Win32:Brontok [WRM] + Isass.exe need Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kid_JS, Jul 1, 2008.

  1. Kid_JS

    Kid_JS Private E-2

    Hi everyone at MajorGeeks!
    First I would like to thank you for the great job you are doing for simple people ;)

    I turned to to you because I, finaly, got hit by the viruses!
    To the point:
    first it was Win32:brontok [WRM] for a couple of days (phisicaly I just didn't have time and knowledge to sort it out). Then I have found you, guys! And last night tried to do everything that is in READ&RUN. Strangely, for the whole night my avast didn't pop-up once with a warning about brontok (like it did before every half an hour).
    BUT after the first rebbot (after first scan) an Isass.exe process apeared! And as far as I know it is not very good process, it is bad, actually .. real bad! It makes my laptop warm up like a heater and slows it down (so it took the whole night to run every scan)! And, once again, strangely, it is not rebooting every 60 sec like in previous posts about Isass.exe.
    Well all scans are done, a lot of dirty stuff had been removed, but Isass.exe still is in my TaskManager (using the most of CPU).

    Can you PLEASE help me to get rid of it.

    here are the logs ... well some of them (if you going to need the rest logs, I will do scans again, because, for some reason, they disapeared rolleyes )
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We do not need you to attach HijackThis logs. They are already embedded into MGtools. We do however need you to attach the other two requested logs from SUPERAntiSpyware and Malwarebytes Anti-Malware. Please attach the original logs, not new ones from a second scan. We need to know what was originally found. The original logs should still be there. Definitely the SUPERAntiSpyware one will be the below folder:

    C:\Documents and Settings\Jur\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs

    You need to uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.

    What is the below shortcut file?
    Code:
    "C:\Documents and Settings\All Users\Desktop\"
    kŽŒ€‘.lnk    Jul  1 2008        2187  "K®¬¯ á.lnk"
    The logs attached thus far do not show signs of a Brontok infection. It you are running anything else (like Brontok Remover) before running our tools you must stop running them. We cannot fix something that we cannot see and you could be masking something from our scans. If Avast is really detecting something, you need to show us a log or tell us exactly where it is detecting it. Is it just in System Volume Information?

    Please also run this Running GMER to detect rootkits and attach the requested log.
     
    Last edited: Jul 2, 2008
  3. Kid_JS

    Kid_JS Private E-2

    Hi, chaslang! Thanx for reply on my case.

    I've found the other two logs (hurray).
    I've uninstalled Viewpoint Media Player.
    That strange shortcut could be Safari shortcut. Why it looks so weird, because I've renamed it as "Compass" only in russian (компас). (well I am russian, and Safari looks like compass :) ) maybe that's it.

    About running brontok remover. I am not running it. I have just tried it for once, didn't help. It was before all the scans.

    Well as I sad, it seems like brontok is gone. But I am sure it was there. I could send you the same print scans as hala3ammi sent you about his brontok virus. Mine was not in Adobe, but elsewhere in Documents and Settings.

    About that Isass.exe process. In the Security Task Manager it is named as LSA Shell (Export Version). I have checked it in the google and it seems like it is some kind of Sasser virus rolleyes . And when I try to remove this process, then my laptop reboots after 60 sec. Can't do nothing about it.

    Well here are the rest of the logs + GMER log. I really hope that it will show you something.

    Thank You.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be touching this file!!! lsass.exe is a required Windows System file and if you kill the process, the response will be the 60 seconds to reboot message you have received. Leave this process alone.

    Are you actually having any real malware problems at the current time?
     
  5. Kid_JS

    Kid_JS Private E-2

    Hi!
    Ok, I'm not that good at computers, but what I know is there definetely something wrong with mine. Everytime I restart my laptop, it works really hard (that lsass.exe uses almost all CPU) for about an hour! This is why I am worried about that process. Then it "calms" down and only then I actually can work with it. It has never been like that before. Before that Brontok virus.
    After all READ&RUN ME stuff, after the last post to you, I have uninstalled my Avast and installed Kaspersky. It has found that Brontok virus again and deleted it. This night I did the scan again..same thing..it is still there.

    I don't want to be pain in the ... but if you still can try to help me please let me know.

    Here I have screenshots of them scans.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note that text logs of what is being found are MUCH MUCH more useful then screen snapshots. I would have to type everything from your snapshot, but from a log I can just cut and paste. Can you please attach a text log?

    Did you purchase Kaspersky or is this just a free scanner that does not fix anything? If you bought it, you should be asking them why they do not remove this.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I decided to create a fix for you to try but you should still yell at Kaspersky.



    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run this Using BitDefender Online Scan and follow the instructions EXACTLY to create a proper log and attach it. This log (as stated) will contain HTML code and you are just renaming it to have .txt file extension so that it can be attached.
     
  8. Kid_JS

    Kid_JS Private E-2

    Hi, chaslang!
    I couldn't find any of the Kaspersky logs, sorry. But I did everything as you told me to do, except for BitDefender log. For some reason I couldn't save it as a text file, there was no choice, windows only could save it as a html file. So I have copied into word doc. Hope it will be allright for you to read. I was surprised with the results, really. It has found some strange stuff! I mean, what a .... is going on with this machine? Why any other prog could not see this? I really hope that you have some answers, man. By the way, I would like to thank you again for devoting some time on my case. Thanx.

    Here are the logs for combofix and bitdefender + sreenshot (yeap) of task manager for you to see how exactly it looks.

    About Kaspersky.. let's say I have borrowed it.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is just things you downloaded. Most of that is just false positives. The keygen is the only real issue. If you want to avoid having malware problems like you are having, stop using kegens, cracks,....etc. Uninstall all illegal software immediately as it may have been compromised and therefore cannot be trust. Continuing to use software like this could make malware removal impossible because any of them could possibly be reinfecting you.


    As in illegal? If so, unininstall it now.

    You have a load of files in the C:\Program File folder that DO NOT belong here. If you wish to keep them, move them somewhere else. This folder should not be used to store your downloads. Malware stores things here. Thus file being saved here are always suspect and often just removed. Here is some of what I see in this folder
    Code:
    2008-07-01 06:23 . 2008-07-01 06:23 605,224 --a------ C:\Program Files\WindowsXP-KB951376-v2-x86-ENU.exe
    2008-07-01 06:21 . 2008-07-01 06:21 8,723,064 --a------ C:\Program Files\windows-kb890830-v1.42.exe
    2008-07-01 05:25 . 2008-07-01 05:25 1,239,875 --a------ C:\Program Files\MGtools.exe
    2008-07-01 05:20 . 2008-07-01 05:20 1,704,944 --a------ C:\Program Files\mbam-setup.exe
    2007-12-17 17:34 2,274 -c--a-w C:\Program Files\CDmage.ini
    2007-07-31 15:04 1,514,496 -c--a-w C:\Program Files\CDmage.exe
    2007-04-09 18:56 19,017,163 -c--a-w C:\Program Files\Kaspersky.Antivirus.v6.0.2.614.rar
    2007-03-08 06:12 465,919 -c--a-w C:\Program Files\flac113b.exe
    2007-01-30 11:20 12,179 ----a-w C:\Program Files\release_notes_en.html
    2007-01-29 20:44 29,768 ----a-w C:\Program Files\setup.exe
    2007-01-29 20:42 20,593,664 ----a-w C:\Program Files\kav6.en.msi
    2006-12-08 22:48 17,674,296 -c--a-w C:\Program Files\avg75free_432a861.exe
    
    Also are the below files you trust? Did you download and save them here?
    2008-06-02 20:35 263,744 ----a-w C:\WINDOWS\RADIOHEAD.scr
    2008-06-02 20:35 1,528,126 ----a-w C:\WINDOWS\RADIOHEAD.exe




    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
    Now since you have Security Task Manager installed, run it when/if lsass.exe is using all of your CPU and see if STM points anything out. Save a log with it and attach it.
     
    Last edited: Jul 6, 2008
  10. Kid_JS

    Kid_JS Private E-2

    Hi!
    I have followed your advice about keygens and files that are "in the wrong place". Keygens are deleted, files moved to my documents.

    That Radiohead file is a screensaver, but I also have deleted it, just in case.
    Next I did everything you told me to do. I have got all the logs.
    The registry that was added was allright.
    But it is a pity to say, after restartitng and having a look at the taskman, it is still the same thing. Still lsass.exe is running like mad :banghead

    So here are the logs you wanted :
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not address what I requested with Security Task Manager.

    Also Kaspersky is still installed. Is it a legal copy?

    What about Ad-Aware that you have installed with Ad-Watch..... Is it legal?
     
  12. Kid_JS

    Kid_JS Private E-2

    Hi, Chaslang!
    Sorry that it took the whole week to get back to you - have been really busy lately.
    Well the good news are (for me they are, you might don't give a damn about them :) ) - it seems like my laptop is clean again.
    The bad news (for me again) are that I uninstalled all illegal antivirus software that I had by your advice. Thanks for that! No, really, now I realize that it is a bad idea to run illegal copies of antivirus (especially that) on your PC.
    So thanks again for your help and advices. Take care!

    P.S. Now I am running evaluation copy of BitDefender and it will end soon.
    Any suggestions on free anti malware software would be much appreciated..I just can't afford the other choice - for some reason they are not cheap you know...
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Everything you need is covered in the link in the last step below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds