MSN Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by The Goatman, May 3, 2007.

  1. The Goatman

    The Goatman Private E-2

    Hi

    My daughter has inadvertantly dowloaded some kind of virus from MSN. It seems to have slowed her laptop to a virtual grinding halt......I've followed all the procedures in your malaware removal section. I'm posting logs as even after the scans, the computer is still very slow. We've also now got an error on Start Up - 'Windows cannot find 'C:\WINDOWS\system32\rxksiin\lsass.exe' & Windows cannot load or run 'C:\WINDOWS\system32\rxksiin\lsass.exe' - can you help with this? I couldn't get a log from CCleaner by the way....hope this doesn't matter too much.

    The Goatman
     

    Attached Files:

  2. The Goatman

    The Goatman Private E-2

    Here's my Hijack This log.....

    The Goatman
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We do not ask for a log from CCleaner, but we did ask for one from CounterSpy and also you forgot the log from ShowNew! Also more importantly, you ignore step 3 of the READ ME. You must only use one antivirus. You have Avast and AVG installed. Uninstall one of them now.

    Also remember to remain in one thread for your problem!
     
  4. The Goatman

    The Goatman Private E-2

    Sorry

    Missed this one

    The Goatman
     

    Attached Files:

  5. The Goatman

    The Goatman Private E-2

    I've just added 'shownew' - can you work with what I've sent, or do you need CounterSpy log - I'll unintall AVG.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run CounterSpy? Did it find anything? Did you fix what it found or did you ignore what it found which many people do by mistake?
     
  7. The Goatman

    The Goatman Private E-2

    Some files were quarantined - here's the report.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download MsnVirRem.exe to your desktop.
    • First close any other programs you have running as this will require a reboot
    • Double click MsnVirRem.exe to run it
    • Once open, click the button labeled Search and Destroy Your computer will now be scanned for Infected Files
    • When scanning is finished you will be prompted to reboot only if infected, Click OK
    • Now click the REBOOT Button.
    • After the Reboot, you will receive file not found errors! Please acknowledge them and continue.
    • A Message should popup from MsnVirRem if not, double click the program again and it will finish.
    • Please attach the C:\msnvirrem.log to your next message
    • Now download this file - combofix.exe by sUBs
    • Double click combofix.exe & follow the prompts.
    • When finished, it will produce a log for you. Attach this log to your next reply
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  9. The Goatman

    The Goatman Private E-2

    The link to the MsnViRem.exe isn't working and I can't locate it! Here's the combofix.txt file.....
     

    Attached Files:

  10. The Goatman

    The Goatman Private E-2

    Sorry - found the MsnVirrem.exe but it didn't find anything, so didn't ask me to re-boot. It was a very quick scan - is this right?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay don't worry about MSNVirRem! Run this ChodeFix - How download and run and attach the log from it.



    Now also attach the below new logs
    1. GetRunKey
    2. ShowNew
    3. HJT
     
  12. The Goatman

    The Goatman Private E-2

    All done. Here are they all are!
     

    Attached Files:

  13. The Goatman

    The Goatman Private E-2

    How do I supply a log for chodefix? I've run it but can't export the findingd to a txt file?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would have to copy & paste from the command prompt window. Don't worry about it now!


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 5
    Kazaa Lite Resurrection 0.0.8

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F3 - REG:win.ini: load=C:\WINDOWS\system32\rxksiiu\lsass.exe
    F3 - REG:win.ini: run=C:\WINDOWS\system32\rxksiiu\lsass.exe
    O1 - Hosts: ECHO is off.
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Startup: lsass.lnk = ?

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\system32\rxksiiu\lsass.exe
    C:\WINDOWS\st2.exe
    C:\WINDOWS\tci.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.
    After reboot locate the below folder and delete if found:
    C:\WINDOWS\system32\rxksiiu

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  15. The Goatman

    The Goatman Private E-2

    All seems to be running fine now.....I've gone through all the processes. Here are the files attached. Hopefully we're malaware free now - cheers for your help!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks better but one item I asked you to fix still remains.

    O4 - Startup: lsass.lnk = ?

    Shutdown Avast and Spyware Doctor, then use HijackThis again to fix the above line. Then check a new log. Did the O4 line get removed this time?
     
  17. The Goatman

    The Goatman Private E-2

    HiJack this failed to delete this file saying it was in use! I have closed the applications you mentioned and tried again but it still won't delete it. The error messages on start up have now gone - is this going to be a potential problem?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It means some aspect of the infection still exists. Please try fixing it after booting in safe mode.

    Also get me the below two logs from Safe Mode (we don't normally want logs from safe mode but sometimes they are necessary).
    • GetRunKey
    • HijackThis
     
  19. The Goatman

    The Goatman Private E-2

    That's weird - it's disappeared in Safe Mode - here's the log. I'll re-boot in normal mode and check to see if its still there.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot the GetRunKey log I requested from safe mode.
     
  21. The Goatman

    The Goatman Private E-2

    OK I'l do that now, but I've just run HJT in normal mode and the item still exists!
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's is what I expected. When you login to safe mode, which user account are you using?
     
  23. The Goatman

    The Goatman Private E-2

    Here's the log from Safe Mode as requested. I'm logging in as Administrator in Safe Mode.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to login to the same user account as normal boot mode. The infection was not in the Administrator account. Please login to the same user account as in normal mode and then attach the two requested logs.
     
  25. The Goatman

    The Goatman Private E-2

    Yes, it seems to be here in Safe Mode and once again HJT won't delete it, saying that it's in use! HJT is also asking me to email someone with the error log....
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay boot into safe mode as the user named Jade Skirton, run Windows Explorer and look for the below file and delete it:

    C:\Documents and Settings\Jade Skirton\Start Menu\Programs\Startup\lsass.lnk

    Then reboot in normal mode and attach a new HJT log.


    Question: Did you knowingly install and do you use this SweetIM software? This has been classified as debatable software which means it is on the edge of definitely being classified malware.
     
  27. The Goatman

    The Goatman Private E-2

    Looks to have gone - here's the log.

    No - I think my daughter clicked on a link by accident! That was her excuse - she has been told!
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is!

    I assume you are referring to SweetIM?? Do you need this? If not then uninstall it.



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds