is this a virus? thanks : )

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chad-roscoe, Aug 20, 2004.

  1. chad-roscoe

    chad-roscoe Private E-2

    hiya.
    i have a gateway laptop, & windows xp.
    the laptop is about 9 months old.
    every so often, maybe twice/month
    everything locks up & when i look in task manager it says "Project 1"
    is running, & sucking up all the memory.
    i've searched and searched the web but i can't find a virus called project 1.
    i've also "searched" my laptop & cannot find any file or program named project 1.
    when i find it listed on task manager & close it it closes easily enough & everything returns to normal.
    i also have to be online it seems for it to occur.
    anyone else ever get this?

    i had a hijaking trojan about 2 months ago that i removed w/ cw shredder if that maybe has something to do with this.

    thanks a bunch ]:+)
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I can not find anything on it either. Have you checked add\remove programs and startup for anything suspicious? If it is running, it has to be loaded from something. Possibly its a rarely used program that it is associated with is the only explanation I can think of as to why you see it rarely.

    You can, of course, do a complete scan with Ad-Aware and maybe a trojan tool like A2.
     
  3. chad-roscoe

    chad-roscoe Private E-2

    thanks so much for responding.
    so if i were to check start
    or add/remove for anything suspicious...
    how would i know it was suspicious?
    thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not know what an item is or do not remember installing it then it is suspicious. You should know what everything on your PC is. If not, find out. After looking in Add/Remove programs and finding something that you are unsure of, do some searches on the Web for the names and see if you can figure out what the program is for. Sometime vendors (even the good guys) name things pretty poorly in Add/Remove programs. That program may have one name but in Add/Remove programs you can quite often see a name that has nothing to do with the program name. It could be the vendors name or something else instead of the program name. Don't just go deleting things without checking what the are.


    You know what, I'm curious about this problem. Download HijackThis from here: http://majorgeeks.com/download3155.html

    Unzip it to its own directory, run it and perform a scan. Save the log file but save it to a .txt file. Then upload the log back here as an attachment.
     
    Last edited: Aug 20, 2004
  5. chad-roscoe

    chad-roscoe Private E-2

    Hi--
    I'm attaching a txt version of the log file after running Hijack This. Please give me any advise on what I should ditch. Thank you so much!!
     
    Last edited: Mar 23, 2007
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Ok, you need to do a complete system scan with Ad-Aware, etc... I see some items that need removal.

    Examples include the MyWay search bar:

    Open 'Add/Remove Programs' in the Control Panel. Select the 'My Search Bar' (MySearch variant), 'MyWay Speed Bar' (MyWay) or 'My Web Search Bar' (MyWeb) entry and click 'Remove'. For the MyWeb variant, be sure to also remove 'Fun Web Products Easy Installer'.

    You can then reset your home page (Internet Options->General->Start Page) if it has been changed, and search settings (Internet Options->Programs->Reset web settings).


    As I first suggested, you need to do a complete system scan, you still have trojan processes being loaded. I suggest you start with removing programs from Add\Remove programs as Chaslang explained and follow up with a COMPLETE system scan and bring that log file back again:

    http://forums.majorgeeks.com/showthread.php?t=35407
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I agree with MA completely. Do those other scans first. Also you have this: http://www.kephyr.com/spywarescanner/library/relatedlinks.lbbho/index.phtml

    You also have been hijacked by new.net.
    You should download LSP-Fix from here: http://www.cexx.org/lspfix.htm
    Just in case your internet connection gets broken during the repair processes, you will need LSP-Fix to repair a broken LSP chain.

    Before running SpyBot S&D (part of the stuff MA referred you to) you need to fix some default settings or it will ignore New.net and some other issues. So run SpyBot and click on Mode and change to Advanced Mode. Then click Settings, Ignore Products and in the right window pane where the products are listed, right click and Deselect All. (about 4 of them, including new.net where selected to be ignored by default). Now run the scan.

    You should get rid of XoftSpy too: http://www.pestpatrol.com/pestinfo/x/xoftspy.asp
    It is a rogue/fake spyware remover.
     
  8. chad-roscoe

    chad-roscoe Private E-2

    Hello Chaslang & MA:

    Thanks for the advice and information. I am in the process of running Spybot S&D in Advance Mode. Chas, where you mentioned there would be about 4 products in the right window pane in Advance Mode, there were actually about 100 or more. I deselected all before running S&D and hope that I was correct in doing this.

    There are a lot of strange (to me at least) things being found such as GAIN.gator, GoldenPalace.Casino, about 34 in all. I clicked on "Fix Selected Problems" and nearly all were fixed. One wasn't fixed--New.net, but I realize now it was deselected, so I'm re-running S&D and will select it to be fixed, assuming that is the appropriate course of action.

    Did not know about XoftSpy being fake, and I actually purchased that item. I've also been using SpySweeper. Do you know if this product is reliable in removing Adware?

    Thank you for your valuable time and insight. You make the world a better place for those of us who aren't in the know--

    chad-roscoe
     
  9. chad-roscoe

    chad-roscoe Private E-2

    Here is a quick update. I ran a system check, and installed the programs chaslang and MA recommended. Then ran Hijack this once again. The report looks a bit different. For one, the "new.net" seems to have been removed. If anyone could take a minute to skim thru the report and let me know if anything else looks suspicious I'd be most appreciative!
     
    Last edited: Mar 23, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

     
    Last edited: Aug 25, 2004
  11. chad-roscoe

    chad-roscoe Private E-2

    Thank you. I apologize for having misquoted you in my earlier post. I misunderstood what you were saying, so thank you for reclarifying it.

    Have fixed the rest of the problems using Hijackthis, and am off to fix the C:\WINNT\lbbho.dll problem.

    Thanks again, and best wishes--

    chad-roscoe
     
  12. chad-roscoe

    chad-roscoe Private E-2

    Hi All--

    Could someone please resend the link for removing lbbho.dll from my system? I went into "view hidden files" and then tried removing the lbbho.dll from WINNT, but this did not work. I'm guessing it would be possible to delete it from safe mode, but I haven't gone into safe mode for a quite a while and am unsure how it's done. Or, if there is an alternative way of removing this, kindly forward any relevant links and I'll give it a go.

    Best--
    CR
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The link is still in this message thread where I posted it, but here it is again.

    http://www.kephyr.com/spywarescanne...bho/index.phtml

    If you cannot get that to work, let me know and I'll give you another method.

    Are you still having Project1 problems?
     
  14. chad-roscoe

    chad-roscoe Private E-2

    Hi--

    Yes, I did follow the link, printed out instructions, and have now successfully removed lbbho.dll from my computer. Thanks so much for explaining (and re-explaining) the process!

    I have not seen the pesky Project 1 lately. It was a very annoying item that was not always easy to detect. Usually, the fans on my laptop would kick into high and the performance would drop substantially. When I would check to see what applications were running in Task Manager, Project 1 would often be there. I would close it, but I never was able to find it on my computer. Perhaps it was removed during the recent cleansings.

    I have one final question, and if this is the wrong forum to present it, I can post it on another forum. But here is the question: I recently reinstalled my HP scanning software. I did this because when I tried to use my scanner, the application would launch but when I tried to scan I would receive an error message, "scanner not found." So I reinstalled, but there were problems. I received online help from HP and was able to reinstall the driver and now everything works great...

    ...except that every time I restart or start up my computer, the following error message appears in a dialogue box:

    HP PrecisionScan LTX Setup

    This program updates your HP scanning software. You may see a message about ‘Digital Signature Not Found.’ You must click ‘Yes’ for the update to install correctly.

    OK


    ...and I must either click "OK" or simply close the dialogue box. Neither seems to affect the scanner's useability, but I'm unsure why this box appears on every single restart. If you know of any steps I could take to remedy this problem, I'd appreciate it.

    Thanks again for walking me through all these processes!!

    CR
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's probably best to ask that question in the Software Forum. But did you click "Yes".
    It may need to finish some update and that process will always be running at startup until you let it complete. On the otherhand, it would not be the first time that a process like this should have ended but never did!
     
  16. chad-roscoe

    chad-roscoe Private E-2

    HI again--

    Yeah, I clicked "yes" several times, and several other times I simply closed the box. Neither seem to make a difference. I've done restarts, and I've turned the machine off entirely and then started up cold, but it doesn't seem to matter. So I went ahead and posted the question in the Software Forum as you recommended.

    Thanks again chaslang! You and Major Attitude rock!

    CR
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds