Layered Service Provider

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Chewy
    Super Moderator
    • Nov 2003
    • 18971

    Layered Service Provider

    Ran into a new malware/trojan today, must have exploited a recent vulnerability in windows and spread accross a network. Running trojanhunter from safe mode found 13 trojans on one computer, all three had been showing popups. After killing the trojans lost all internet connectivity.
    Ran a new slipstreamed cd as a repair disk, but still no internet, but windows offered to run a network troubleshooter, found the LSP installed and offered to remove it. After reboot the internet worked fine.

    new one on me

    A Layered Service Provider, or LSP, is a piece of software that is tightly woven into the networking services of a computer.
  • volfann
    Digital Video Enthusiast
    Digital Video Enthusiast
    • Jun 2006
    • 384

    #2
    Did these trojans get through a firewall and antivirus or was it an unprotected system? Sounds like a mean sucker.
    sigpic


    Rent This Space



    Comment

    • Chewy
      Super Moderator
      • Nov 2003
      • 18971

      #3
      windows firewall would have been on, one system was running spybot/tea timer and norton's but probably out of date

      in the next few days I'll know more when I check out the other 2 computers

      Comment

      • volfann
        Digital Video Enthusiast
        Digital Video Enthusiast
        • Jun 2006
        • 384

        #4
        Would be interested in hearing more when you finish your investigation Chewy. I like using examples like these to show my wife the dangers that can be encountered from the net.
        sigpic


        Rent This Space



        Comment

        • src2206
          Super Member
          Super Member
          • Jan 2007
          • 234

          #5
          Avoid using TrojanHunter, it has a bad reputation of giving false positives and earlier versions were listed as rougewares.

          It seems that your LSP chain was compromised, and many malwares do that.

          Download and run AVG AntiSpyware in SAFE MODE, allow it to clean. Then download HijackThis version 1.99.1 [not the latest BETA version] and run a full system scan in Normal Mode and save the logfile. Its report will show what is there in your LSP chain. Some LSP malwares are not really easy to remove.

          Cheers

          Comment

          • Chewy
            Super Moderator
            • Nov 2003
            • 18971

            #6
            Avoid using TrojanHunter, it has a bad reputation of giving false positives and earlier versions were listed as rougewares.
            I have always found it to be one of the top 2 or 3 legitimate programs and would have an issue with anyone claiming it as rouge ware

            I have followed the program and it's reviews for over 3 years

            Comment

            • src2206
              Super Member
              Super Member
              • Jan 2007
              • 234

              #7
              Apologies chewy,
              I have mistaken Trojan Hunter with some other rougeware.

              Comment

              • Chewy
                Super Moderator
                • Nov 2003
                • 18971

                #8


                this old review got me started after norton's av failed so miserably with true trojans, I tested ewido and a squared and found them good products also

                it seemed the best work was being done by new german software companies

                well the network security part turned out to be bust, the second computer scanned had 22 adware/trojans but no LSP installed, disinfection left the computer fine

                did find out that the same person(s) had been using both computers
                Last edited by Chewy; 25 Mar 2007, 02:40 AM.

                Comment

                • katzdvd
                  Lord of Digital Video
                  Lord of Digital Video
                  • Feb 2006
                  • 2198

                  #9
                  well the network security part turned out to be bust, the second computer scanned had 22 adware/trojans but no LSP installed, disinfection left the computer fine

                  did find out that the same person(s) had been using both computers
                  Just curious as to their surfing activity; what does the history show?

                  were then visiting "nasty" corners of the 'net, where alot of these nefarious applications are known to propagate?

                  Comment

                  • volfann
                    Digital Video Enthusiast
                    Digital Video Enthusiast
                    • Jun 2006
                    • 384

                    #10
                    I had to train my wife not to "Click Here" every time a web page said "Click Here". The computer she owned when we first met was so infected with junk I spent weeks cleaning it out. She didn't even know what anti virus was. Since it was an old P3 with Windows ME I finally junked it out and gave her one of my older units that she used with no problem until she got into The Sims and needed more power. So far she has kept the Dell XPS unit clean as long as I remind her to watch where she goes when searching for Sims mods and to make sure the firewall and anti virus are always on and updated.
                    sigpic


                    Rent This Space



                    Comment

                    Working...