Virus Help - In lsass.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by voodoo_ca, Dec 4, 2007.

  1. voodoo_ca

    voodoo_ca Private E-2

    Hi everyone,

    I am close to a mental breakdown because of a virus that is on my aunts computer. It was infected when her granddaughter was using MSN and recieved a file that said something like "hey is this picture you? file.zip"... when she ran this it installed a virus in the computer and caused all of the contacts on her MSN list to get the same message.

    Here is where I am at, and I am stumped...

    1. Almost anything that can help fix the virus closes - hijack this, regedit, msconfig, most antivirus websites...

    2. I have been able to run a hjt log and noticed that the F3 entry is lsass.exe that is starting from a file that is different than windows/system32... this leads me to believe that this is the problem/infected file.

    3. Safemode will not start... whenever I try it, I see all of the files load at the start (DOS view) and then the video goes out of range of the monitor and I cannot see anything...

    I am lost... I need to stop lsass.exe from loading but once its running I cant stop it (because of its critial nature to windows)... I have been searching and searching for solutions and coming up empty.

    Most frustrating is when things close because you use a key word that the virus knows is helping you solve things...

    Anyone?!

    TIA
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    C:\windows\system32\lsass.exe is a valid and required Windows process.

    You need to try and do as much of the below as possible. Try ALL steps even if you cannot do one, continue on thru all of them. Report back later any problems you had. One of the most important things will be getting MGtools.exe to run. You will see this as you work thru the procedure.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. voodoo_ca

    voodoo_ca Private E-2

    Hi Chas,

    thanks for taking some time to look at this...

    I know that lsass.exe is a valid process but I dont think its normally run from this location...

    F3 - REG:win.ini: load=C:\WINDOWS\OPTIONS\CABS\bqgnbyuec\lsass.exe
    F3 - REG:win.ini: run=C:\WINDOWS\OPTIONS\CABS\bqgnbyuec\lsass.exe

    (those are 2 lines from the HJT report I managed to squeeze in before the programs closed)

    I did take a look at your procedures before I started posting (and I have been searching the next left right and centre for hlep on this) and I can either do what you are asking with no result, OR the program wont run, stay running or I cant even get into the website to download things...

    One of the biggest things is that for some reason safe mode puts the video signal out of range of my monitor so I can even do anything in safe mode...

    Thanks again,
    Chad
     
  4. voodoo_ca

    voodoo_ca Private E-2

    I guess I will add this file too so you can look, but I currently cannot get HJT to run long enough to even clean any of these items after a few seconds it closes...

    Even doing a search in a web browser with the word hijackthis causes the browser to crash...

    I will head back to her place again and go thorugh your recommended steps, but most stuff doesnt even dream of working...

    Thanks
    Chad
     

    Attached Files:

    • hjt.txt
      File size:
      7.3 KB
      Views:
      1
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not valid. As I said in my last message, this one is valid: C:\windows\system32\lsass.exe

    You have a Chode infection and running MGtools.exe will often fix at least part of this infection. Did you download it and try running it? Please try. If it does not run in normal boot mode, try running in safe boot mode. If that does not work, try running the below procedure:

    ChodeFix - How download and run
     
  6. voodoo_ca

    voodoo_ca Private E-2

    Hi Chas,

    I am going to go and try all of the steps later tonight. I will let you know which of them I am able to do and the ones that I cant complete.

    I will then try the chode fix and the other tool to see if they can help...

    Your assessment of the chode virus is just from your knoledge having seen this type of thing before? I have been searching and trying to find anything on the net with some help, with little sucess.

    Oh, and I am still having the safe mode problem where the monitor goes out of range, do you have any idea why this would happen?

    Thanks
    Chad
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You just have a different/newer form than is normally seen. By different form, I'm just referring to the location of where the infection is. Yours is in a subfolder of C:\WINDOWS\OPTIONS\CABS which is not the typical location that even ChodeFix will probably not fix properly. In addition, your is playing around with lsass.exe rather than one of the below which has been seen up to now.
    I may have to add your form to ChodeFix after I see all the information that can be obtained by running MGtools.exe
     
  8. voodoo_ca

    voodoo_ca Private E-2

    Ok, I have done the 4 major steps including the chodefix...

    I have added the logs that have been created.

    Thanks again,
    Chad
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We strongly recommend not using Messenger Plus! Live. It has caused tens of thousands of PCs to become infected.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. voodoo_ca

    voodoo_ca Private E-2

    Ok, so I have had a change to try the things that you are suggesting above (or below).

    So far I have added the registry entries. The first time I tried this the virus closed the window so I tried a second time and clicked fast... it said that the keys were succesfully added to the registry.

    Then I ran Avenger... I received an error message, that I think you will see in the log for Avenger. I dont know how it applies...

    And last I ran the MGTools again...

    Here are both the logs.

    Thanks again.

    CK
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Avenger did not run as desired so we will modify our procedure a little and hopefully we get it to run correctly this time. We will also use a new fixME.reg patch.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.


    Make sure you tell me how things are working now!
     
  12. voodoo_ca

    voodoo_ca Private E-2

    Ok, well that all seemed to go much better that time.
    I didnt notice any problems with any of the different steps that I was taking and it appears that everything worked, you will have a better idea from the logs im sure.

    The only thing I noticed is that the startup was looking for the bad lsass.exe that was deleted and said that the registry had reference to it but it could not be found. I am guessing that this was taken care of, and I am going to restart the computer to see what it says now.

    Thanks again for all your help, and let me know what you think...

    Chad
     

    Attached Files:

  13. voodoo_ca

    voodoo_ca Private E-2

    Ok, another quick update...

    I restarted and I am still getting messages saying that the C\WINDOWS\OPTIONS\CABS\bqgnbyuec\lsass.exe is in the registry but cannot be found...

    Not sure where exactly that would be, or where I should look to stop it.

    CK
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\OPTIONS\CABS\bqgnbyuec\lsass.exe
    F3 - REG:win.ini: run=C:\WINDOWS\OPTIONS\CABS\bqgnbyuec\lsass.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    You must remember to tell me if you receive a success message about adding the above registry patch to the registry. If you do not get a success message, it definitely did not work and I need to know this.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     
  15. voodoo_ca

    voodoo_ca Private E-2

    Ok, sorry about the delay but this is the first that I have been able to get back at this computer.

    First off the HostXpert program worked fine... as far as I could tell anyway...

    Next, both of the F3 problems DID NOT show up in Hijack this... seems strange, but they werent there.

    Then I was unable add the information to the registry... here is the error message:

    cannot import C:\Documents and Settings\Cheryl K\Desktop\fixme.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor.

    Not sure what it means..

    finally here is the zip file...

    Thanks
    Chad
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It means that you did not create the file properly. This will happen if you do not have the REGEDIT4 as the top line (like you left it out) or if you put a blank line above it. Or other similar issues.

    It does not matter now. As the offending items are now gone. You just have one line to fix with HijackThis:


    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    Your logs are clean other than the above.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds