Overrun

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by paulmc, Aug 6, 2006.

  1. paulmc

    paulmc Private E-2

    I'm overrun by these nasty trojans... logs attached, but here are some symptoms that may help in your

    work - which I thank you for VERY much.

    NAV has been unstable since first infection, which I suspect may have been early July. NAV shows

    Trojan in c:\windows\system32\lpt5.jbj which cannot be removed, corrected or cleaned. NAV

    denies access.

    NAV sometimes (appears to) work, but then gives me Symantec Integrator failure or LiveUpdate

    failure or no A/V software. Every bootup is different.

    NAV's website diagnostics tell me I have a "third party firewall" which I cannot switch to either Win

    or NAV.

    BraveSentry has created files in both C: and D: which refuse to be deleted. (Recycler)

    I cannot perform a successful System Restore.

    Spybot SD found Smitfraud-C. Windows Defender found SpySheriff.

    Please advise! I'll be running your Special Recovery Procedure for Smit and SpyS tomorrow. Any

    advice meantime?
     

    Attached Files:

  2. paulmc

    paulmc Private E-2

    Here are the online scan files.
     
  3. paulmc

    paulmc Private E-2

    trying again to post online logs...
     
  4. paulmc

    paulmc Private E-2

    Had problems posting bitdefender and panda logs yesterday... Here goes again. Please help.

    Whew, it worked.
     

    Attached Files:

  5. paulmc

    paulmc Private E-2

    Went ahead and did special procedure and ran SmitRem and Panda again. Logs attached.

    NAV still buggy as hell and still reports system32\lpt.jbj trojan. It doesn't appear in Explorer, of course.

    Performance is okay, but have problems with POP3 login every once in a while.

    Recycler and System Volume Information files appeared concurrent with trojan problems... in both drives C: and D: and they cannot be deleted; computer gives "in use by other user" message. Hmmmm.

    Another possible clue: Recycle Bin icon changed to generic file icon rather than the trash can.

    Thanks for taking a look at this.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what is it that this PC is used for and who has been using it??????

    This PC appears to have the registry infected with almost every know piece of malware. It would appear that some one was trying to infect this PC as it would be almost impossible to have this many components of malware in the registry without doing it on purpose. Or unless the PC had been run for quite awhile with zero protection or outdated protection in place.

    In reality it maybe safer to fdisk, repartition, format and reinstall this PC. We could attempt to clean it up by using a load of additional scanners and quite a bit of manual cleaning steps but it could be very time consuming and we may not even be able to locate everything.

    If you would like to do manual cleaning, begin with the below:

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Question: Did you knowingly install MovielinkManager and The Weather Channel FW ? I'm not saying they are malware. I just want to know if you installed them or if they were installed without your knowledge.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Then uninstall the below software using Add/Remove programs:
    Java 2 Runtime Environment, SE v1.4.2
    Java 2 Runtime Environment, SE v1.4.2_05
    Mozilla Firefox (1.0.1)
    Viewpoint Media Player


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O1 - Hosts: localhost 127.0.0.1
    O2 - BHO: Class - {58C41DD1-9710-395E-F0B5-801EC66F7E9C} - C:\WINDOWS\lnllt1.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\lnllt1.dll
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now run this procedure Running Spy Sweeper and attach the Spy Sweeper log.

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  7. paulmc

    paulmc Private E-2

    Chas - Thanks SO much for your help. I'm blown away about the depth of the problems. This PC is an XP Media Center laptop used at home. Maybe I have been hijacked longer than I realized... Ugh! I've had NAV the whole time, but I now don't trust it. (Did you see Consumer Reports rating of Zone Alarm Internet Security Suite as #1? Maybe time to change.) I HATE being a Petri dish!

    Movielink came with the PC (you can rent movies via download) and yes, I did install Desktop Weather 4. I would entertain your advice about their further use.

    I'm going to try a manual cleanup, then move my personal files to external drives, then rebuild the system.

    Again, I am extremely grateful. Please give me a day or so to take the steps you advise and I'll let you know results when I post the logs.:eek:
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! If you look at one of our other stickies (something we recommend when we finish cleaning PCs) you will see ZoneAlarm recommended. It was the first firewall put on the list. This is the sticky How to Protect yourself from malware!

    Not necessary! I just wanted to be sure you installed them or at least knew about them.

    Okay! We shall see how much we can fix but with so many bad things being present in the registry it could be very difficult to complete clean this PC. How did it get like this? What is it used for and who is using it?
     
  9. paulmc

    paulmc Private E-2

    Chas - Sorry for the long delay - "Life is what happens while you are making other plans..." I'm going to change my mind about cleaning and go ahead and fdisk and rebuild. There is just too much junk on this machine. Thanks again for your help and I'll keep MajorGeeks in mind. Next time I sign in I hope it is for fun. P.S. This machine is primarily personal use, but I have helped two college age friends recover their sick PCs with it. Perhaps that is where the trojans originated??? Also, I'm dumping NAV and going with Zone Alarm or Micro Trend or FProt. NAV just made my problems worse, I think.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds