Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

LAMZAP - So far, nothing removes it.


  • This topic is locked This topic is locked
2 replies to this topic

#1 Bud Parker

Bud Parker

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:05 AM

Posted 30 July 2016 - 10:30 PM

I have what I believe is a Rootkit designed to cause havoc.  I have spent many days with other forums trying everything under the sun to remove this devil.

 

Some of the apps I've used so far are; AdwCleaner, aswMBR, JRT, Malwarebytes Anti-Malware, RogueKiller, ComboFix, Rkill, FRST64, etc. . .

 

This Lamzap keeps reappearing in the C:/ProgramData directory.  Even if one app locks the directory, it soon reappears.  It has two initial directories, Lamzap & Lamzaps.  It installs a hijacker in Firefox that takes you to a new unwanted Homepage.  In my case it was a search engine; search.safesearch.

 

It also loads many, many directories in the C:/ProgramData directory.  All contain executables and other necessary files.

 

 

Attached Files



BC AdBot (Login to Remove)

 


#2 satchfan

satchfan

  • Malware Response Team
  • 2,662 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:02:05 PM

Posted 31 July 2016 - 03:23 AM

Hello Bud Parker and welcome to Bleeping Computer.

You have posted in multiple forums which is not fair on the volunteers who offer their free time and can also lead to confusion for you if you receive conflicting advice.

As it appears that you are receiving help here, I’ll close this topic.

Satchfan


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#3 satchfan

satchfan

  • Malware Response Team
  • 2,662 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:02:05 PM

Posted 31 July 2016 - 03:25 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users