Phantom user accounts

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sflee, Jul 17, 2006.

  1. sflee

    sflee Private E-2

    I recently discoverd that a number of new directories have appeared in my "Documents and Settings Folder". They are named as combinations of directories that were created when user accounts were created (ie. Steven.Taylor or Steven.000). These appear to be clones of other pre-existing directories containing all of the same files. However they do not show up as user accounts at log on or when switching users.

    When I attempt to delete these directories I get a message"Cannot delete AntiPhishing". However I cannot locate a file by this name (I do have view system and hidden files activated). I have googled AntiPhishing and found only a couple of entries (both in German).

    I suspect that this is the result of some malware on my system and have followed all of your "do these first steps".

    However before I post the logs of my various scans I thought I would ask if any of the forgoing is a known or common phenomenon. I may be barking up the wrong tree completely.

    Thanks
     
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If you have done a "Repair" install you can get directories like this. Some forms of Malware can do this also.

    Post your logs and we'll have a look to see what is there.
     
  3. sflee

    sflee Private E-2

    Here are my scans. Thanks in advance.
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  5. sflee

    sflee Private E-2

    Thanks. I didn't see an option for saving a log file from VundoFix but it reported that no files were found. I am attaching the most current Hijackthis log file.
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  7. sflee

    sflee Private E-2

    here is the vundofix log - thanks for pointing out where it was.
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Uninstall the following Java Versions:
    Java version is 1.4.2.5
    Java version is 1.5.0.3
    Java version is 1.5.0.6

    Install Java Version 1.5.0_07 available from http://java.sun.com/javase/downloads/index.jsp.

    Clear the Sun Java Cache

    Download
    - Pocket Killbox

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  9. sflee

    sflee Private E-2

    Followed all your instructions. For what it is worth IE loads much faster now than it did earlier today.

    Here is the most recent Hijackthis log.

    Thanks again for all your help.
     

    Attached Files:

  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds