ICanNews: Anyone had it and gotten rid of it?

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheDoug, Jul 9, 2005.

  1. TheDoug

    TheDoug MajorGeek

    I've been given a laptop to disinfect, and have cleaned up everything but one last persistent baddie called ICanNews. Google searches only return a couple of hits, basically forum posts by infectees, dated within the last week. Searches here return nothing.

    Only MSAS seems to detect any significant portion of it, identifies it by name, and says it removed it, but, upon reboot, it's back and MSAS regards it as "Previously Ignored" and offers to remove it again.

    HJT picks up on only one of the DLLs, but if removed, it returns instantly. HJT info point says the DLL is being loaded very early in the boot process, which is a common trick for trojans, etc, as it makes it more difficult to kill. Over the course of several days and failed attempts, I have identified these points:

    HJT scans list only one of up to as many as 4 DLLs identified by MSAS.

    MSAS, besides the DLLs, detects a file called "guard.tmp", all in Windows/System32, plus a triggering registry entry under HKLM/Software/Classes/CLSID that refers to one of the DLLs.

    I have used up-to-date versions of SpyBot S&D, AdAware, CCleaner, KillBox, TrojanHunter, AVG and others, to no effect. "Delete file upon reboot" settings are ineffective.

    Although the DLL filenames mutate from time to time, there has been a consistent one lately named "ijssam.dll" that recurs (which is the one HJT lists), along with the aforementioned "guard.tmp". "ijssam.dll" is not the one referred to in the registry entry.

    Safe Mode and logging in as Administrator do not help, nor does deleting files from Recovery Console command prompt.

    Nothing from this PITA is evident in Task Manager, so there's no help there.

    I am performing all cleaning operations while disconnected from the web.

    Does anyone have a suggestion as to another angle to try to attack this from until it becomes a more known threat and is able to be dealt with?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    guard.tmp is normally associated with what we have been calling a Look2Me VX2 infection.

    Please download the following tool and save it where you will be able to find it.

    L2MeFix Tool

    Please print out these instructions now or save locally so that you can operate with All Browser Windows CLOSED.

    Exit Browsers now before continuing

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Now reconnect and come back here and post as an attachment the l2mfix log. Based on the log, we will determine the next steps. Please DO NOT REBOOT after scanning for these logs!! Otherwise potential problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, what I gave you will not fix the VX2 infection yet. We first need to see what you have then we can proceed with the fix.
     
  4. TheDoug

    TheDoug MajorGeek

    Will have to wait until Monday-- the laptop is at the office. Done some googling on look2me and group.tmp together, but not seeing anything familiar.Will proceed with your notion in any case, in the absence of other alternative. May or may not be worth mentioning that the AdAware VX2 plugin found nothing.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's guard.tmp!

    Ad-Aware's VX2 plugin does nothing for this type of infection. It does not even detect it.
     
  6. TheDoug

    TheDoug MajorGeek

    Yeah, typo. (obviously)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just wanted to check because there are lots of hit on guard.tmp
     
  8. TheDoug

    TheDoug MajorGeek

    OK, here is report.txt.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! You do have the L2ME form of infection.

    L2Mefix cleanup


    Print or save these instructions locally now because you will have to be disconnected with no browsers open in the next step.

    Please make sure ALL Browser Windows are Closed and also you should physically disconnect from the Internet by unplugging your cable.

    Go to the L2MFix Folder on your Desktop and DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go bazonkers (now there's a great technical term!) for a bit, but just let it run. It should eventually spit out another log in Notepad. Please attach that log.

    Again, don't run any other files in the L2MFix folder.



    Let me know how things look now.

    If you still have problems, follow the steps below:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  10. TheDoug

    TheDoug MajorGeek

    Here is log.txt from L2MFIX and the subsequent HJT log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That looks like it fix a bunch of stuff. Are you having any problems with things like the Recycle Bin. Does it work properly? Some times it was affected by this VX2 problem and additional steps were needed to fix it.

    I notice a couple other things:

    1) two antivirus applications being used - McAfee and AVG

    2) I believe the below is a valid AIM application:

    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl

    But this next line is also in your log and it does not seem to be a valid item to me.

    O4 - HKLM\..\RunServices: [AOL Instant Messenger] aimsgr.exe
     
  12. TheDoug

    TheDoug MajorGeek

    Recycle Bin seems OK. Consensus is that aimsgr.exe should go, although I searched for the file (hidden and system included) and it was not found. I also emptied the Prefetch folder on advice of another MF like you (c'mon, now, it stands for Malware Fighter, remember?) who also agreed on the aimsgr.exe issue. I put AVG on there because the McAfee install is currently broken.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So did you fix the aimsgr.exe line in HJT (I assume so)? Maybe you should uninstall McAfee then since it is broken anyway.

    How are things working?
     
  14. TheDoug

    TheDoug MajorGeek

    All seems OK at the moment-- after it's owner gets it back, well... that remains to be seen. Windows Update doesn't want to install the updates it successfully downloads, but that's an issue for another forum. Thanks for your help.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There seem to be a lot of problems with Windows Updates going around. And none of the things suggested in MSKB work. It would be nice to find out what is going on. I suggested in one case to try enabling automatic updates to see if that would help. I have seen that work when manual procedures would not. But I do not guarantee that it will be the answer in all cases.

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds