odd trojans
Results 1 to 15 of 15

Thread: odd trojans

  1. #1
    Registered User
    Join Date
    Jan 2009
    Posts
    7

    Angry odd trojans

    So ive been having some issues with my computer. It started about 2 days ago, i was surfing the web and i got hit. my computer started spamming pop ups and my icons and start bar dissapeared. since i have ran vs several times. i keep getting 2 trojans in C:\ WINDOWS\system32\mljGaaya.dll and C:\ system32\lsass.exe (820) My vs can not delete these and i have tried manually to remove them and get Access denied. Im running AVG anti-Virus
    and its on xp media center edition. each time it boots up, it runs fine till everything is loaded, then my icons and start bar dissapear, so it is not an issue with them not being there at all, they dissapear after everything is loaded up.

    Thank you for any help you can offer.

  2. #2
    Registered User
    Join Date
    Jan 2009
    Posts
    7
    also i have tried running explorer.exe as i have seen in many posts and the icons and start bar come back, but only for a min or so, then they dissapear again.

  3. #3
    Registered User
    Join Date
    Jan 2009
    Posts
    7
    so do i need to go get another copy of xp for this wipe?

  4. #4
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    You should backup your information. However I suggest copying the lsass.exe from another pc with the same version of windows that isn't infected then on the other computer download combofix put it on a CD or a thumb drive, also download malwarebytes from www.malwarebytes.org and put that on the cd or thumbdrive. Reboot your pc in safemode and install malwarebytes, then run combofix. After that run malwarebytes. Once you are done Copy the lsass.exe file. That is if it didn't cause the pc to shut down after you removed it. If it did you need to slave the drive into another pc to replace the lsass.exe If I recall this should work as the lsass.exe isn't a picky file to replace like the other windows directory files.
    One Script to rule them all.
    One Script to find them.
    One Script to bring them all,
    and clean up after itself.

  5. #5
    Registered User
    Join Date
    Feb 2006
    Location
    Canada, Eh!
    Posts
    4,091
    If you can access another comp, get Hijack This, MalwareBytes and Superantispyware downloaded to a cd and try and install them in Safe Mode.

    If they install, run them.

    http://www.trendsecure.com/portal/en...kthis/download

    http://www.malwarebytes.org/

    http://www.superantispyware.com/

    edit: IF you are not familiar with these products, have them scan ONLY and then post their log files as attachments here.
    Last edited by CCT; January 7th, 2009 at 08:41 PM.

  6. #6
    Registered User
    Join Date
    Jan 2009
    Posts
    7
    this is a custom build, but the harddrive is from a compaq i had. It had the recovery on a seperate partition but when i tried to run it, it put me into a command/dos screen. I didnt go any futher because i did that type of recovery on my dads computer for him and it was just like installing windows again, i never saw a screen where i had to type in commands. I have already backed up files i would like to keep onto another drive, luckly the files were not infected, so my only concerns were if i had to zero out, and if i needed to get a new copy of xp. First ill try the file removal.

  7. #7
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952
    So the xp media center is from another computer? specifically a compaq?
    Gigabyte 990FXA-UD3
    AMD FX 8350 4ghz OCTO-Core
    Windows 8.1 PRO 64
    Adata 256 gig SSD
    Kingston HyperX 1600 16 Gigs
    Sapphire R9 280 2gig
    Enermax Liberty Modular 620
    www.northernaurora.net
    http://www.northernaurora.net/page/chat.html

  8. #8
    Registered User
    Join Date
    Jan 2009
    Posts
    7
    yes, i bought it in '06. is there some other way for me to post the log file? its to long for me to post, and the only formats i can upload are pics.. its a .txt file.

  9. #9
    Registered User MobilePCPhysician's Avatar
    Join Date
    Jan 2002
    Location
    Cleveland, Oh
    Posts
    2,384
    You can break it up into multiple posts.
    Sergeant WOTPP

  10. #10
    Registered User
    Join Date
    Jan 2009
    Posts
    7
    !!!!!!!!!!!!!!! Thank you so much!! i ran those programs, and now there is nothing. no dissapearing icons, still have start bar! So, now that we have that squared away, should i just set it on a schedule to scan my computer? or is there any other clean up issues i need to be worried about?

    Once again, thank you so much everyone!

  11. #11
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    Quote Originally Posted by icehog06 View Post
    yes, i bought it in '06. is there some other way for me to post the log file? its to long for me to post, and the only formats i can upload are pics.. its a .txt file.
    The compaq windows was sold for use ONLY with the original compaq machine. Unfortunately you are now running an illegal copy.

    As for clean up, run a hijackthis log and post it and we can have a look to see if there is anything left over.
    Never, ever approach a computer saying or even thinking "I will just do this quickly."

  12. #12
    Registered User Gabriel's Avatar
    Join Date
    Aug 2000
    Location
    Tel Aviv Israel
    Posts
    2,161
    As a side not I think that UBCD for win should be a part of every technician handbag:
    http://www.ubcd4win.com/
    custom built with many features - easy to understand and no dependancy on host OS

    I never bother of instaling spyware tools on the computer - I always clean with the CD

    Cheers,
    Gabriel
    Real stupidity beats Artifical Intelligence
    Avatar courtesy of A D E P T

  13. #13
    Registered User
    Join Date
    Jan 2009
    Posts
    1
    Just an aside: CCT mentioned installing your Anti-virius apps in SafeMode. Normally Windows won't allow you to install anything in SafeMode but there is a workaround. After booting to SafeMode go to the command prompt and enter the following command :

    REG ADD "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Mi nimal\MSIServer" /VE /T REG_SZ /F /D "Service"


    (For SafeMode with Networking)
    REG ADD "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Ne twork\MSIServer" /VE /T REG_SZ /F /D "Service"

    That will enable you to install most programs in SafeMode. Comes in handy.

    Taraje Solomon

  14. #14
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    Welcome to Windrviers Taraje and thanks for the Tip!
    Never, ever approach a computer saying or even thinking "I will just do this quickly."

  15. #15
    Registered User
    Join Date
    Feb 2006
    Location
    Canada, Eh!
    Posts
    4,091
    Yes Taraje, I did omit that little detail.

    Thanks.

    There are people working to help all the time - this site has a method of preparing some av for cut/paste (in Safe Mode);

    http://forums.techarena.in/security-virus/745438.htm

Similar Threads

  1. Odd trouble!
    By daywalker in forum Networking
    Replies: 6
    Last Post: August 14th, 2007, 12:20 PM
  2. Odd 'scrambling'?
    By ohtheknives in forum Windows XP
    Replies: 5
    Last Post: August 6th, 2006, 02:21 PM
  3. really odd thing going on here...
    By Six Eyed Smily in forum Networking
    Replies: 14
    Last Post: June 27th, 2003, 09:51 PM
  4. hang and odd lock up
    By obituary in forum BIOS/Motherboard Drivers
    Replies: 8
    Last Post: January 3rd, 2003, 08:43 AM
  5. Outlook 2000: odd behavior
    By Poseidon in forum Microsoft Office
    Replies: 2
    Last Post: April 1st, 2002, 02:06 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •