virus that wont go away??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by starbaby22, Nov 26, 2004.

  1. starbaby22

    starbaby22 Private E-2

    ok.. someone needs to HELP ME. i was bombarded by ads and a bunch of trojan downloaders downloaded onto my comp along with well duh trojans and some nasty bugs. anyway i do have a virus scan, and pop up blocker and ad aware.. AND i have read the "Basic Spyware, Trojan And Virus Removal" AND i followed instructions..mind you i couldnt reboot in save mode with networking support so maybe thats it; but anyway.. i still have these two programs running in the background and the names are "bdt" and "Luol". i have no idea what they are..i have scanned the comp with all of the above and it doesnt seem to go away. im also getting this pop up.. with some kind of computer registry software by systweak and it doesnt wanna go away either. so im outta ideas i have no clue of what else do to.

    can anyone help??????
     
  2. PhilliePhan

    PhilliePhan Guest

    HI Starbaby22,

    Did you try the online scans in regular mode? You might also try a-squared and the online Trojan Scans in the Alternative Scans section of the tutorial.

    If all else fails, go ahead and send us a HijackThis Log. Make sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    Somebody will take a look when they get a chance.

    Best :)
    PP
     
  3. starbaby22

    starbaby22 Private E-2

    okay so i did the hijackthis log file and im posting it now...i dont know if theres anything wrong because my comp seems okay now.. but i still get some pop ups altthough i have like 2 or 3 blockers and i get this annoying one in particular about "computer registry" somthing.. well anyway.. see if you guys can fix it.. here it is..many thanks. :)
     
  4. starbaby22

    starbaby22 Private E-2

    i'm re attaching the log file.. i did something wrong the first time around..
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to check for updates to your OS and IE. You are still running IE 5.5. That's a bad idea.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    LBMUZCH

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {484A5481-DC1E-7BD6-3E8F-C1F0821A52DE} - (no file)
    O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - (no file)
    O2 - BHO: Search Bar - {4E7BD74F-2B8D-469E-A1F6-FC7EB590A97D} - C:\WINDOWS\DOWNLO~1\SEARCH3.DLL
    O2 - BHO: (no name) - {76936178-CD8F-24A4-7846-5D4435B14F5D} - (no file)
    O2 - BHO: (no name) - {B70A7E38-9DA9-DE0F-89DE-E2ABA9710490} - C:\WINDOWS\SYSTEM\SGXR.DLL
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O3 - Toolbar: (no name) - {D9031006-41E3-8460-AA51-EB125E7F6601} - (no file)
    O4 - HKCU\..\Run: [Rsde] C:\WINDOWS\Application Data\luol.exe
    O4 - HKCU\..\Run: [Ruy] C:\WINDOWS\SYSTEM\lbmuzch.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    I don't know if you added the two below items to your trusted zone or not but personally will not put anything in the trusted zone.
    It's up to you. If you know you absolutely need them there, leave them be.
    O15 - Trusted Zone: http://www.hispeed.rogers.com
    O15 - Trusted Zone: http://www.behr.com
    Wild Tangent should definitely be fixed.
    O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://www.wildtangent.com/install/wdriver/racing/dodgespeedway/microsoft/wtinst.cab
    After clicking Fix exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\DOWNLO~1\SEARCH3.DLL <--- DOWNLO~1 is probably "downloads" or "downloaded programs files"
    C:\WINDOWS\SYSTEM\SGXR.DLL
    C:\WINDOWS\Application Data\luol.exe
    C:\WINDOWS\SYSTEM\LBMUZCH.EXE

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. starbaby22

    starbaby22 Private E-2

    okay so i did what you said.. deleted those files..but when i restarted in safe mode i didnt find any of the files you mentioned... i looked for them in normal mode as well..but they're not there.. i dont know if thats bad or good? but heres another log...
    also i know i'm running ie 5.5..i tried installing 6 but it doesnt work..half of it installs, it reboots and then it tells me to reboot again because a previus installation is pending reboot..and so on..it never fully installs for some reason...if you have any ideas im open to suggestions... also after i deleted those files i started getting these error messages whenevr i open anything on the desktop (even in safe mode) about an error in some .dll.....
    and i think thats all for now.. :rolleyes:
    thanks for helpin me out...
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said you could not find any files to delete. Did you mean after having HJT fix those registry entries.

    You need to be more specific about the error messages. Give the exact word for word text of the messages and what dll they are referring to.
     
  8. starbaby22

    starbaby22 Private E-2

    okay sorry i suppose i was being a bit vague..
    yes i got HJT to delete the registry files and that was okay
    then in went into safe mode and i didnt find any of these files
    C:\WINDOWS\DOWNLO~1\SEARCH3.DLL <--- DOWNLO~1 is probably "downloads" or "downloaded programs files"
    C:\WINDOWS\SYSTEM\SGXR.DLL
    C:\WINDOWS\Application Data\luol.exe
    C:\WINDOWS\SYSTEM\LBMUZCH.EXE

    i also checked in normal mode.

    about the error messages.. i can't really tell you because it doesnt happen all the time..next time it does i'll copy and paste the error message.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you having viewing of hidden files enabled when you tried to find those file?

    As far as the error message, you said "these error messages whenevr i open anything on the desktop (even in safe mode) about an error in some .dll." So I assumed it always happened. Next time it happens make sure you get all the exact info.

    Any other problems?
     
  10. starbaby22

    starbaby22 Private E-2

    about the error messages, yes i had them after i had removed those registry files...it seems to be okay now, havent gotten it since.

    and yes i did have the showing of hidden files/folders enabled and i still couldn't find them, i looked for them a couple of times, they're not there...
    is that a bad thing?

    but that is all..thanks alot.. :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's okay if the file were not found! I just wanted to make sure you had viewing of hidden files enabled to be sure.

    The main thing is that everything is okay now! That's good.

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds