Options

Banker worm?

Well, I found the lsd_f3 in my system folder, but I can't find the reg keys that sophos tells me to delete, I deleted every bad thing I think there was and I still can't delete the .dll. Here Is my Hijackthis log:
Logfile of HijackThis v1.97.7
Scan saved at 2:21:55 AM, on 5/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Registry Clean Expert\RCScheduler.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kazaa Lite\kazaalite.kpp
C:\Documents and Settings\Spear\My Documents\install files\hijackthis\HijackThis.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\System32\fast.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKLM\..\Run: [ist service uninstall] C:\WINDOWS\msstasks.exe /u
O4 - HKLM\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe -X
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [RegClean Expert Scheduler] "C:\Program Files\Registry Clean Expert\RCScheduler.exe" /startup
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: WLAN Monitor Utility.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

and of course I already swtiched over to Mozilla Firefox

Comments

  • edited May 2004
    Have you tried booting up in safe mode and then seeing if your AV program can remove the dll file yet? If not, then boot in safe mode (hit the F8 key right after the inital bios screen shows on bootup) and run your AV software after you are booted up in safe mode. I would think that your AV software will be able to delete that dll then.
  • edited May 2004
    Nope, I have Norton AV and it won't delete it(even from Safe mode which is where i have been working from)
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited May 2004
    SpearSoft, try going here:

    http://housecall.trendmicro.com/

    and letting housecall run through your box.

    And see if any of the things listed here pop up:

    http://uk.trendmicro-europe.com/enterprise/security_info/ve_search_result.php?hidChoice=1&VName=Banker&General=Quick+Search&ddmVPayload=&ddmVType=&radVDayCritSel=1&ddmVWkday=&ddmVMonth=&ddmVDay=&ddmVYear=

    Trend Micro is calling this family Troj_Banker and Command Antivirus is calling it TR.dldr.banker. So far, only hits I can find are in the UK and Europe, suspect Symantec does not know this whole family of vars yet and that we will not see it in US for a couple days in enough qty that Symantec will rush defs out. Housecall knows this family and can ID it for you, the search result will tell you how to delete specific kinds, but write down where Housecall finds it, and the file name-- you will need that info for the instructions on removing to work. Trend Micro knows 5 major variants of it so far.

    It is also known as Troj_Bancos
  • edited May 2004
    Tried it as well, Apparently it is called download.trojan and it is linked to the file: lsd_f3.dll
    and it redirects IE to http://cashsearch.biz/redir.php I tried removing it with CWS shredder, but I had no luck. I tried norton, sopho's instructions, housecall, ad-aware 6, registry mechanic, S&D, everything I can think of. what should I do? It also makes my computer slow as hell.
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited May 2004
    download.trojan is a generic name, unfortunately, for a type family of viruses.

    the only suggestion I can make is to try this:

    go to http://securityresponse.symantec.com/avcenter/download.html

    And get today's (manually installed) def update for NAV-- yes, they added a bunch of defs today, your NAV will not automatically pick them up until Friday.

    It will come as a file that needs to be loaded this way:

    download it from link on page.

    save to desktop(easiest place to find it).

    with NAV disabled and not running, double-click file.

    Let it load defs gotten by download.

    restart XP.

    Now, get into NAV's settings, set it to try and quarantine found viruses, and delete if it cannot. If it can quarantine it and recognize it better with new defs, you can get it killed and then delete the quarantined file. You will get to use the helps in NAV, each version of NAV differs as to how to set details. I would also set NAV in the most agressive of bloodhound modes for the scan you need to do to try and kill this thing, it can be a new one (probably is a new virus, possibly from Japan area) and since most AV does not know it you cannot find howto kill info yet on AV sites.

    Do a scan, expect it to take about 2-3 times more time than normal due to bloodhound mode which uses heuristics to the fullest they can be used.

    Explaining how to kill a file and override XP's protection of a file is hard unless you know command console and how to disable Explorer temporarily and then reenable on the fly, would take big posts, not going to do that in this post. You can email me at feedback link on personal website I have a link to in my signature, I will talk you through how to manually force a file killing, but want to see if an updated NAV can do it now when with old defs it could not find the virus and disable to let you kill it. Plus, I will not get folks ripping on me due to saying too much here that way-- that has happened.
Sign In or Register to comment.