did you try all the tools I suggested then? even hitman pro which is what I also suggested? maybe should of given you the link then
0
 
LVL 22

Expert Comment

by:optoma
ID: 33710706
@ Rockiroads. Sorry. I overlooked that you mentioned Hitmanpro :(
0
 
LVL 7

Author Comment

by:rettif9
ID: 33711449
@ rockiroads - My apologies, you did mention hitmanpro first and I should have at least shared the  points. I simply overlooked it.

rettif9
0
 
LVL 7

Author Comment

by:rettif9
ID: 33711465
@ rockiroads - just FYI I did try rootalyzer and tddskiler without success.
0
 
LVL 65

Expert Comment

by:rockiroads
ID: 33711555
no probs, good idea to keep note of all the tools mentioned in case you get something again.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2010 DAG 8 102
Comparison of Enterprise Level Software 3 72
WinZIp - quick question 8 12
Is Windows Defender in W10 sufficient protection? 5 26
Sub-Titled: “My Way” (with apologies to Francis Albert Sinatra) Let me start by stating emphatically that I am one of those Experts who prefer doing things “My Way”. It’s kind of a no-brainer. “The following procedure works for me, so here is …
It started not too long ago. It was at first annoying. My keystrokes seemed to be randomly generated, not the ones I typed on the keyboard. For some reason this only happened in certain applications (especially browsers such as IE11, Firefox and Chr…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question