need your help chaslang...

Discussion in 'Malware Help (A Specialist Will Reply)' started by infoseeker, Jul 28, 2007.

  1. infoseeker

    infoseeker Master Sergeant

    rolleyesHi chaslang, its me again (its still coming in your way with new problem).
    almost three months past, my old HD say goodbye to me (got damaged and did not leave anything to me)
    so i bought a new one and install a fresh xp sp2 pro.
    i have still no internet in my house so i cant follow most of the rules in READ & RUN ME FIRST.
    The virus/worm or let say malware name i noticed is "Cn.wAQdn Isass.exe" in folder C-windows.1
    (but when i take a look that folder, i cant find this shit thing) the SS&D always found everytime i scanned it.
    i found in google 2 cases but no definite remedy.
    i got infected coz of the flash drive of my friend (he ask some of video converter) since i have no internet i did not bother to
    install AV, AS, FW.
    so here my problem: its always puting a folder name "New folder" in every drive connected with my pc with info (when mouse pointing the folder) Company: IT University File Version: 1.0.0
    Run,TaskManager, System Restore are all missing. i noticed that everytime i scanned and fixed with SS&D, Run and TaskManager are coming back but system restore still missing. But when i reboot again, back to square one again(infected again).

    So how i gonna deal with this? im getting afraid to lost again my data.
    i only inquired this here in the pc here my work (even my flash drive is getting infected everytime i connect to my pc in the house)
    so i mustt scanned it here via AVg before i open and always found boot.exe worm

    just let me know what to do. confused
    Please help me and thanks in advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to dowload copies of the below using another PC and then transfer them to your PC via a USB drive, a CD,....etc. The USB infection problem may be cureable by steps further down. However using a CD may be the safest bet if your CD drive still works.
    • AVG Antispyware
    • GetRunKey
    • ShowNew
    • HijackThis
    Make sure you follow the directions in the READ ME for installing and using them and then run them and attach the logs here. You will need to copy the logs back to the other PC so you can upload them here. Without the logs, there is not too much we can do for you other than suggesting that you run an updated antivirus program in safe mode. You other alternative is to boot into safe mode and shutdown ALL unnecessary applications and then make sure you have enble viewing of hidden files and folders as instructed in step 2 of the READ ME. Then look for the below file and delete it:

    C:\WINDOWS\lsass.exe

    Only delete the above if found. DO NOT DELETE C:\WINDOWS\system32\lsass.exe which is valid.

    I also recommend that you never let anyone put anything on your PC again.


    You need to keep your PC properly protected and not let so called friends install or plug anything into it anymore. Especially to install codecs to view questionable videos.

    Do the below:

    Editing AUTORUN.INF on all drives if infected
    1. Right-click Start then click Search
    2. In the Named input box, type:
      AUTORUN.INF
    3. In the Look In drop-down list, select My Computer
    4. Once located, select the file then open with Notepad. Check if it contains the following strings:
      • shellexecute=Boot.exe
      • shell\Open\command=Boot.exe e
    5. If those lines are found, delete the two lines with boot.exe on it.
    6. Make sure you check ALL drives (thumb drive too) and do the same on all drives.
    7. Save the edited file and then reboot.
     
  3. infoseeker

    infoseeker Master Sergeant

    one quick question:

    How can i update this AVG antispyware ocz i dont have internet in my pc?

    i can post tomorow the result

    thanks again...
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  5. infoseeker

    infoseeker Master Sergeant

    Thanks for that, actually i googled that and same as what you said, thanks again

    when i run this:
    getrunnew
    i got the ff:
    Registry Editting has been disable by your administration

    and this one:
    shownew
    i got this
    The system cannot find the file specified
    but it produce results



    cant find that thing

    then i think i delete something like this:
    coz everytime my pc starts, im getting this messages:
    http://aycu11.webshots.com/image/23890/2001772485905689081_rs.jpg
    i think i made mistake

    heres my logs:

    PS-
    i noticed that the TASK MANAGER, RUN are back
    regedit- not working
    System Restore and Folder Option are not working also
    Hompage- its been hijack, cannot change and cannot edit (even though i have no internet) i think you can see that in my HJT results

    thanks again...

    and this "NEW FOLDER" creating in every drive is not anymore there
     

    Attached Files:

    Last edited: Jul 29, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You MUST install and rename HijackThis as requested in step 7 of the READ ME. You have this:

    C:\HijackThis

    It MUST be this:
    C:\Program Files\HijackThis\analyse.exe

    Why didn't you allow AVG Antispyware to fix what it found??


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to HFOBJH
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • VLNEIKQDESUZLG
      • Messenger Sharing USN Journal Reader service
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste HFOBJH into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • VLNEIKQDESUZLG
      • usnsvc
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS.1\system\lsass.exe
    F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS.1\system\lsass.exe
    O4 - Global Startup: MSconfig.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS.1\

    After clicking Fix, exit HJT.
    No reboot into safe mode and delete the below if found
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MSconfig.exe
    C:\Documents and Settings\Administrator\Local Settings\Temp\HFOBJH.exe <-- you may need to login to the Administrator account in safe mode to find and delete this.
    C:\Program.exe


    Now reboot into normal mode.
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. infoseeker

    infoseeker Master Sergeant

    im very sorry chaslang, i forgot that thing regarding the renaming HJT, i read that before but i got again new problem with my pc (hardware i think) red color is missing...

    i have question regarding HJT, so i must rename it before i will run as per your instruction?


    so meaning i will disable System Restore while im in here and after i do this????:

    i know AVGAS i make fix the WORM.VB.ck but maybe later not in the first scanning as the one i attached here

    thanks again
     
    Last edited: Jul 30, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you should properly install it and rename it before continuing.


    No! Only when we have determined that your PC is clean.
     
  9. infoseeker

    infoseeker Master Sergeant

    i dont know what happened :(... my hardware also is getting mess... :cry:cry

    it cant boot in normal mode and also in safe mode...confusedconfused
    i tried everything, checking all but no luckrolleyes.. tomorrow i will bring in the repair shop...
    when all will get back in normal, ill post the things what it needs for my pc..

    thanks a lot....
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good luck!
     
  11. infoseeker

    infoseeker Master Sergeant

    no more luck
    it goes in diagnose and no more choice but to reformat

    thanks a lot for the effort, i also learned again...
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds