Found Trojan horse gen* and decompression bomb on my system

Hi,

I downloaded a file from internet and executed it, from the point my system has been opening IE as soon as I start IE, and then I get an error, that IE must close.

Sometimes, it just redirects be to multiple sites

So I scanned by system with AVG, and AVAST, these are the list of what it showed:

Trojan Horse Lop.BL
c:\document and settings\user\local settings\temporary internet files\content.IE\NLY1WBG\lo1[1]

Trojan horse generic3.QLS
c:\windows\system32\hfpwoxa.dll

Trojan horse lop.bl
c:\windows\system32\geeby.dll

adware generic ABS
c:\program files\install shield installation information{FOA37341-D692-11D4-A984-009027E-C0A9C}\setup.exe

A0107950.dll - Trojan horse generic3.qls
in system vol info folder

A0096944.exe - Trojan horse generic2.EWV
in system vol info folder

A011492.exe - Trojan horse generic2.EWV
in system vol info folder

C:\FOUND000\FILE0000CHK\FILE000
Unable to scan → this is a decompression bomb

There were some more of the same kind.

I tried to heal these files through AVAST AVG didn’t work.
I tried to move these files to vault through AVAST AVG didn’t work.
I tried to delete these files through AVAST AVG didn’t work

Every time I get the same message unable to scan.
I tried to manually delete these files, a few I could but most of them, specially
C:\FOUND000\FILE0000CHK\FILE000
I couldn’t find this.

I read about it as much as I can manage in a day on internet, but still I don’t have any information to remove these files.

I use my computer to work from home, so formatting it would be a big step for me.
Can anyone help me with this.

Please!!!

Hi ashanka,

Do you have avast! and AVG installed on your computer? Two AV’s with resident protection is not a good idea because they will conflict and cause problems.

Please go to Start>Control Panel>Add/Remove Programs and uninstall Lop, if you can find it. Also check that you have no adware/spyware programs in Add/Remove: Google any applications you are not sure about and remove any that are reported to be adware or spyware.

Then run these free adware/spyware/Trojan scanners:

AVG Anti-spyware (requires Win2k/XP):

http://www.ewido.net/en/product/

a-Squared Free:

http://www.emsisoft.com/en/software/free/

Ad-Aware:

http://www.download.com/3000-2144-10045910.html

Spybot Search & Destroy:

http://www.safer-networking.org/en/download/index.html

Don’t forget to update all the programs before you scan!

It’s best to do the scans offline and in safe mode if possible:

http://www.computerhope.com/issues/chsafe.htm

Might also be worth running these two tools if you still have problems after running the scanners:

http://www.bleepingcomputer.com/forums/topic18610.html

Please also check that you have the latest version of Sun Java and remove all older versions from Add/Remove Programs.

http://www.java.com/en/download/index.jsp

Hi,
I’ve both these softwares installed on my PC.

I had avast but, after I was not able to delete the files using Avast I installed AVG

Hi,

 I cannot connect to internet while working in safe mode, is it possible?

Also I’ve zone alarm firewall.
And may be it got corrupt, because I’m not able to update it anymore.

I've both these softwares installed on my PC.

You must uninstall one or you will have instability problems.

I cannot connect to internet while working in safe mode, is it possible?

Update the programs while connected then scan in safe mode offline- not connected to the internet.

Also I've zone alarm firewall. And may be it got corrupt, because I'm not able to update it anymore.

You can download the latest version and choose the upgrade option when installing.

I recommend doing this immediately after you finish all your scans and while still offline- download a copy of ZA before you start your scans.

Thanks I’ll try them all.

You need to boot in Safe Mode with network support (there must be an option to that if you click the F8 key while booting…).

Hi,

  I've tried all the steps that have been mentioned, but still everyday I find new trojans in the system. And ealier I was able to get into safe mode to can now, it boots to safe mode but I get only a blank screen, I can reach the task manager using CTRL+ALT+DEL, that's all that I can do.

 Also I uninstalled my Zone Alarm Firewall since it was not working, now I am not able to reinstall it cause it say's that the VSMON.exe file is corrupt.

 I uninstalled all my Antiviruses and installed the latest versions, they are working well, but not the Firewall.

Is there any other way that I can get these Trojan's out.

Thanks,

Clean your temporary files.
Disable System Restore.
Schedule and run avast at boot time. Send infected files to Chest.
Enable System Restore again.

Very probably you have an open backdoor allowing new Trojans to be downloaded onto your computer as soon as you delete the old ones.

You can only try again: update all your anti-malware applications.

Download a clean installer for ZA.

Go off line: pull the internet connection.

Run boot time scan with avast!

Run scans with AVG Anti-Spyware, a-Squared, Ad-Aware and Spybot.

Try to install your firewall again.

Reconnect to the internet and see if you still have problems.

Otherwise it looks like a reinstall of the OS might be the best option.