Should I have two Issas.exe file's running...?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Steve_Start, Sep 9, 2007.

  1. Steve_Start

    Steve_Start Private E-2

    Hi there, I recently detected some possible forms of malware: winsup.exe and sleep.exe which were located in docs&settings>all users> start menu>programs>Start Up

    Although, when scanned with norton and avg they found no infections on them I have put them in the recycle bin so far, anyway I think they were connected to lssas.exe which ive read up on and believe that Issas.exe is a virus and Lssas.exe isn't...Now in the processes tab of taskmngr I see there are two running but when typing in the letter I nothing comes up but typing L they appear which leads me to assume these are clean files although Im curious as to why there should be two running, as there is a lssas.exe folder in windows>config created today, should this be here? I've ran avg and spybot full system scans with nothing found so Im hoping everything is ok...

    ***Edit: ive check the processes in avg and 1 lssas.exe is running from C:\WINDOWS\system32\lssas.exe
    and the other is running from C:\WINDOWS\Config\lssas.exe (and looks like a yellow folder as opposed to a normal exe file)

    Many thanks in advance!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure about the file names? lssas.exe is not valid no matter where it is running from. lsass.exe is valid if running from C:\windows\system32.

    If you are having malware problems, please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Steve_Start

    Steve_Start Private E-2

    Hey Chaslang ye sorry they were all meant to have read lsass.exe (doh!) but yeah the folder that was created today at the same time as the other exe files mentioned - I have ended the process and deleted it from the Config folder and re scanned and ran ccleaner etc. and everything seems to be working fine after reboot too, thanks a lot for your response!

    Steve
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Have you run full antivirus and antispyware scans on your PC?
     
  5. Steve_Start

    Steve_Start Private E-2

    I've ran full Spybot and Avg (7.5.1.43 Plus) was considering running norton but am thinking about removing that from my comp now that I have AVG Plus...anyway scans were clean

    When I rebooted the comp today I had a error come up saying that windows could not find (the folder I removed) windows>config>lsass.exe

    Although lsass.exe is still running fine from win32 as it should be and nothing seems to have come of the error...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a very very bad idea to have multiple antivirus programs installed. Uninstall Norton now!!!

    I highly recommend that you complete the instructions given for running the READ & RUN ME and attaching the logs.
     
  7. Steve_Start

    Steve_Start Private E-2

    Ok Norton has been uninstalled..I have the log files to attach altho when running counterspy it started out ok it went really slow after a while and was not going very fast for a few hours, after I post these files im gona reboot in safe mode and try again...
     

    Attached Files:

  8. Steve_Start

    Steve_Start Private E-2

    ...and the others
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you are in pretty good shape. We just have a few things to do.

    First uninstall the Sunbelt CounterSpy trial program since we are finished with it.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below folders which may be left behind:
    C:\Documents and Settings\Steven\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Now delete the below files:
    C:\1F3.tmp
    C:\WINDOWS\system32\thxcfg.ini


    Run HijackThis (select Do a system scan only) and select the following line if it still exists but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe

    After clicking Fix, exit HJT.

    Now run Ccleaner

    Now attach a new log from HijackThis.

    Make sure you tell me how things are working now!
     
  10. Steve_Start

    Steve_Start Private E-2

    Okay done all that with no probs but when I shut down the comp an error comes up saying something like: lsass.exe dll - the application failed to initialize...

    It has been doing that from the start of the problem but I thought hjt would have fixed it there...and the folder is still inside windows>Config and running in the processes window from 'Steven' and the other runs from 'SYSTEM' where I presume is the correct place...

    In case it's at all relevant, the folder inside windows>Config isn't like a normal folder it's a bit more jagged as if the picture quality of it has been halfed, which arose suspicions in the first place...

    Thanks for all your help so far! :)
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must be more specific. Give me the exact word for word message with exact spelling too. HijackThis is not a cure all. It can only fix certain things that it can show. And this is a very limited list.

    I don't quite understand this too. You are not being specific. I thought you said you deleted the lsass.exe file from the c:\windows\config folder. Also the other one (the valid one) does not run from "SYSTEM". It runs from C:\Windows\system32 and you can see it in the HJT log process list you just posted. It is the fourth process down under the Running processes title.


    What files do you see in the c:\Windows\config folder? Be specific and give exact file names.


    You don't appear to have a properly installed and function antivirus program installed. You have some leftover junk from Symantec that is wasting system resources but it is not a functional antivirus and I only said to uninstall it because you said you had AVG7 antivirus installed. Why are you running with no antivirus now? I think perhaps you were confused and thought AVG Antispyware was an antivirus program which it is not. I suggest you uninstall the below (which you may not see both):

    LiveUpdate 3.0 (Symantec Corporation)
    Symantec KB-DocID:2003093015493306

    And then you should unstall an antivirus program like this:AVG Free Edition


    Then attach the below new logs so we can see what may remain from Symantec that needs to be cleaned up.
    1. GetRunKey
    2. ShowNew
    3. HijackThis
     
  12. Steve_Start

    Steve_Start Private E-2

    Sorry, the reason I can't be more specific about the error coming up is that it flashes up right before the computer closes down so it's really hard to see what it is saying in the split second...

    Apologies also, I restored the lsass.exe jaggedy folder to where it was created (windows>config) from the recycle bin after when starting the computer it was coming up with an error saying windows couldn't find the file...so to clarify that is what is in the windows>config folder again, at this time and as I mentioned it's like a windows folder although the graphic quality is poor giving the jaggedy look...

    Also, ye I understand the valid lsass.exe runs from System32, I was meaning the "User name" it was filed under in processes of tskmngr, apologies for the confusion, it was just to mention there were two still running and from different 'user names'

    Your correct, that I have confused the two AVG programs, so I have remedied that as advised, and had uninstalled liveupdate earlier today, and yeah i think there may still be more files left from symantec after a message came up when removing liveupdate that it had found it was still being used by another program or something to that effect, but when going through the list in add or remove programs I don't see any Norton/symnatec programs still installed, hopefully these logs will suggest some answers.

    Also I installed comodo firewall today since Norton has been removed and it came up saying lsass.exe was trying to access the internet, which I blocked...

    Logs to follow shortly, just finishing a scan with the newly installed AVG
    Thanks
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    lsasse.exe is a file not a folder. You need to delete this one that is in the c:\windows\config folder and then empty your Recycle Bin. Also you then need to tell me what else you see in the config folder.


    But which lsass.exe. If it was the one from system32 it is valid.
     
  14. Steve_Start

    Steve_Start Private E-2

    Theres nothin else in the config folder, and as i went in to delete the lsass.exe file, AVG antivirus found it as a virus and healed it and now its gone so I spose that explains it all, now in processes of tskmngr there is only the valid lsass.exe file running, hope that clears everything up (also yeah it was the lsass.exe from the config folder trying to gain access)

    Sorry, still waiting for AVG to complete it's scan, will post logs asap
     
  15. Steve_Start

    Steve_Start Private E-2

    Logs, cheers!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    While I look thru your logs, redo the fixME.reg patch from message number 9 again and then immediately attach a new log from GetRunKey. Also tell me if you receive a success message on adding this to the registry.
     
  17. Steve_Start

    Steve_Start Private E-2

    I received a success last time, and again this time with fixME.reg

    Here is the log...
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay part of the registry patch work and part did not. Let's see if the below fixes the rest of it.


    Okay a couple things from Symantec remain.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Core LC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Now run the procedure in the below link and attach the requested log at the end of the below procedures. This new log is called GetUnKey.txt not to be confused with GetRunKey.txt.

    Getting Uninstall Programs List From The Registry



    Run HijackThis (select Do a system scan only) and select the following lines (the O23 Service line for Symantec may be gone already) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    After clicking Fix, exit HJT.

    Now delete the below folders:
    C:\Program Files\Common Files\Symantec Shared
    C:\Program Files\Advanced Spyware Remover

    Now reboot you PC

    Now after reboot, please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. and don't forget the GetUnKey.txt log too.


    Make sure you tell me how things are working now!
     
    Last edited: Sep 12, 2007
  19. Steve_Start

    Steve_Start Private E-2

    Hi Ok, all those steps went fine I have the log's altho the 'manage attachments' box isn't there right now so I can't select anything to upload...all that is there is the text saying 'Valid file extensions: bmp etc.....
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click refresh a couple of times and see if the Manage Attachments button shows up. If not, then do the below.

    To flush your Internet Explorer Cache:
    • click Tools
    • Internet Options
    • Now on the General tab and click Delete Files and select Delete all Offline content too
    • Click OK.
    • When it finishes Click OK.

    Now click refresh and see if you can attach things.
     
  21. Steve_Start

    Steve_Start Private E-2

    Ok, I use firefox, but Im in internet explorer now and the box is here, so here goes!
     

    Attached Files:

  22. Steve_Start

    Steve_Start Private E-2

    getunkey is too big... Howd u like me to attach/send/edit?

    Edit* I compressed it with winrar, altho .rar file's aren't aloud so I changed it to.zip, hopefully that works for u?
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is the final fix for the left over Symantec item.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    You forgot to say how things are working now. Your logs are clean.
     
  24. Steve_Start

    Steve_Start Private E-2

    Hi there, yeah sorry, everything is working great now, the error has gone when shutting down, thanks again for all your help!!

    Steve
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds