Help Needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by lost0, Jun 2, 2006.

  1. lost0

    lost0 Private E-2

    Hey there, after formatting twice Im still having issues,

    Still have lsass.exe running giving me 60 second shutdown message when closed,but no scan is picking up the sasser worm. Plus im still occasionally getting svchost.exe taking up all the cpu.

    Any help would be appreciated. Thanks
     

    Attached Files:

  2. lost0

    lost0 Private E-2

    I should add that ive also run Ccleaner, Microsoft Windows Malicious Software Removal Tool, Ad-Aware SE, Spybot Search & Destroy as well as Counterspy, and gone through the registry myself to remove any suspicious entries. However every time i connect to the net, after a certain amount of time svchost start going nuts. Also, through process explorer ive seen svchost has opened up command prompt, and also ftp.exe, as well as strangling my net by sending out packets. I think ive fixed most of it but as i mentioned above svchost is still going nuts and no scan seems to be able to pick up/fix the problem.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You are having problems because you have not installed the updates for your OS. You are only running SP2. You need to get upgraded to Windows 2000 SP4. Goto the below link and immediately complete step 1:

    How to Protect yourself from malware!


    You may need to selectively run only a few updates at a time if your PC is getting shutdown every minute. Or you could try using another PC to download SP4 and burn it to a CD and then install on the infected PC. The below link may help:

    http://www.microsoft.com/windows2000/downloads/servicepacks/sp4/sp4Eng.mspx


    You should also delete the below file:
    C:\WINNT\system32\setup_71367.exe
     
  4. lost0

    lost0 Private E-2

    Cheers chaslang!

    Yeah I know I should be SP4 but since I reformatted ive had phenomenal issues trying to update to because im on dial up. This is an issue because by the time its halfway through downloading the pack, svchost has gone nuts and if i get all the way through the download the only way i can free up cpu to unpack the files to install it is by resetting svchost through process explorer, but this generally leads to other problems anyway, as when I did this two days ago the install didnt work properly and I couldnt repair windows, so inevitably had to format. I'll give SP4 another go tonight as the system seems to be running a bit better, and i'll let you know.

    A couple of questions though, should LSASS.exe be running from startup? The only time its giving me 60second shutdown message is if i manually end it so it's not too much of a problem but I'm curious? Also that file (setup_71367.exe) doesnt seem to exist, so I assume it's gone if it was there. Also is there a downloadable version of SP4 that is offline installable, ie. a simple self extractor rather than running through microsofts downloader? If not any idea where the temporary SP4 files are downloaded to? Because I believe in order for the installation to be successful I'm going to have to do it after freshly rebooting, but if I do this currently I lose the downloaded setup files?

    As I write this Norton has just picked up C:\WINNT\system32\qvbo.exe infected with w32.linkbot, only I cant find the file through explorer so I can't manually delete it, and Norton can't fix it, any thoughts?

    Thanks heaps for the help its very much appreciated, sorry my posts are sort of all over the place its been a long time since ive done this sort of shit haha :D~
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It is a valid process that should be running.

    Did you enable viewing off hidden and system files in the READ ME?

    It's in the 2nd link I gave to you. See the one titled: SP4 Network Installation

    It is a 129Mb download so you may need to get someone with a highspeed connection to download it for you and burn it to a CD. Then you can install it while offline. After installing it. You will need to go back to Microsoft's Windows Update site because there are many more updates to add even after SP4.


    This is the Microsoft Windows LSASS Buffer Overrun Vulnerability problem you are having. Try deleting it in safe mode, it may be necessary to kill the process first. None of the symptoms of this infection showed in your previous HJT log. See the below for more info on this infection:

    http://www.symantec.com/avcenter/venc/data/w32.linkbot.m.html

    You could try to download just the below patch from Microsoft and install it but I'm not sure if it will install on a system only running SP2:

    http://www.microsoft.com/downloads/details.aspx?FamilyId=0692C27E-F63A-414C-B3EB-D2342FBB6C00&displaylang=en
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds