Is this a sasser variant?

Discussion in 'Malware Help (A Specialist Will Reply)' started by urbmd, Jan 8, 2011.

  1. urbmd

    urbmd Private E-2

    Can you tell me what virus this is? I have a virus on an old (but important) win2000sp4 computer that seems to act like a sasser: After startup, a small fake password box appears on the desktop with a 10 second system shutdown countdown. If it is clicked on, it puts a timer in the upper left desktop corner, which counts down about another 50 seconds then shuts down the computer, and seems to use a fake "it is now safe to turn off your computer " screen.

    Malwarebytes in safe mode or normal (the one time I somehow stopped the shutdown) mode finds nothing. Using "shutdown -a" does not stop the shutdown or just crashes the shutdown.exe program, then it shuts down anyway.

    The one google reference I found sounds exactly like this: http://www.techspot.com/vb/topic34623.html , but that was from 2004 and it is hard to believe malwarebytes can't find a virus from 2004.

    I am working through your required Run and removal processes, but from safe mode it will likely take me the rest of the day, and I am wondering should I even try to install Spybot search and destroy while in safe mode as it will not be able to update, and if the malwarebytes will cause interference?

    Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was 2005 and CyberSitter is not a virus. Also Malwarebytes is not an antivirus program.

    Spybot is not part of the READ & RUN ME.

    Just finish the READ & RUN ME and attach the logs. Then we may be able to give you more specific answers to what your problem might be, but CyberSitter does sound like a candidate.
     
  3. urbmd

    urbmd Private E-2

    After much work getting Avast to load in safe mode (it removed several pups but the timer still kept appearing), I used taskmanager to shut off a process ParentalLockGuard.exe and this stopped the shutdowns. Parental Lock guard is a lousy internet safety freeware that was recommended by Cnet.com that I tried for a few minutes then uninstalled about 4 years ago, but apparently it did not fully uninstall. What caused it to reactivate its timer I don't know; perhaps someone is now using it as malware.

    I searched for the ParentalLockGuard.exe, deleted it, and since have not had any problems.

    Thank you for your help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds