Go Back   TechArena Community > Technical Support > Computer Help > Windows Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags:

Sponsored Links



How to remove lzx32.sys?

Windows Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 18-12-2006
LoganX
 
Posts: n/a
How to remove lzx32.sys?

Having searched this on the internet I have found it is malware.
There is a program called Prevx1 which said it could remove it, but it DIDN'T.

How can I get rid of this?

Thanks
Reply With Quote
  #2  
Old 18-12-2006
Earl Grey
 
Posts: n/a
Re: How to remove lzx32.sys?

Hello LoganX:

The first thing I would do is to contact your malware program's
technical support. They will want to know that their program could not
remove your malware, so they can (try to) include a solution in an
update to the program. Moreover, they should be able to give you
specific manual removal instructions.

Earl Grey

LoganX wrote:
> Having searched this on the internet I have found it is malware.
> There is a program called Prevx1 which said it could remove it, but it DIDN'T.
>
> How can I get rid of this?
>
> Thanks

Reply With Quote
  #3  
Old 18-12-2006
David H. Lipman
 
Posts: n/a
Re: How to remove lzx32.sys?

From: "LoganX" <LoganX@discussions.microsoft.com>

| Having searched this on the internet I have found it is malware.
| There is a program called Prevx1 which said it could remove it, but it DIDN'T.
|
| How can I get rid of this?
|
| Thanks


For: Backdoor.Haxdoor, Goldun and RazeSpyware

Marckie's HaxFax
http://users.telenet.be/marcvn/tools/haxfix.exe



Download Haxdoor.exe from the URL --
http://www.ik-cs.com/programs/virtools/Haxdoor.exe

Execute; Haxdoor.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

It is suggested that you perform a Normal Mode then a Safe Mode scan.

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it will be
displayed in your browser (Opera, FireFox or Internet Explorer). However, if you are using
WinXP, Win2K or Win2003 your system will be left in a state where you will have to manually
shutdown/reboot the PC. On Win9x/ME platforms the report will not be shown in your bowser
but your PC will automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.
It would be best to scan in both Safe Mode and in Normal Mode and save a copy of the HTML
report for each session.

Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #4  
Old 18-12-2006
LoganX
 
Posts: n/a
Re: How to remove lzx32.sys?

Thanks for the advice I will try what you have said now.
Also I have just written down one of the blue screens (I turned off the auto
restarts in case of system failure) and here is what it said.

Technical Information

STOP: 0X0000008E (0X0000005, 0XF71CF439, 0XF6C97A20, 0X00000000)
System32:lzx32.sys - Address F71CF439 base at F71CD000, SateStamp 45830b7f

I can't understand it but maybe someone out there can tell me what is wrong
and how to fix it. I took print screens from when windows has loaded with the
"windows has recovered from a serious error" pop up but I think it is similar
information as what I have put above from the blue screen.

Thanks very much.
Reply With Quote
  #5  
Old 19-12-2006
David H. Lipman
 
Posts: n/a
Re: How to remove lzx32.sys?

From: "LoganX" <LoganX@discussions.microsoft.com>

| Thanks for the advice I will try what you have said now.
| Also I have just written down one of the blue screens (I turned off the auto
| restarts in case of system failure) and here is what it said.
|
| Technical Information
|
| STOP: 0X0000008E (0X0000005, 0XF71CF439, 0XF6C97A20, 0X00000000)
| System32:lzx32.sys - Address F71CF439 base at F71CD000, SateStamp 45830b7f
|
| I can't understand it but maybe someone out there can tell me what is wrong
| and how to fix it. I took print screens from when windows has loaded with the
| "windows has recovered from a serious error" pop up but I think it is similar
| information as what I have put above from the blue screen.
|
| Thanks very much.

It's a Backdoor.Haxdoor Trojan.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #6  
Old 19-12-2006
PA Bear
 
Posts: n/a
Re: How to remove lzx32.sys?

To avoid confusiong and duplication of effort, please only reply to your
original thread here (Problems Installing IE7). Thanks.
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE, OE, Security, Shell/User)

LoganX wrote:
> Having searched this on the internet I have found it is malware.
> There is a program called Prevx1 which said it could remove it, but it
> DIDN'T.
>
> How can I get rid of this?
>
> Thanks


Reply With Quote
  #7  
Old 19-12-2006
LoganX
 
Posts: n/a
Re: How to remove lzx32.sys?

Sorry for starting a new thread, but this problem is more widespread than
just installing IE&7 and I's liked to get it sorted as soon as I can.

David, thanks for all your help so far. I did the auto fix of the first
program and it found nothing. But with the second program it crashed to the
blue screen again but it had different information, I tried it twice just to
make sure and here is what I got.

First time:
0X000000F4 (0X00000003, 0X87063020, 0X97063194, 0X805F9F88)

Second time:
0X000000F4 (0X00000003, 0X871173D0, 0X87117544, 0X805F9F88)

Hope that information is helpful in some way and I hope you can help me sort
this out, is there anyway of finding the files on my hard drive that are
causing this and deleting them?

Thanks very much
Reply With Quote
  #8  
Old 19-12-2006
David H. Lipman
 
Posts: n/a
Re: How to remove lzx32.sys?

From: "LoganX" <LoganX@discussions.microsoft.com>

| Sorry for starting a new thread, but this problem is more widespread than
| just installing IE&7 and I's liked to get it sorted as soon as I can.
|
| David, thanks for all your help so far. I did the auto fix of the first
| program and it found nothing. But with the second program it crashed to the
| blue screen again but it had different information, I tried it twice just to
| make sure and here is what I got.
|
| First time:
| 0X000000F4 (0X00000003, 0X87063020, 0X97063194, 0X805F9F88)
|
| Second time:
| 0X000000F4 (0X00000003, 0X871173D0, 0X87117544, 0X805F9F88)
|
| Hope that information is helpful in some way and I hope you can help me sort
| this out, is there anyway of finding the files on my hard drive that are
| causing this and deleting them?
|
| Thanks very much

Close ALL programs.

Download and execute HiJack This! (HJT)
http://www.spywareinfo.com/~merijn/files/HijackThis.exe

Create a HJT log file and post it in the below SpyKiller Forum.

{ Please - Do NOT post the HJT Log here ! }

http://www.thespykiller.co.uk/forum/?action=forum

Please indicate you used Prevx and Marckie's HaxFix utility. Additionally let them know I
sent you.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #9  
Old 19-12-2006
LoganX
 
Posts: n/a
Re: How to remove lzx32.sys?

Thanks for all your help, I have done what you said here.
Hopefully someone over there can get to the bottom of this nasty problem.
Thanks again.

"David H. Lipman" wrote:

> From: "LoganX" <LoganX@discussions.microsoft.com>
>
> | Sorry for starting a new thread, but this problem is more widespread than
> | just installing IE&7 and I's liked to get it sorted as soon as I can.
> |
> | David, thanks for all your help so far. I did the auto fix of the first
> | program and it found nothing. But with the second program it crashed to the
> | blue screen again but it had different information, I tried it twice just to
> | make sure and here is what I got.
> |
> | First time:
> | 0X000000F4 (0X00000003, 0X87063020, 0X97063194, 0X805F9F88)
> |
> | Second time:
> | 0X000000F4 (0X00000003, 0X871173D0, 0X87117544, 0X805F9F88)
> |
> | Hope that information is helpful in some way and I hope you can help me sort
> | this out, is there anyway of finding the files on my hard drive that are
> | causing this and deleting them?
> |
> | Thanks very much
>
> Close ALL programs.
>
> Download and execute HiJack This! (HJT)
> http://www.spywareinfo.com/~merijn/files/HijackThis.exe
>
> Create a HJT log file and post it in the below SpyKiller Forum.
>
> { Please - Do NOT post the HJT Log here ! }
>
> http://www.thespykiller.co.uk/forum/?action=forum
>
> Please indicate you used Prevx and Marckie's HaxFix utility. Additionally let them know I
> sent you.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Reply With Quote
  #10  
Old 19-12-2006
David H. Lipman
 
Posts: n/a
Re: How to remove lzx32.sys?

From: "LoganX" <LoganX@discussions.microsoft.com>

| Thanks for all your help, I have done what you said here.
| Hopefully someone over there can get to the bottom of this nasty problem.
| Thanks again.


OK, good.

Hopefully Derek or one of the others will assist you, soon.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #11  
Old 20-12-2006
David H. Lipman
 
Posts: n/a
Re: How to remove lzx32.sys?

From: "LoganX" <LoganX@discussions.microsoft.com>

| Thanks for all your help, I have done what you said here.
| Hopefully someone over there can get to the bottom of this nasty problem.
| Thanks again.

I was wrong ! :-(

It is not a Backdoor.Haxdoor RootKit, it is a Rustock.B RootKit .

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #12  
Old 21-12-2006
LoganX
 
Posts: n/a
Re: How to remove lzx32.sys?

Well at least you know what they are and what the difference is! More than I
know.
But if it wasn't for you I wouldn't of gotten anywhere near to sorting it out.
Derek gave me a application which I think has fixed it, everything seems to
be running normally again now. Just uploaded a file that he wanted to check
out.

Thank you very much for all your help.

"David H. Lipman" wrote:

> From: "LoganX" <LoganX@discussions.microsoft.com>
>
> | Thanks for all your help, I have done what you said here.
> | Hopefully someone over there can get to the bottom of this nasty problem.
> | Thanks again.
>
> I was wrong ! :-(
>
> It is not a Backdoor.Haxdoor RootKit, it is a Rustock.B RootKit .
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Reply With Quote
  #13  
Old 21-12-2006
David H. Lipman
 
Posts: n/a
Re: How to remove lzx32.sys?

From: "LoganX" <LoganX@discussions.microsoft.com>

| Well at least you know what they are and what the difference is! More than I
| know.
| But if it wasn't for you I wouldn't of gotten anywhere near to sorting it out.
| Derek gave me a application which I think has fixed it, everything seems to
| be running normally again now. Just uploaded a file that he wanted to check
| out.
|
| Thank you very much for all your help.
|

You are most welcome.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #14  
Old 25-12-2006
Brian P
 
Posts: n/a
Re: How to remove lzx32.sys?

I have the same problem as you. How did you solve this?

"David H. Lipman" wrote:

> From: "LoganX" <LoganX@discussions.microsoft.com>
>
> | Thanks for the advice I will try what you have said now.
> | Also I have just written down one of the blue screens (I turned off the auto
> | restarts in case of system failure) and here is what it said.
> |
> | Technical Information
> |
> | STOP: 0X0000008E (0X0000005, 0XF71CF439, 0XF6C97A20, 0X00000000)
> | System32:lzx32.sys - Address F71CF439 base at F71CD000, SateStamp 45830b7f
> |
> | I can't understand it but maybe someone out there can tell me what is wrong
> | and how to fix it. I took print screens from when windows has loaded with the
> | "windows has recovered from a serious error" pop up but I think it is similar
> | information as what I have put above from the blue screen.
> |
> | Thanks very much.
>
> It's a Backdoor.Haxdoor Trojan.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Reply With Quote
  #15  
Old 25-12-2006
David H. Lipman
 
Posts: n/a
Re: How to remove lzx32.sys?

From: "Brian P" <Brian P@discussions.microsoft.com>

| I have the same problem as you. How did you solve this?



For the Rustock RootKit
http://www.uploads.ejvindh.net/rustbfix.exe


Then follow-up with the Multi AV Scanning Tool...


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *




--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "How to remove lzx32.sys?"
Thread Thread Starter Forum Replies Last Post
Unable to remove internal devices from safely remove hardware list? LaMarcus Hardware Peripherals 4 11-09-2011 10:18 AM
change/remove buttons missing in add remove programs Dan99 Windows XP Support 9 10-06-2011 12:52 AM
How to remove External Drive from computer if 'Safely Remove Hardware' disappears Author Operating Systems 1 13-04-2011 06:24 PM
Missing change/remove icon in add/remove programs Morse Windows XP Support 4 12-05-2007 08:13 AM
ALL change/remove buttons missing from Add or Remove Programs jimmymoon Windows XP Support 5 26-09-2006 03:35 AM


All times are GMT +5.5. The time now is 02:28 PM.