Trying to help Friend Went through First Steps

Discussion in 'Malware Help (A Specialist Will Reply)' started by Destructo, Apr 29, 2005.

  1. Destructo

    Destructo Corporal

    Hello most likely chaslang,

    My friends comp is plagued w/pop ups. First off went through the post (twice) of "before you post go through these programs....." Anyway did all in safemode, trend cleaned 8, symantec wouldnt go the second time, adaware found about 300 entries, spybot found some more, did CC, ran CW, first time it found somthing (forgot what it was) second time nothing, and I ran kill2me.

    Anyway I am stilling getting popups in IE and Firefox and some damn thing keeps grabbing trojans. Particularly Appsetup.exe (troj_small.cb). ezstub.exe, wo (somthing).exe also come back and I remember a picsvr.exe and a n20050308.exe too all come back.

    I have lojack analyzed a couple of hijackthis logs each after rebooting and nothing else seems to show up in the log (there are some winsock entries but havent done anything yet since i have connectivity) I know is has something to do with Ezula and zesty search (the last showing as a hijack attempt twice in adaware and i think spybot)

    She needs her comp back tonight so i wont be able to do much but any thoughts would be appreciated. I hope you dont hate me but Im attaching a jack log too so you can see what im talking about.

    one of the websites that keeps popping up: www.loadingwebsite.com/normal/yyy32.html and redzipsearch just thought id mention it incase it helps
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you must use Add/Remove programs to uninstall Messenger Plus! 3. It puts a bunch of malware on your PC including a nasty LOP infection.

    Download LSP - Fix

    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the aklsp.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move aklsp.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.

    Now download the following tool: L2MeFix Tool

    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and Type 1 and ENTER to select Option #1 for Run Find Log . Allow it as much time as it needs to run until NotePad opens with a log.

    NOTE: Please do not run any other options or files in the l2mfix Folder!

    Get a new HijackThis log.
    Now come back here and post the l2mfix log and the new HJT log as attachments.

    Please DO NOT REBOOT after scanning for these logs!! Otherwise problems may mutate and spread. Wait for me to get back to you with the next steps.
     
  3. AliWiseman

    AliWiseman Private First Class

    Messenger plus only puts the spyware on your system if you choose to accept the sponser :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's true! But most people put all of it in! But sneaky crapware like this does not deserve to be used. If they want to be so underhanded, they deserve to be treated the same way because the simply cannot be trusted.
     
  5. Destructo

    Destructo Corporal

    Thanks a lot for looking. I didnt even really think of what messenger plus might be. ugh, was so burnt out by the end of it. Is MessPlus associated with the loading website and redzip crap/pops? or is it more the lps entries? Anyway will hopefully be able to post by tommorrow night or Monday.

    Thanks again and the comp. was shut down since i posted, will this be a problem w/the LSP&L2fixes? i.e. do i have to do the scans over and repost jack log? crap. Ill check back tomorrow fo rthe exciting conclusion.

    Destructo
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Messenger Plus can cause lots of problems it is easier to just uninstall it.

    Just run the LSP and L2Mefix after you power back up. Then do not reboot after posting the log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds