lsa shell (export version)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Spidersan, Sep 14, 2008.

  1. Spidersan

    Spidersan Private E-2

    Hello,



    I’ve noticed my pc going slower gradually with days so I started looking around for what might be wrong, I’m no expert but I got some basic skills, and found “Lsa shell (export version)”. After looking it up over the internet, it said its sasser worm so here is what I did then

    Rebooted in safe mode > full scan on the pc, found one virus, deleted, then restarted again just to find the same problem lurking still. After trying stinger, ad-aware, malware removal tool by MC, Ccleaner, Registry mechanics, updating etc etc (trust me my pc been scanned like a bish the past few days lol) I gave up on getting this infection out and did a system restore to a time where I didn’t have any problem. Yet I still have the problem. Right now, I only have about couple hundreds of hairs on my head. Things I’ve noticed change:

    - Browsing over the internet can be real slow at times, normal at others.
    - Pc processing became slower
    - Can not log into my hotmail, only from this pc, as it takes about 10 mins or so trying to sign in then gives up
    - Skype starts then disconnects then takes about 2-3 mins to reconnect again.
    - Playing online games isn’t affected at all with this slowness, everything runs perfect and fast on the game
    - I have NOT got any error messages from this problem, which is weird….


    I also read removal guide and been browsing for a similar case, found one (with almost exact problem on everything) but it did not work for me

    please, if not for my PC...do it for my hair :cry
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    No!!! C:\Windows\system32\lsass.exe is a valid Windows system file and it is called LSA Shell (Export Version).


    You need to run it! And attach all 4 requested logs. Quite frequently slow PCs are not due to malware but the only way to really know is via these logs.
     
  3. Spidersan

    Spidersan Private E-2

    first of all, thank you for your reply and sorry for the long wait, I got busy with college

    here are the requested logs
     

    Attached Files:

  4. Spidersan

    Spidersan Private E-2

    also this one
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While MBAM found and removed a few problems, that is the only malware found. Your logs are clean. You do need to uninstall the below as requested in step 1 of the READ & RUN ME:


    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Viewpoint Manager (Remove Only)


    And you really need to stop using MSconfig as also requested in step 1 of the READ & RUN ME.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. Spidersan

    Spidersan Private E-2

    sorry about Msconfig, meant to change it before i shut down but i forgot. did everything you said and the fixme.reg message said it was successful. However, i'm still having the problem of a really slow connection/process and the random spam that comes to my msn messenger since 2 weeks.
    I'm just glad its not a virus

    Thanks a bunch guys!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be a malware issue, but before I send you off to the Software Forum, let's check for rootkits.

    Run this Running GMER to detect rootkits and attach the log.

    Once you get your email address on spam lists, you will continue to get more and more spam especially if you ever respond to any of them in any form. Even it is to try and unsubscribe. If you do this, you just confirm that your email address is valid and you will get more spam. Everyone gets spam. If it really bugs you, try out some spam blockers but you may find that they block things you do want.
     
  8. Spidersan

    Spidersan Private E-2

    ok i went according to the topic until the copy part. It says "copied to the clipboard" but i can't seem to paste anything anywhere, i tried doing it few times but no luck. Instead, i did "save as" and changed it from .log to .txt

    a 2nd problem, I been trying to upload that file here but i keep getting
    "sending request to forum" for a long time then "Upload of the file failed" I'll try to upload it again later
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the size of the file? If it is too large, you may need to ZIP it to attach it.
     
  10. Spidersan

    Spidersan Private E-2

    oh that made it work!:-D
    here it is
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The GMER log is also clean. The only other suggestion I have for you to try is to uninstall McAfee, reboot, and then run the below

    McAfee Consumer Product Removal Tool

    Then see how things are working. If still having problems, uninstall ZoneAlarm, reboot and then see how things are working.

    If uninstalling the above have no effect on your problem, then reinstall your protection. Then complete my instructions in message # 5. Then post the specific details of your problems in the Software Forum and tell them you already did the malware removal procedures.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds