InfoStealer - Lanmandrv.sys

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bcampesi, May 23, 2008.

  1. bcampesi

    bcampesi Private E-2

    Here I go again,

    My son entered yesterday in a web page to play a game, and my PC got messed up again...

    I ran the READ & RUN ME FIRST and it looks good now...The only thing is that when I was half way of these steps, Norton Antivirus was still detecting the following:

    Threat: Infostealer
    Filename: lanmandrv.sys
    Location: C:\WINDOWS\System32

    I just wanted to upload the log files from this and see if you see something else I need to do...

    I could not upload the logs from MGLogs.zip as I only can upload 3 files...Will try after I post this.

    Thanks a lot....

    P.S.: Yes, I have now closed access to my kids on this PC
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are still a few things to remove, so please attach the C:\MGLogs.zip with your next reply. :)
     
  3. bcampesi

    bcampesi Private E-2

    Attaching the file...
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You look pretty good...let's just do this:

    Use add/remove programs to uninstall:
    Java(TM) 6 Update 4

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now install:
    Java Runtime 6

    Attach the Avenger log and tell me how things are running.
     
  5. bcampesi

    bcampesi Private E-2

    Uninstalled JAVA
    Ran Avenger
    Reinstalled new version of JAVA

    PC seems to be running fine

    Attaching Avenger log file

    Thanks
    Bernardo
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good....If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  7. bcampesi

    bcampesi Private E-2

    Everything looks fine....

    Thank You very much!!
    Muchas Gracias
    Muito Obrigado
    Merci beaucoup
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds