BuffaloHELP
Aug 31 2008, 07:16 AM
I've been meaning to write this post for days but the days just got away from me. Recently I've subjected my personal laptop for this malware which was downloaded to my clients email. The email client was Google Apps (Gmail) and the sender was from a known contact. However the beginning, the issue is that this Trojan was downloaded even through FireFox 2.0.0.16 and passed Google Apps filter. I was also told that some websites contain scripts to disable firewall and download malware without the computer user's knowledge. The final product is called Antivirus XP 2008 and here are the symptoms: 1) you will immediately notice that your firewall is disabled 2) background has changed 3) cannot change your background 4) cannot change your screensaver 5) cannot launch Control Panel to do anything 6) cannot launch normal programs 7) cannot launch CMD or any command programs 8) cannot launch regedit 9) cannot clean spyware(s) that keeps on spawning 10) your typical antivirus does not show any alert. The names of malware are different but they all reside under C:\Windows\system32\lph*********.exe C:\Windows\system32\*ph****.BMP C:\Windows\system32\ntos.exe C:\Windows\system32\wsnpoem\* C:\Documents and Settings\LocalService\Application Data\wsnpoem\audio.dll C:\Documents and Settings\NetworkService\Application Data\wsnpoem\audio.dll It is still unclear to me if two applications are working together (wsnpoem, ntos and lph********.exe a.k.a. a.exe). But the solution I found was able to clear my laptop from the hijacked stage. Trojan types reported lph**********.exe | Trojan horse SHeur.CDRG ntos.exe | Trojan horse PSW.Generic6.YTJ Download SDFix.exe (also attached at the bottom of this post). How to use SDFix Download SDFix and extract. I recommend that you unzip and unpack (self extracting EXE file--this board will not let just EXE file to be posted) on your desktop. You will be running this fix under the SAFE mode. So it's better to have it where it can be located quick and fast. Restart your machine and enter SAFE mode. To enter SAFE mode, simply hold down F8 during the restart. You will hear continuous beeping sound but I suggest you hold it until you see the Windows start up option screen. Select SAFE MODE. Once you start in SAFE mode, go to the SDFix folder and double click to run RunThis.bat. A command prompt will open and will take about 10 minutes to do its own thing. Once the registry is clear from the Trojan it will ask you to restart the machine. Follow the on-screen instruction. Once restarted SDFix will run once again. This will take another 10~20 minutes. A message will appear at the end of the clean up showing Report.txt as a log. No need to save since it saves and displays at the same time. You should be clear from this Trojan. Enable your firewall, run your usual spyware remover and virus remover. Key registries affected by Antivirus XP 2008 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\ parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\ parameters\firewallpolicy\domainprofile\authorizedapplications\list] SDFix file [attachment=1281:SDFix.zip] UPDATE ============================================================================ Direct download for latest patch from original source http://downloads.andymanchesta.com/Removal...DFix_ReadMe.htm
Comment/Reply (w/o sign-up)
jlhaslip
Aug 31 2008, 08:07 AM
Will this Trojan attack Linux machines? Do we need to stay away from Google Apps? Any idea how wide spread this Trojan is at present?
Comment/Reply (w/o sign-up)
rvalkass
Aug 31 2008, 08:58 AM
QUOTE(jlhaslip @ Aug 31 2008, 09:07 AM)  Will this Trojan attack Linux machines? Only Microsoft Windows from 95 upwards by the looks of it. Another win for Linux! Although, I guess you could run it under WINE if you want  QUOTE(jlhaslip @ Aug 31 2008, 09:07 AM)  Do we need to stay away from Google Apps? Same caution as with all emails. According to Symantec it has to be manually downloaded and installed, so just be your usual wary self and don't download random stuff. It's not specific to Google Apps, but I'm surprised they're not filtering it out. QUOTE(jlhaslip @ Aug 31 2008, 09:07 AM)  Any idea how wide spread this Trojan is at present? Fairly widespread according to Symantec.
Comment/Reply (w/o sign-up)
Saint_Michael
Aug 31 2008, 05:55 PM
AAh so this trojan got upgraded then because I have gotten its older brother a few times and so I just go into safe mode find the program in the win32 folder delete it and then run my computer with spybot and McAfee. So it seems that this exe pokes around in more files then the older version. Of course the quickest way to know that you got this trojan installed is opening Task Manager and you should see lph*********.exe running. I agree with rvalkass that this trojan won't affect Linux since it is windows specific or rather XP specific.
Comment/Reply (w/o sign-up)
-Sky-
Aug 31 2008, 06:21 PM
Oh great lol. I use Windows XP Home Edition, and I've had this trickster before. Quite so hard to remove aswell, especially when you don't have a good Anti-Virus.  AVG, Kaspersky, BitDefender, and them are rubbish. I need a GOOD Anti-Virus. Can anyone also find me one?  @ Michael: Yeah. It has a brother in It's infected family of code  Thanks Buffalo!  I shall keep a look at with these things.  -Sky
Comment/Reply (w/o sign-up)
Saint_Michael
Sep 1 2008, 04:49 AM
Well its not that those anti-viruses don't work its just that some trojans are design to sneak in behind the scenes and so regardless if the major software has patches and what not to find them and delete them. So the only way to remove them is the old fashion way of finding the files and then delete them; however, that were most non tech people think a small program that removes these things will work but instead just add to the problem and what not.
Comment/Reply (w/o sign-up)
jlhaslip
Sep 1 2008, 05:33 AM
Has anyone tried NOD32 to whack it?
Comment/Reply (w/o sign-up)
bluedragon
Sep 1 2008, 09:05 AM
Thanks Buffalo, Its there in one of My College's computer. I'll try to remove it  . Ppl at my college actually used to think that its an Antivirus .. LOL. .. Any Idea if this can be manually removed using 'HijackThis' to remove the registry entries and then delete the files manually ?? Can this trojan spread through pen drives ? I am using Norton Inernet security 2007 on a Laptop and it has a lot of sensitive data that I cant risk loosing. Will this pass through that also ?
Comment/Reply (w/o sign-up)
iGuest-sweetie
Sep 9 2008, 12:02 PM
Trojan virus EVERYWHERE!
Antivirus Xp 2008 - Recent Trojan Threat
Hi! Please help!! I have one of these trojan things currently killing my laptop and I have no clue how to get rid of it. I have AVG 7.5 anti virus software but it doesn't delete it, it just puts it in the virus vault & the folder it originates from can't be deleted...And I think there are many of the little buggers because there are many folder with weird names, but I don't want to delete them just incase they are important & not meant to be deleted! Everytime I switch the laptop on another one slips through the net! HELP! Can someone please tell me (in very plain english) how to fix this!! Thanks :o) P.S I have tried to do a system restore but it won't restore to any date other than the date I got the trojan & I've even played around in safe mode but I still can't delete the folders! HELP ME! -reply by sweetie
Comment/Reply (w/o sign-up)
iGuest-Eilean
Sep 18 2008, 08:09 PM
Help with removing a Trojan
Antivirus Xp 2008 - Recent Trojan Threat
Replying to BuffaloHELPHi BuffaloHELP, I found your post on the web and I have a Trojan that will not go away. I ran anti virus and tried manually removing suspicious files in safe mode as well as backing up to an earlier date. Still no dice. Your link for the SDFix file is not working for me. I figure I ought to try whatever I can to fix my computer before biting the bullet and bringing it somewhere to be formatted. :-( Can you re-link the SDFix? -reply by Eilean
Comment/Reply (w/o sign-up)
kobra500
Nov 3 2008, 03:05 AM
I downloaded some scareware that tried to make me download that. Lucky it wasnt the trojan, it was the first virus ive downloaded
Comment/Reply (w/o sign-up)
BuffaloHelp
Nov 1 2008, 10:32 AM
QUOTE(Echo_of_thunder @ Oct 11 2008, 06:25 PM)  2 antivius programs that removed it, AVG and BitDefender. That wasn't the case for me. One of the machines had Windows XP with AVG and the others with Windows XP with Symantec corporate edition. They both were infected and both antivirus programs could not catch it in time. After I was disconnected from the internet AVG shows some sign of healing but after reboot the same warning message popped up and it was cleaning again. So each and every time machines were reboot the virus kept coming back. It was not until I ran SDFix that it picked up the recursive program that spawned the virus. Anyway, for me SDFix worked and have been using other machines to clean them out. But the best cleaner is to make sure your computer is not infected to begin with.
Comment/Reply (w/o sign-up)
Echo_of_thunder
Oct 11 2008, 10:25 PM
I have had this virus myself, very nasty to remove too. I dd find out there are 2 antivius programs that removed it, AVG and BitDefender. Both free. took a double run of them both, but was able to remove it, along with a couple of other, spyware.
Comment/Reply (w/o sign-up)
room2593
Oct 11 2008, 02:58 PM
You want a fix in simple english? REBUILD YOUR COMPUTER. Get your windows disc and make that sucker spin. Back up files if you like, but get yourself an excellent virus scanner and scan everything before you put it back on your computer. If you like open source, comodore or clamwin are excellent for this. I'll tell you why one fix won't universally work: I had this trojan with TOTALLY different names under TOTALLY different circumstances. I battled this trojan for a good month. I got it off, but my computer was so ravaged that I reinstalled windows and called it done. My variation was THE MOST excellent piece of virus software I have ever seen. I'll elaborate on how I got rid of it. The trojan would start up before I even logged into my profile. IN THE WELCOME SCREEN! So I knew it was in the registry. It would sit unobtrusively in the background. But I think that this dang thing had a key logger. Every time I visited a site that might be able to help, it cut my ethernet connection. I would calmly have to ping my router to get it to recognize I existed. If you let it sit too long, it would create instances of IEXPLORE.EXE that would start eating more and more system resources. It's smart, though. It's not the IEXPLORE, it's a different program. If you watch for a long enough time in the task manager, you'll see it. I found mine; it was a jumble of letters and numbers that started with a C6 (I can't remember the rest of the crud) Point is, I looked that thing up on the internet and I couldn't find squat. And here's where the real genius comes in: I think that IT RANDOMIZES IT'S FILE NAME. That's incredibly intelligent. Whoever wrote this should be shot. More annoying things: Whenever I did a search for it in any virus software, it would cause an exception and throw my computer to the blue screen. If I did anything for too long without manually shutting this thing off, I would go to the blue screen. But it's just at the edge of annoying. You don't want to go to the lengths required to get rid of it, because you think "I can deal with this..." It's annoying, but not annoying enough to drive you to the edge. It's a masterful piece of work. The way I got rid of it: If you can still get into safe mode, then get there, for gosh's sakes. If you know what the file's name is, then go into system32 in the windows folder and delete it. I found mine there, and another one with more jibberish for a file name. Once you've gotten rid of them from there, go into your registry and use the find tool to find them there. If you don't know how to do that, then look it up (my post is too long already). Then restart your computer and hope for the best. My computer worked after that, but the drivers conflicted so much I had to rebuild anyway. It sucked.
Comment/Reply (w/o sign-up)
BuffaloHelp
Oct 11 2008, 11:04 AM
For guests who tried SDFix: Try the updated link to download newest registry and spyware clean UPDATED LINK http://downloads.andymanchesta.com/Removal...DFix_ReadMe.htmI had several computers where this Antivirus 2008 was left in for weeks. It apparently took over registry for hardware control and permanently took over the network interface card--I could not remove the DNS redirection and pop ups were still showing random advertisements. Only thing that kept pop ups from appearing was to use Firefox instead of Internet Explorer. I am going to attempt another removal with newest SDFix patch. To the guest that could not download SDFix from our board: You must be a registered member to download our uploads. For your convenience I have placed links to download from the source. I hope you find it useful.
Comment/Reply (w/o sign-up)
Similar Topics
Keywords : antivirus, xp, 2008, antivirus, xp, 2009, recent, trojan, threat, symptoms, fix
- Any Antivirus That Can Be Booted/run From Usb ?
(3)
Report: Fake Antivirus Programs Claim 30 Million Victims
(9) I know everyone here on trap has seen those anti-virus ads that do those fake scans and force those
pop up ads to make you go buy their scareware. Which is the tecnical term for software vendors or
hackers to scare you into buying their products in order to solve your problem. what I found really
interesting about this article that their are over seven thousand variations to this scareware
tactic, and the odds are those 30 million people are the onlys that barely know about a computer or
how to properly secure and making sure their personal information isn't floati....
Best Antivirus Combination
NOD32 + Spybot S&D + MalwareBytes... (1) Use ESET's NOD32 as your usual antivirus and firewall etc... But every once in a while, you
should get Spybot S&D and scan your computer for possible spyware or unfriendly cookies you may have
picked up while browsing the net... But, no single antivirus can detect and remove every single
virus out there... Which is why you should keep a version or two of "Malware Bytes'
Antimalware" software... It is very good, though it doesn't have a very good heusteristics
program which is why NOD32 is good... I had a virus like 2 days ago... I had NOD32 delete all of....
Bogus Grand Theft Auto Iv Contains Trojan
(7) Well not really surprise that hackers are targeting this game after scoring $310 million dollars in
the first day, and what gets me is that people were downloading the pc version days before it came
out, So either complete stupidity on the fact people though it came out early or the fact they
didn't know that these games would loaded with malware goodies. Nonetheless, I think its time
gaming companies start taking cheat codes out of games and write protect files and that way they
can't be over written. SOURCE ....
I Am Using A Free Antivirus That I Found On The Web
(5) Hi folks, I'm new here and still learning the do's and don'ts. So I am not sure if I
am allowed to post the name or the link of the antivirus I have found. I wouldn't be surprised
if most of you know which one I am talking about anyhow... The basic addition is free, or you can
step up to the next package which they charge. The basic free doesn't have the adware &
spyware. For that I use search and destroy and adwarese. (not sure if I am allowed to post that,
please delete thread if I am breaking spamming rules, sorry) If I am allowed to post ....
Pop-up Virus / Trojan Problem
Constant pop-up, won't go away (11) Hi Guys, Lately I have had this same annoying pop-up dialog box pop up that says: QUOTE NOTICE:
If your computer has been running slower than normal, it may be infected with Viruses, Adware, or
Spyware. Adwareremover2007 will perform a quick and completely FREE scan of your system for
malicious programs. Download AdwareRemover2007 for FREE now! I have scanned it with Avira
AntiVirus and ad-aware2007. They both returned infected files, which i deleted, but i still have the
pop-ups. Any ideas?....
White Paper: Security Threat Report: 2008
(0) I saw this white paper and I thought I bring down some interesting information that has come from
2007 and leading into 2008. I have to say though that the information on this white paper is pretty
darn mind blowing as I bounce some facts to everyone. Of course since I been getting into this
since last year it is not all that surprising since I posted many topics about it as well.
-Sophos currently sees 6,000 new infected webpages each day -One infected page every 14 seconds
-Only about 1 in 5 of these sites is a hacker site -83 percent are hacked sites, or legitima....
Windows Vista Sp1 Blocks Antivirus Programs
(5) Well it seems this is the first major problem for Vista SP 1 in the sense for those who have the
following Secuirty Suites installed on your ocmputer that is running Vista. They block the
following programs; Zone Alarm Security Suite 7.1, Trend Micro Internet Security 2008, BitDefender
10, and the 2008 version of the Jiangmin antivirus. As for the reason why these programs don't
work, Microsoft says "they are incompatible and so they must be block". Well not exactly like that
but you get the point they also mention that other small programs might now work either b....
Security Warning 2008: Top 11 Malware Threats To Watch Out For
(0) Before I go into this topic I have to say, stop making up these crazy names. I know I just getting
into the security side of things but still as long as there are computer problems and ways to sucker
someone into downloading the stuff, the crazy names will still live on. QUOTE Lieware
ADVERTISEMENT In 2007, there was a lot of "rogue anti-virus software," which is sometimes also
referred to as "fake anti-virus software." But these terms are confusing because there's too
much negation going on. Fake anti-virus software is not anti-virus software at all. So what ....
New Rootkit Uses Old Trick To Hide
Info on Trojan.Mebroot (2) Well it seems Trojans and root kits are making a deadly combination this especially with a technique
thats pretty darn old. QUOTE The malware, called Trojan.Mebroot by Symantec, installs itself on
the first part of the computer's hard drive to be read on startup, then makes changes to the
Windows kernel, making it hard for security software to detect it. Well at least I understand
how or where root kits become effective a bit more, but really you think if everyone is aware of it
they would have found a way to patch that hole. I guess not since 5000 computer....
New Aim 6.5 Has Trojan- Win32.tibz.ez
(1) I just recently redid me computer and installed a new OS and i went to install AIM ( I HATE AIM BUT
I KNOW A LOT OF PEOPLE THAT USE IT ) I installed it as normal and my anti-virus went off showing {
win32.tibz.ez } trojan theres no way i could have got a virus that fast. I installed my OS and
updated and then installed and update my zonealarm suite. Then i when to install AIM and my
anti-virus went off and the AIM installer got a error "installation of a component has failed (error
code: IS-2008 ). But the funny thing is after I get the error I can still use AIM and it ....
New Twist On An Old Backdoor Trojan
Suspect this trojan infects or changes BIOS settings (2) Seems, there is a variant of backdoor.Sdbot family of worms and IRC backdoor Trojans that is
disguised as Microsoft Security Adviser. This is quite nasty because it infects system files and is
very difficult to remove. Trend Micro has a nice online tool called House Call but this trojan
survived that so you have to look elsewhere to remove it. No telling what the triggers are but I
simply removed the files and the registry keys pointing to them and now I can't even get into my
BIOS. Search for msscan.exe if you have it then find RegRun on the net and they claim it r....
Could You Be Infected With Hidden Trojan?
continuation of DNS hijack (10) This post is the continuation of my previous post DNS Hijack SearchAtHand.com Browser Result
Removal but deserves its own topic. This trojan, not new but something that's been going
around the web for few years, seems to be quite strong and hard to get rid of. The reason is that it
randomly changes its full file name when a weak anti-spyware attempts to remove it improperly. I
have been using Spybot Search & Destroy and Norton Anti-Virus Corporate Edition for many years and
have never seen such a resilient torjan. Recently I have tried AVG Anti-Spyware but it too....
Trojan /spyware Protection---best---low Resource Util.
PROTECTION LOW RECURSES UTIL . (5) My eyes have been completely opened to all this spyware/Trojan junk... /ph34r.gif"
style="vertical-align:middle" emoid=":ph34r:" border="0" alt="ph34r.gif" /> I'm behind a
hardware firewall in my Router----running Windows firewall----using the very latest Nortons AV....
I seem very secure against "viruses" /blink.gif" style="vertical-align:middle" emoid=":blink:"
border="0" alt="blink.gif" /> But this spyware/trojan thing..... /tongue.gif"
style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" /> Oh my! /ohmy.gif"
style="vertical-align....
Question About Trojan Horse
how to remove them? (14) hi this is the 1st time i am here, so sorry if i posted in the wrong section i received a url thru
msn messenger, i clicked on it and i got trojan horse on my pc i cant remove it with AVG virus scan
this is the report: http://i88.photobucket.com/albums/k199/jinwun/viruss.jpg can anyone help me?
thanks in advance. Welcome to the Trap. I will move it for you. ....
How Do I Completely Remove Trojan Viruses
anti-virus put them in virus vault (36) I have AVG anti-virus on my PC, and a few weeks back it found a trojan virus on my pc. It put it
into the virus vault but could not heal it. How do I completly remove a trojan virus? Or even can
I? Do I have to download specific software to remove it, or is there some more complexe way of
going in to the system?....
Firewall & Antivirus
(8) I have to say the best overall firewall and antivirus i have ever used is the Zone Alarm Pro
firewall and the AVG antivirus.....
I Find A Good Antivirus Complete Suit.
(14) But is not free is shareware. its oo pctools comphany. System doctor. I install shareware version
and made some tests, and beleive this software is great. Detects, removes and blocks all types of
Spyware. have too a lot of script secure for detect and automatically remove process in full
version. http://www.pctools.com/spyware-doctor/?ref...&OVMTC=standard . look there made a tests
and good luck. ....
Why Do People Trojan?
(14) It is so retarded how people will send files with trojans attached, lucky for me, my antivirus is a
king at detecting. But anyways, like 40% of averything i download has a trojan or keylogger, i mean
come on. Why do you have to steal peoples accounts and know info about people, why cant they get
there own lives? Just a warning, use caution, people attach trojans to alot of things. Get a good
antivirus if you like to go on downloading sprees like me =P. I was looking one up online and it
showed that you can look at the saved internet exploror passwords too. My Norton prot....
Top 7 Antivirus For Windows
(13) This will help for those who likes to know if they are using one of the best Anti-virus programs.
1. Platinum Internet Security 2005 2. PC-cillin Internet Security 2005 3. BitDefender Professional
Edition 4. ZoneAlarm Internet Security Suite 5. F-Prot for Windows 6. Kaspersky Anti-Virus Personal
7. G Data AntiVirusKit 2005 (AVK) Reference:
http://antivirus.about.com/cs/beforeyoubuy/tp/aatpavwin.htm ....
Trojan Emits Bogus Google Adsense Ads
Trojan Emits Bogus Google AdSense Ads (5) Trojan Emits Bogus; Google AdSense Ads A Trojan horse program is churning out bogus Google ads
promoting products Google eschews—gambling, cheap Viagra, girlie photos and adult dating. The
ads, being targeted at small publishers, are identical to Google AdSense ads except that referral
graphic buttons are being converted to text, apparently due to a bug in the Trojan, according to the
publisher who reportedly discovered the Trojan. That publisher, Raoul Bangera, told Techshout.com
that the non-contextual and risqué content of the ads are what set them apart from....
Best Antivirus
good and best antivirus (0) hi all world in best antivirus program kaspersky for download www.kaspersky.com SEARCH the
forum before making a new topic. Your topic started here
http://www.trap17.com/forums/index.php?sho...ndpost&p=148439 continue your discussion there. Topic
closed. ....
Get Rid Of Trojan Horse
Think I got one.. (16) Hi everyone! I think I got the virus Trojan Horse, I have a Norton Anti-virus, and he detected
the thing!!! He says its in the system32 directory, but he couldn't delete it. Does anybody
knows how to get rid of this sh*t cause think it lowers my inet speed! and comp. performance. Thanks
alot! xxx Moved to Security Issues area. Original post did not belong in tutorials section. ....
Fastest Antivirus & Firewall Software
(55) I did a clean install of Windows XP some time ago.. It returned to the fast speed and all
animations were sleek... Only after I installed Norton AntiVirus and Norton Internet Security, my
computer became slower then before... Startup now takes longer time and the computer seems to
process something even the computer just boot into the desktop... Task Manager shows a jump of
additional processes in the background... I understand that it's all normal to have Norton
AntiVirus to run applications in the background to track virus every micro-second.. so does Norton
Int....
Trojan Removal
How to/Best software for removal (11) On this topic: http://www.trap17.com/forums/Help-Running-...mize-t8569.html I was told that I
have a Trojan. I downloaded a program called ScanSpyware and am scanning for Trojans. Is this a
good program for me to keep, or is there something better?....
Looking for antivirus, xp, 2008, antivirus, xp, 2009, recent, trojan, threat, symptoms, fix
|
Searching Video's for antivirus, xp, 2008, antivirus, xp, 2009, recent, trojan, threat, symptoms, fix
See Also,
|
advertisement
|
|