Bloodhound w32.ep virus removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by biggers99, Apr 2, 2006.

  1. biggers99

    biggers99 Private E-2

    Hi there,

    I operate on Windows XP Home and use a Compaq Presario which is about 5 years old. I've completed all the actions from the Read me and Run me first page but have been unable to remove the Bloodhound w32.ep virus. I am constantly advised of it's existence by a Norton pop up that says it can't fix the file - the object details are C:\WINDOWS\SYSTEM32|WININET.DLL. It causes what seems to be common from reading other threads e.g. slow running, long time to log on. Also my IE Browser is "about:blank" - this has been the case for a long time and I use Mozilla but thought you might want to know this.

    If it helps I think I picked this virus up around the time I tried to download AVG - when I also picked up PS Guard that keeps coming back.

    I have attached the results of the Counter Spy scan and also Hijack This. When I ran Bite Defender it did pick up a load of stuff but as soon as the scan was completed (it took over an hour) Internet explorer just closed down of it's own accord without giving me a chance to save a log

    I'm hoping you can help out. Many thanks
    Mark
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not attach your PandaActiveScan log as required BUT do not run it again now! Also you did not follow the instructions in step 7 of the READ ME and as a result, you do not have HijackThis install correctly. In fact you are running it directly from the ZIP file which we specifically request that you not do. Please fix this now before you continue.

    Your OS and IE versions are way out of date and represent a major security risk to you. After we fix any malware problems, you must get updated.

    Now run this: SpywareStrike, Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    You will not see many of the items mentioned in the SmitRem procedure. That's okay, just continue on thru to the end and now also attach the requested PandaActiveScan log along with the smitfiles.txt log.
     
    Last edited: Apr 3, 2006
  3. biggers99

    biggers99 Private E-2

    Thanks Chaslang,

    Sorry about missing the Hijack This instruction - I have now extracted it and ran a scan as part of the procedure you asked me to do - I'm not sure if you needed a HJT log saved so I haven't at this stage. I have now attached the smit file and the Panda file.

    The Norton pop up warning me about the Bloodhound virus seems to have stopped. When I logged on I got a pop up window titled "Notice" which said that an Internet Explorer URL Change Requires approval - which I am aksed to Allow or Block - I've done nothing with it as I'm not sure where it came from.

    I still have PS Guard icon on my desktop.

    You mentioned about OS and IE versions being out of date - what do i need to do? Does it matter that I don't normally use IE but Mozilla?

    Cheers
    Mark
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
    O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\notepad.com
    C:\WINDOWS\system32\ms0b920b.dll
    C:\Downloads for fixes\toolbar_uninstall.exe

    Additional step to delete WildApp.inf:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s WildApp.inf
    del WildApp.inf
    exit


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings (if you get another popup about a change to your start page or other pages, allow it since we are doing it):
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  5. biggers99

    biggers99 Private E-2

    Hi Chaslang,

    I've done all of that and have posted the HJT log.

    All seems to be relatively OK - I'm still not getting the Norton pop up re Bloodhound so that's good.

    I still have PS Guard icon on my desktop + not sure what do about upgrading OS and IE that you mentioned in your 1st post. PC log on and general operation is still not as fast as it was pre-virus.

    Thanks
    Mark
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just delete the PSGuard icon by right clicking on it and selecting Delete. Does that work?

    Is your CounterSpy version the free trial or a paid version? If free, uninstall it and keep MS Antispyware (for now until you get Win XP SP2, then you would change to Windows Defender).
    If CounterSpy is the paid version, uninstall MS Antispyware.

    Then if you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!


    The first step in the above is going to take you to Windows update so you can get your OS and IE versions updated. These are going to be very large updates so hopefully you have a high speed internet connection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds