ms04-011 lsass exploit, running amok

Discussion in 'Malware Help (A Specialist Will Reply)' started by nykesoul, Dec 11, 2005.

  1. nykesoul

    nykesoul Private E-2

    thanks for being here. if you are major geeks, i am a major newbie, maybe even a zygote.

    while my original problem may be common, and already addressed in your archives, there is a slight twist here:

    my os is in GODDAMNFRIGGIN'CHINESE.

    friggin' is the local dialect here in taiwan.

    i have tried downloading highjackthis, but can't figure out which option on the right-click menu is extract. i have tried all of them, but nothing seems to happen.

    i have tried downloading the programs to give you my basic computer info, but the same thing happens, somewhere along the way, i don't know what is what. this is really frustrating. i have asked a friend to send me english xp, but that could take a month or longer...

    i am not sure where to turn off system restore as it also is on a right click menu, eh?

    any ideas?

    i have been booted off of google with a message saying "your computer is sending out mass emails", been warned by pc-cillin 2006 that the bug is trying to send out my credit card info, yahoo sites tell me in sidebars that the site i am trying to access will only be accessible if i go into pc-cillin options and add "x".com to the excepted addresses that can receive my personal information...the list continues, but what's the point, eh?

    i await your reply with eager anticipation...and a heap of gratefulness, too.

    nyke
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  3. nykesoul

    nykesoul Private E-2

    i don't think you read my post completely...i have tried to do what your solution says, but am unable to complete the process either because i can't tell what the correct choice is or even if i do find it, since it's in an english program, it comes out as gibberish on my computer...please read the post completely. that's the only way you will know what the problem is, eh?
     
  4. nykesoul

    nykesoul Private E-2

    also,...if i back up my hard drive right now, will i be making a back-up of the infection?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I read it but saw no reference to trying to run the READ & RUN ME. All I saw was what you wrote about your problem and you said you tried using HijackThis (which is not the first step). You also said something about
    And you also mentioned not knowing how to turn off system restore. But none of this mentions trying to run the READ & RUN ME. If you cannot figure out which things mean what, how do you expect us to help you when we cannot see the PC at all.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. nykesoul

    nykesoul Private E-2

    chas, thank you for your help! i have successfully made a hjt log and will keep trying to use read & run...

    well, when i click the "manage attachments" button, there is a super quick flash of a screen trying to open .... then it just disappears...probably some pop up disabling thing from spysweeper or pc-cillin...will keep trying...
     
  9. nykesoul

    nykesoul Private E-2

    did that work?...
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than the below, there are no problems showing in your HJT log.

    O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
    O23 - Service: SpywareCleanerService - Secure Computer, LLC - C:\Program Files\Spyware Cleaner\SCService.exe

    Did you install this SpywareCleaner program? If so, uninstall it.
     
  11. nykesoul

    nykesoul Private E-2

    this program installed itself and i have been trying to uninstall, but can't figure out which icon in "system" is the add/remove programs icon...

    ...also, if there is nothing visible in the hjt log, what can i do?

    many thanks!
     
  12. nykesoul

    nykesoul Private E-2

    ...got it!
     
  13. nykesoul

    nykesoul Private E-2

    ...am trying to "unhide" the folders, am in the options menu in tools, but everything is in chinese so i don't know which is which...if you can tell me what the icons look like i can choose that option...will that work?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does this mean you uninstalled it? If so, reboot and then make sure those two lines no longer appear in your HJT log.

    If your log is clean, you will have to run scans to see if anything else can be found. Otherwise I would have to ask if there is something on your PC that you have used to put it into a mode to show chinese text. I do see the below running which is normally related to stuff like this:

    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

    This is part of Microsoft\'s Input Message Editor (IME) for translating Japanese/Chinese text in IE, Outlook and Word
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are no special icons. There are just folders and then check boxes and radio buttons. Right now you do not even need to worry about this because we have nothing that we need to even delete yet.
     
  16. nykesoul

    nykesoul Private E-2

    ...or, there are letters associated with the choices on the first tab (view?) they are: "f" (selected) and "i"; "m" (selected) and "w"; then "s" and "d" (selected)

    unfortunately, when i looked at the tab with the list of boxes to check/uncheck it has no icons or letters associated, just a long list of chinese phrases with boxes next to them...if the boxes happen to be in the same order (which i have found is sometimes, but not always the case) then we can just count them and choose the ones that are in the same location...and hope for the best!
     
  17. nykesoul

    nykesoul Private E-2

    the reason my os is in chinese is because it was loaded with a chinese os ...is there a way to change it into english without reloading the os?????? that would be just unbelievably fantastic!!!!!!!!!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So are you saying the PC was always like this?

    If so, why are you coming to the malware forum for help. This would not be malware?

    Or is your real reason because of the mass emailing?
     
  19. nykesoul

    nykesoul Private E-2

    um, yeah...and the attempts at sending my personal information, including credit cards numbers...and the constant notifications about the @#!&*!! bug...but i didn't want to turn off the notifications, seemed like closing your eyes just 'cuz the view is scary...want to know what is happening, eh?

    and, yes, i removed "spy cleaner" and am sending a hjt log...shortly

    still would like to know how to unhide files and extensions...there are letters for keyboard shortcuts associated with the view tab, could you let me know which are which? that would be very cool...
     
  20. nykesoul

    nykesoul Private E-2

    here is the next hjt log...
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if you can get to the Regional and Languages Options form normal accessed from Control Panel. But try it this way, open Windows Explorer and enter the below into the addess bar:

    c:\windows\system32\intl.cpl

    And hit enter. Now the trick is to see if you can find the English (Unisted States) selection in the top box on this form. You also would have to select United States in the very bottom box.

    If this does not work, try asking for suggestions in the Software Forum on this. This is not malware since your PC is installed with a Chinese OS.

    As far as Hidden files, if you are on that form, the very top item is a Folder and the english text would be Files and Folders. There should be 7 check boxes under it and then another folder icon. This is the icon lableed Hidden files and folders. Under it there are two radio buttons. The upper one should be unchecked and the lower one should be checked. Below this second radio button make sure the next two check boxes are also unchecked. Then click Apply (the apply button should be at the lower right corner of the Window).
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess you did not notice the below:

    O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot

    Have HJT fix this line. And look for the C:\Program Files\Spyware Cleaner folder and delete it.
     
  23. nykesoul

    nykesoul Private E-2

    ...otay, here's the latest...and i deleted swc from the program files folder as well...will that be sufficient? or do i need to zap it somewhere else?

    just a note...the little slogans on the homepage, delicious! who is responsible for these? they make it worth coming to the page all by themselves...
     
  24. nykesoul

    nykesoul Private E-2

    one more time...
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! That should be all you need to delete.

    You mean things like: "MajorGeeks.com - Geek it 'till it MHz!"
    The owners put a whole bunch of them into a script that randomly chooses one to show.

    Did you try what I said in message # 21 yet?

    Gotta go now! Bed time!
     
  26. nykesoul

    nykesoul Private E-2

    ah, yes....this has already been done for me by one of my chinese co-teachers...it helps a weeeee bit, but also changes some of the chinese characters into "?" so on some dialogue boxes there are options with lots of ???????? ??? ????? ??? ? next to them...but most everything is still in chinese...thanks for trying!!
     
  27. nykesoul

    nykesoul Private E-2

    ...um, what about the bug?? there is still a nasty bug on my computer...is there anyone else who can help??

    and, chas, thank you for your time! i am so grateful to you guys for being here!! sweet dreams!!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post exactly what PC-Cillin is finding!

    Is it the antivirus or the firewall that is giving you messages?

    If you cannot run the READ & RUN ME, there is not much else we can do for you to locate any viruii or trojans. You will have to get some one to translate for you.

    Why are you using a PC that is setup for Chinese if you do not understand Chinese?

    You could give the below a run but I'm not sure we will find anything.


    Please download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.

    Good night! (I'm really done this time! :) )
     
  29. nykesoul

    nykesoul Private E-2

    chas, thank you for all your help. it must be awfully late there!

    i am working on a chinese os bc i am in china! the pc was loaned to me from the school i am working for...i am actually in taiwan in the fu xing mountains teaching elementary school kids english

    i have attached the notices from trendmicro (funny, it's a taiwanese company i am told...)...i am so glad i thought to save them!

    it is 4pm for me, so it would be about 2am denver time, and lord only knows where you are...could be even later, so, again, thank you for your help and get some sleep buddy!!:)
     

    Attached Files:

  30. nykesoul

    nykesoul Private E-2

    i have been downloading the programs from "read & run" but received the "bad checksum" message with spybot...how do i choose a different server? does that mean deleting it and reloading it from a different place on the globe? i used au internode as i am in taiwan...
     
  31. nykesoul

    nykesoul Private E-2

    is anyone out there? i am experiencing new and exciting problems with this bug...after downloading ccleaner, ms anti-virus, ad-aware, and doing two of the online scans recommended in "read & run" my anti-bug programs have been disabled and do not function...please, any advice would be appreciated
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These look like firewall related messages. Have you used this PC to purchase stuff via the web? If so, from what sites? Are you sure you are not misinterpreting the messages? Is your credit card info really in the messages? Also note that whatever they are, they firewall is blocking them. You should look in the log or messages from the firewall to see what application is sending this and when. Is it only when on line?

    penton.us.intellitxt.com is related to Vibrant Media. An advertising type adware company. Did you buy anything from them?

    This by106fd.bay106.hotmail.msn.com is a hotmail account related to MS.
    This support.webroot.com the support site for Webroot (the creators of SpySweeper and other tools).

    This us.f321.mail.yahoo.com is for Yahoo Email.
    I have no idea what the last one is: red.as1.falkag.de
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run Spybot and then click Update. When the list of possible updates comes up, look towards the top menu area. And to the right of Search for Updates is a pulldown box where you can choose from a different list of servers. Just try different ones until it works.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please be more specific! What program or programs are you talking about? Are you saying Trend Micro does not work? Or are you having a problem with Spy Sweeper? What is it that does not work? Describe what you are doing and what action that you expect does not occur.

    And exactly what have you run and did any of the scans find anything?

    You also did not run WinPfind that I gave you in message #28.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds