I just downloaded Windows defender after battling all weekend to rid my
system of a Malware trojan that my up to date McAfee Antivirus found, but
would not fully clean as I'd rebouut, rescan and there it was again. I went
through the painfully time consuming removal process described at:
http://forums.mcafeehelp.com/showthread.php?t=227241 including having to
rename everything before running the suggested packages. I was 99.9% sure it
worked because I rebooted, and a McAfee scan founnd nothing, and mu browsers
behaved as expected. This trojan would redirect you to random links after
clicking on a link from a Google Search and I had none of that. Less than 30
seconds after starting my first Windows Defender Scan, Mcafee finds the same
trojan, and it says it found it in winidows defender. Details:
Name: c:\windows\system32\gaopdxardpayglmkuoecuirmayoeyquqkqrimh.dll
In Folder: c:\windows\system32
Source:
Detected As: DNSChanger.r
Detection Type: Trojan
Status: Cleaned (but I doubt it)
Date ant Time: 4/9/2009 10:55:01
Application:C:\Program Files\Windows Defender\MsMpEng.exe
Username: NT AUTHORITY\System
Client ID:0(my pc name)
Any thoughts as to what might be going on?
Preferred practice is to 'flatten' and rebuild a computer that has been
exposed to malware.
http://www.microsoft.com/technet/community/columns/secmgmt/sm0504.mspx
http://technet.microsoft.com/en-au/library/cc512595.aspx
Clean Install Windows XP
http://www.elephantboycomputers.com/page2.html#Reinstalling_Windows - What
you will need on-hand
--and--
http://www.michaelstevenstech.com/cleanxpinstall.html
--or-- (even better because its illustrated and more reader friendly)
How Do I Install WindowsXP
http://xphelpandsupport.mvps.org/how_do_i_install_windows_xp.htm
Step-By-Step Windows Vista: Installation
http://www.w-tweaks.com/html/windows_vista_setup__step_by_s.html
It is defenitely advantageous to create an 'image' of the operating system
and create a data/file backup of the affected PC.
The image can then restored to the impacted PC and the user's data/file is
subsequently restored to the operating system.
An experienced and properly prepared user can do that in substantial less
time than scanning with complex and sophisticated AV applications.
Alas, since many users are less prepared and/or lacking the experience;
Scanning with an AV apps. is the only option, unless the user consults a
computer technician.
If you're one of the many less-experienced users, try to go through the
succeeding steps 1-4:
1.Clear the (IE) temporary Internet files and the history cache.
Click 'Start' and then click 'Run'... then type (or copy/paste)
"inetcpl.cpl" (w/out quotation marks) into the box, then click the 'OK'
button.
In Internet Properties panel 'General' tab, under 'Browsing history', click
'Delete...'button, in 'Delete Browsing History' panel, click the 'Delete
all...' button then place a checkmark into the box beside 'Also delete
files and settings stored by add-ons', Click 'Yes' and exit the Internet
Properties panel by clicking the 'OK' button.
2.Clean HDD
Click 'Start' and then click 'Run...' then type (or copy/paste) "cleanmgr"
(w/out quotation marks into the box, then click the 'OK' button. Select
your drive (presumably WinXP (C
and click OK.
http://support.microsoft.com/kb/310312
--or--
2a.Delete files using Disk Cleanup (if on Vista)
http://windowshelp.microsoft.com/Windows/en-US/help/1264bc24-72a8-48aa-84e3-a355327139d91033.mspx
3.Download/execute:
Malwarebytes© Corporation - Anti-Malware
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=mncol
--or--
http://majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
--direct--
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
--and--
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html
--direct--
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE
Both free versions of MBAM and SAS are on-demand scanners and offer no
'real-time' protection. Keep them installed and use them as
'second-opinion' scanner which is purposely (by design) recommended by
their respective authors.
4.Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis
Please, do not post HJT logs to this newsgroup.
Fora where you can get expert advice for HiJack This! (HJT) logs.
http://www.thespykiller.co.uk/index.php?board=3.0
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.tomcoyote.org/index.php?showforum=27
http://www.bleepingcomputer.com/forums/forum22.html
http://www.malwarebytes.org/forums/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://www.theeldergeek.com/forum/index.php?s=2e9ea4e19d3289dd877ab75a8220bff6&showforum=29
NOTE:
Registration is required in any of the above mentioned fora before posting
a HJT log and read the 'stickies' (instructions/guidelines) for the
respective HJT forum.
Additional references:
Malicious Software Removal Tool
http://www.microsoft.com/security/malwareremove/default.mspx
(Skip: Run an Online Scan of Your PC for Malicious Software).
How to optimize or reset Internet Explorer
http://support.microsoft.com/kb/936213
Applies to: Windows Internet Explorer in Windows Vista
How to use Reset Internet Explorer Settings (RIES)
http://support.microsoft.com/kb/923737
Read: "What you must know"
Applies to: Windows Internet Explorer for Windows XP and
Windows Internet Explorer 7 in Windows Vista
GMER - is an application that detects and removes rootkits.
http://www.gmer.net/index.php
For additional assistance in relation GMER scan results consult either:
http://www.thespykiller.co.uk/index.php?board=3.0
--or--
http://antirootkit.com/forums/index.php?sid=9e746bb696ac0bb38781ffe4361c3a17
CCleaner - Free
Cleans temporary internet files, cookies, history, recent urls, application
MRUs, etc. ...(*Tune out the registry scanning/fixing option!*)
http://www.ccleaner.com/download/builds/downloading-slim
If Windows Defender is utilized go to Applications, under Utilities
uncheck "Windows Defender" (so it won't delete the history of WD).
If you wish, click 'Options' button the 'Settings' [check] 'Run CCleaner
when the computer starts'.
--or--
Setup CCleaner to Automatically Run Each Night in Vista or XP
http://www.howtogeek.com/howto/wind...-automatically-run-each-night-in-vista-or-xp/
Routinely practice Safe-Hex.
http://www.claymania.com/safe-hex.html
Good luck