Need Help : Trojan.Lootseek keeps coming back 1

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fferay, Sep 24, 2006.

  1. fferay

    fferay Private E-2

    Hi,

    I got this Trojan Lootseek. It keeps coming back every now and then. Norton deletes it but apparently not completely.

    I followed the READ & RUN ME FIRST post. Here are the attachments.

    Thanks,
    Fab
     

    Attached Files:

  2. fferay

    fferay Private E-2

    Need Help : Trojan.Lootseek keeps coming back 2

    Here are the last 2 attachments...

    Fab
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Need Help : Trojan.Lootseek keeps coming back 2

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0

    Now do you know if the below line has anything to do with all this anonymous proxy server stuff you have setup:
    O20 - AppInit_DLLs: ASAPHook

    Also what is the below for?
    O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll

    Is the below your desired start page?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.free.fr/

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - REG:system.ini: Shell=
    O4 - HKCU\..\Run: [Tok-Cirrhatus-2421] "C:\Documents and Settings\Fab_2\Local Settings\Application Data\br5865on.exe"

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Fab_2\Local Settings\Application Data\br5865on.exe

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode!
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new HJT log.

    Make sure you tell me how things are working now.
    If you still have problems with Trojan.Lootseek, attach a log that displays exactly what and where Norton is finding int.
     
  4. fferay

    fferay Private E-2

    O20 - AppInit_DLLs: ASAPHook

    I don't know what i is might be linked to anonymous browsing thing. I guess I should uninstall that thing anyway. I'm not using it.

    O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll

    I don't know what this is.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.free.fr/

    That's my IE homepage: free.fr is a great internet provider in France. Latest technology for very very affordable, free TV, free phonecalls over part of the world and 20Gb for something like $25. Can't beat that!

    That Tok-Cirrhatus had already been removed by Norton. That was a souvenir from my vacations in Japan... But I still followed your instructions.

    I had also run a removal soft that I found somewhere, before I got your instructions, but it didn't work. The Lootseek came back.

    Here is the new HJT log.

    Let's wait and see. It sometime takes a few days before it comes back.

    Thanks for your help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not using the proxy server stuff then uninstall them. I see:
    Anonymous Browsing
    ProxyWay

    You should also have HJT fix the below line:
    O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)

    I don't want to touch the O20 - AppInit_DLLs line until we see if it is related to the proxy stuff.

    Now attach a new HJT log and a new log from ShowNew.

    How is everything running right now?
     
  6. fferay

    fferay Private E-2

    All that is done. Here are the new HJT and showview logs.

    Lootseek is still quiet but it's too soon to tell. Last week it stayed quiet for 4 or 5 days before reappearing again.

    Thanks for your support,

    Fab
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  8. fferay

    fferay Private E-2

    Thank you very much for your help.

    Fab.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  10. fferay

    fferay Private E-2

    Bad news: lootseek just came back...

    Norton suppressed the following files:
    C:\Documents and Settings\Fab_2\Bureau\setup.ex
    C:\Documents and Settings\Fab_2\setup.ex
    C:\Documents and Settings\Fab_2\Mes documents\setup.ex
    C:\Documents and Settings\All Users\Documents\setup.ex

    'Bureau' stands for Desktop
    'Mes documents' stands for My documents


    That thing is driving me crazy!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you just try deleting those files?

    Also did you toggle System Restore?

    Does the below file exist:

    C:\Windows\System\smss.exe
     
  12. fferay

    fferay Private E-2

    Apparently, Norton deleted the files successfuly.
    The system restore is still off.
    c:\Windows\System\smss.exe does not exist. The only .exe there is in this folder is wowpost.exe
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Restore should be enabled if you did what I requested in message # 7.
     
  14. fferay

    fferay Private E-2

    Yes, it was off since I got a Brontok worm a few weeks ago. I just didn't toggle it back on.
    I thought I might have missed some other steps in your instructions so I redid everything and didn't forget to toggle System Restore back this time.

    Here are the new logs.
     

    Attached Files:

  15. fferay

    fferay Private E-2

    the other logs
     

    Attached Files:

  16. fferay

    fferay Private E-2

    I heard Lootseek opens a 'backdoor' on security systems. I don't know what that means, but could it be possible that the virus is actually destroyed on the computer but I keeps coming back through the internet because it would somehow have opened a 'backdoor' in Norton?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is Norton still detecting Lootseek? Make sure you empty your C:\Program Files\Norton AntiVirus\Quarantine folder!

    Please look for this file:

    C:\WINDOWS\system32\ASAPHook.dll

    I would like to get some more info on the ASAPHook.dll file. So if found (using Windows Explorer) right click on it and select Properties. Now see if there is a Version tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.

    I'm wondering if it is part of the HP ProtectTools Security Manager
     
  18. fferay

    fferay Private E-2

    It says it's from Conizance Corporation, the item is descriçbed as a 'Cognizance Application Protection Hook'
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. fferay

    fferay Private E-2

    Not that I know. I don't know that company.

    Lootseek hasn't come back since sept. 29. That's a week now. May be the second time I did the READ & RUN ME thing was the good one.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that is good that LootSeek is gone!

    Perhaps we should just ignore the ASAPHook.dll file unless you are having any problems. It may be part of something else you have installed. Maybe like I said part of the HP stuff, but I really don't know at this point.

     
  22. fferay

    fferay Private E-2

    Ok.

    Thank you for everything.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds