I tried, I failed, I need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sgt_Pepper, Jul 17, 2005.

  1. Sgt_Pepper

    Sgt_Pepper Private E-2

    I completed all the steps in the FAQ and am still having the problem. When I try to run the internet, it intially runs very slowly (I have broadband) and then stops loading all together. I will click on something and the status bar will just say "Done" on a blank page. I use firefox, but had the same issue with IE. I am in safe mode right now because I can't use the internet otherwise, but I ran HJT in normal mode, and have attatched the file. Bitdefender found and deleted four viruses, but it didn't solve the problem. Neither Stinger or RAV found anything, nor did any of the other programs I ran. Thanks in advance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the future please do not post HijackThis logs unless requested. You must only run one HijackThis session and you must run it the correct folder. You had:
    C:\Documents and Settings\HP Authorized Custom\Desktop\hijackthis\HijackThis.exe <--- should not be running
    C:\Program Files\hijackthis\HijackThis.exe <--- correct

    Also you must exit ALL browsers ( C:\Program Files\Mozilla Firefox\firefox.exe ) before using HijackThis.

    First goto Add/Remove programs and uninstall the below if found:
    Viewpoint Manager <--- unless you use it. Most people do not.
    WildTangent

    You should not be running McAfee Virus scan online ( C:\WINDOWS\MCBIN\AV\RT\MGAVRTE.EXE ) when you already have Avast.


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to lsass or Local Security Authority System Service Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    lsass


    If that does not work, try: Local Security Authority System Service


    You may be told to reboot at this point. Do not reboot just exit HijackThis and we will be restarting it with different options in a moment.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [System Kernal Support] system.exe
    O4 - HKLM\..\Run: [Services] C:\WINDOWS\csrss.exe
    O4 - HKLM\..\RunServices: [System Kernal Support] system.exe
    O4 - HKCU\..\Run: [System Kernal Support] system.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O23 - Service: lsass (Local Security Authority System Service) - Unknown owner - C:\WINDOWS\lsass.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\csrss.exe <--- only delete the file in this folder. Do not delete the one in system32
    C:\WINDOWS\lsass.exe <--- only delete the file in this folder. Do not delete the one in system32
    C:\Windows\System32\system.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  3. Sgt_Pepper

    Sgt_Pepper Private E-2

    Thank you, it seems as if the problem is gone. I ran a new HJT and have attatched it. I am noticing none of the effects I did before. Thank you again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds