Yesterday, Thursday April 9, I had a friend's infected laptop.
All kinds of bad stuff going on with this thing. Did the usual, removed the malware and uninstalled the bad apps, (Windows XP Ant-Virus, Windows XP anti-virus Pro, etc.)
Finally, I wiped my brow and thought, it's finally clean. AV time. So I downloaded and registered a free version of an AV (Home Edition) and installed it. Ran the scan... and to my dismay!! Viruses! The bad kind.
Explorer.exe (%systemroot%\explorer.exe) infected!! Could not be cleaned.
Lsass.exe (%systemroot%\lsass.exe)
Winlogon.exe (%systemroot%\winlogon.exe)
Services.exe (%systemroot%\services.exe)
SVChost.exe (%systemroot%\svchost.exe)
All the legitimate ones! I downloaded and tried all the tools for removal from all the major and not so major vendors. And nothing! Nothing could clean these files, delete them or get rid of my viruses.
I figured, right before I gave up, I would give it one more shot. The LONG shot.
So I proceeded to remove the HDD from the infected machine. I downloaded the Service Pack for the machine that was infected, in this case XP SP2.
- Ran the SP2 installer from a COMMAND prompt with the /x option and extracted to a partition on the clean machine.
Updated the AV (Symantec EP) on another machine, removed that machine from the network and installed the HDD in it.
I allowed the drive to be scanned, and SEP said, bad things here. And deleted the culprits. Very important files from Windows in order to successfully.
This is exactly what I wanted to happen.
Back to the COMMAND prompt. Service Pack was extracted to the C:\temp folder.
expand c:\temp\i386\explorer.ex_ e:\windows\explorer.exe
expand c:\temp\i386\lsass.ex_ e:\windows\lsass.exe
expand c:\temp\i386\svchost.ex_ e:\windows\svchost.exe
expand c:\temp\i386\services.ex_ e:\windows\services.exe
expand c:\temp\i386\winlogon.ex_ e:\windows\winlogon.exe
No more Boot Sector virus! Scanned with SEP and machine is clean.
**Problem**
If I scan with SFC it will not recognize the date stamp on the Executables, I put in from the SP. So will want to squash them.
**Solution**
Installed SP3 on top of the now clean machine. Date stamps good again.
Seems long to do, but I spent 4 and a half hours trying to remove the damn thing before coming up with this 15 minute solution.
Cheers.