VBS/Sasan.a.worm

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ancsi0909, Oct 12, 2008.

  1. Ancsi0909

    Ancsi0909 Private E-2

    Hello!
    I've read through some postings and found that you already helped other guys with this problem, I hope you can help me too.

    I've got a Microstar notebook (3 yr old). About a month ago it began to act strangely, the switching on required a password and by switching off there were not the usual pics, but text instead to log off or switch on, etc.
    Then one day (2 weeks ago) if I clidked on "own computer", or C: or D: driver, it would not open, because of a missing script file, and also the "task coordinator" (in the CTRL + ALT + Delete section) didn't work, and it appeared a failure message that there's a trojan spyware program on my PC, which can access to my personal data.
    I went to the service and they rebooted everything, and gave my a new Panda Pro 2009 program. My PC worked fine for 10 days, without having to enter the password at the beginning, and with the images to switch off.
    But 2 days ago I put in a pendrive (memory stick) and I saw two hidden files, and immeaditaly Panda told "C:/.MS32DLL.DLL.VBS file has VBS/Sasan.A.worm, it was cleaned." But the message came up every 2 minutes, again and again, with C and D driver, same worm.
    I went to the service again but they couldn't help. Yesterday the Panda program by checking the whole PC found and deleted 3 worms, from the D driver, and the message doesn't come up any more, BUT I again get a failure message of a missing script file by trying to open in Own computer D: driver. (C: can open). And by switching on it asks for the password, and no images, but text instead by switching off, too. So partly the problem seems fixed, but I know that it's still on the computer somewhere! What shall I do? Can you help?
    Thank you in advance.
    (Sorry for not knowing the exact phrases as I'm Hungarian and I have Windows XP in Hungarian language.)

    Thanks!
    Ancsi
     
  2. Ancsi0909

    Ancsi0909 Private E-2

    Hello there,

    I went through the "Malware removal" "read first" points, installing and running all those different programs.
    It did help in a way: now I can access D: driver through "Own computer", but it still asks a password (no password existing, just to click enter while logging in as User) and it still has written texts by switching off, not the three images (if you know what I mean...).
    I attach the log files and zip which the programs gave me. You will find a "doc", where I saved the result of the three programs together: SUPERAntiSpyware Scan Log, Spybot – Search & Destroy, and Malwarebytes' Anti-Malware 1.28. (I run the first twice, so you'll find two dates, both today). I hope you'll understand the essential, even if it's in Hungarian...

    Thanks for the help so far & I'm looking forward to get your response to the remaining problems. Thanks!
    Ancsi
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to run MGtools again and make sure that you accept the license agreement for TrendMicro HijackThis and also make sure that you allow MGtools to finish running. Your logs are very incomplete. Also make sure the Panda is not blocking it from running. Attach a new MGlogs.zip file.

    Based on what I see in the logs you have attach thus far, I do not see any malware issues.
     
  4. Ancsi0909

    Ancsi0909 Private E-2

    Hi there!
    Thanks for your reply.
    I'm afraid I can attach the same file, because I run MGTools again, but it did not ask me for a licence agreement and there was no pop up window about TrendMicro HijackThis.
    I uninstalled Panda for this 20 minutes because I couldn't switch it off (it didn't work with the right-click on the icon), so it surely didn't block it now.

    I read the possible error messages, but in the log it only said "Error: The system was unable to find the specified registry key or value" a dozen times.

    I don't know why it's incomplete, and I don't know why the HijackThis doesn't come up or asks me for accepting... :(

    I attach the new MGlogs.zip file.

    I also think, all those antivirus programs that you suggested managed to clean the PC, but can you tell me how to adjust those 3 small things, that I mentioned, that are not working now the way they were before? (1. By switching on the desktop appeared, I didn't have to press enter for the non-existing password, 2.) by switching off there are not the 3 images, but a text-box where I have to scroll down for restart or log off and 3.) for some reason I can't change the form of the date, which is shown in the desktop, down and right. Before it was "15:44" but now it's 15:44 v1.0. Also in the Outlook it says "12.10.2008. 16:20 v1.0." and I'd love to "delete" this v1.0 and have only the time, but it wouldn't disappear, whatever I try to change.)

    If there's a trick how to get the licence's approval request, please let me know.

    Thanks for your help!

    Aniko
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still did not run properly. Are you using a 64 bit version of Windows?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not safe to immediately logon without requiring a password. If you do this, you are giving any malware or hacker complete ability to do anything they want to your PC after gaining access.

    I'm not sure what you mean. Can you post a snapshot? It sounds like a possible registry setting change but I don't know what.

    Perhaps the below will be of some use as it shows where and how to change clock settings.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.
     
  7. Ancsi0909

    Ancsi0909 Private E-2

    "Still did not run properly. Are you using a 64 bit version of Windows?"

    I just called the PC-service where they repaired it, and the guy said I'm using a 32 bit version. So I don't know, why MG tools doesn't run properly. :-( Could it be something to do with the firewall? If you have any other idea what to do, I'll try.

    As for the small inconveniences:
    OK, I listen to you and leave the logon session on by switching on the PC.

    As for the time format v1.0 - you are the best! Thanks, I found where to adjust it and now it's just perfect, so much better! :) Thanks!

    The 3rd thing, by switching off: I made two photos and attach them, these are what I can see now. First: "Start menu" I click on "Switch off", then a window appears, where I have to choose from "switch off" or "log off" or "restart PC" or "saver mode". Before the virus attacked the PC, it wasn't like this, but a window with 3 small images symbolizing these different buttons, not written by letters. I hope I could understand it better now. I tried to change the setting to "Start menu" from "Classic start menu" but it didn't make a difference.

    And there is one more thing which changed since the virus. Before when I put in a CD then there was a pop up window, and asked what I wanted to do, to open the folders or print the files, etc. Now I have to go to "Own computer" and click on "E:" to open the CD, even if it's a program installation. But it is not a big problem, I just told it to say that it also changed since the malware.

    Thanks a lot!

    Aniko
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.


    Make sure all accounts are password protected too!!!


    See if this helps: http://billjr.spaces.live.com/blog/cns!28CBD6442F406227!808.entry?wa=wsignin1.0

    In addition you could also check out item number 267 in the below link which is a fix for this:
    http://www.kellys-korner-xp.com/xp_tweaks.htm

    You more than likely lost the startup process that was doing this. It probably came installed on your PC that way. I actually delete that junk because it never work properly anyway. When you tell it to do nothing and always do the same, it always wants to do something.
     
  9. Ancsi0909

    Ancsi0909 Private E-2

    I have the feeling, something is still not perfect here...
    I entered cmd, it opened a window, said C:\Documents and Settings\Owner>
    I entered cd\MGtools . It changed to C:\MGTools>
    I entered GetRunKey (enter)
    Message: "The system doesn't recognize the given name (GetRunKey) as an inner or outer command, runable program or packagefile"
    (this is probably a bad translation, but I don't know these PC phrases...)

    I entered ShowNew and get the same message, with the name ShowNew in the brackets. So it showed C:\MGTools> again, and I closed the window.

    I'll try to follow the other things about the switching off procedure. Thanks!
    Aniko
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like your PC may have lost some windows file associations or more. Try the same instructions as last time but instead of using GetRunKey and ShowNew, use GetRunKey.bat and ShowNew.bat

    Now what happens?
     
  11. Ancsi0909

    Ancsi0909 Private E-2

    Absolutely the same. I get the same error messages twice, that the system doesn't recognize these names (names with bat extension)
    I lost some windows file associations? Couldn't there be a connection with that I downloaded Windows Recovery Console when I cleared the PC? By switching on the PC, after the image Pentium 4, the next window shows I can choose between normal mode or the recovery console mode, but if I don't adjust anything, it stays on the "normal mode".
    Or should I uninstall those programs that I downloaded by the procedure, like CCleaner, Malwarebytes AM, AntySpyware or ComboFix? I don't know how to make the recovery console disappear though.
    Or shall I just take the PC to a service and ask them to reinstall the whole system?

    Thanks!
    Aniko
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure I follow what you are trying to say here but installing the Recover Console has nothing to do with losing file associations and I'm not even 100% sure that is exactly what your problem is.

    You could try running the Batch File Association Fix on the below page and if you get it to run then see if you can run GetRunKey.bat and ShowNew.bat

    http://www.dougknox.com/xp/file_assoc.htm

    You don't need to remove the Recovery Console. It is a good idea to have it available like this especially if you do not have a bootable Windows CD. For some malware problems and even Windows problems, it could be a life saver.

    You may have to reinstall as you may have a lot of problems and they may not be all due to malware. It is possible that many of your Windows files have been removed or infected.
     
  13. Ancsi0909

    Ancsi0909 Private E-2

    I clicked on the batch fixing link, saved it, I opened the zip file, then double clicked on the reg file. It asked: "Are you sure you want to add this information to the system describing database?" I click "yes", and it says "The (batch file reg) information was successfully added to the database."
    But even then, Run - cmd - MGTools - GetRunkey.bat and ShowNew.bat, it says that the system doesn't recognize these names. :-(

    As for the bootable Windows CD, I'm not sure if I have one or not, because I did buy the notebook with an official Windows on it, and got some CDs, Medion HomeCinema, Medion Nero Burning, and there is a Medion Product Recovery CD-ROM Windows XP Home Edition SP1. But I never used it yet, so I'm not sure whether it's all I need to reboot.
    As far as I know, you can reboot it in a way, that all your data (images, documents, etc.) stay on the PC, the other way would delete everything and give you a blank new computer. I don't know which way this CD, which I have, works? But I don't want to loose my data...
    What do you suggest?
    Thanks!
    Aniko
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It really appears that your problems are within your Windows Operating System. You may need to reinstall. However have you tried using System Restore to go back to a point before your problem began?

    A product recovery CD may return the PC to the state in which it was shipped.

    I suggest you either speak to the manufacturer of the PC or post in the Software Forum. Your other choice it to try loading that CD and see if it contains any documentation; however this is not something we can help you with in the Malware Forum.
     
  15. Ancsi0909

    Ancsi0909 Private E-2

    I brought my PC to a service and let it reinstall again, so now all is new and many programs have been deleted. I just started to go through the Malware read & run capture again, I download all those programs again and will send you the logs I get this time. I hope it runs completely! I will send you the files this evening or tomorrow, depending how long it'll take to scan the system with all new programs.

    Aniko
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. Ancsi0909

    Ancsi0909 Private E-2

    Hello! It was reinstalled, but the guy saved my old programs, drivers, files and after the installation he "put" them back to the D: driver.
    But I won't run the procedure if you think it's not necessary any more. Before getting your last reply, I downloaded and run CCleaner, SUPERAntySpyware, Spybot S&D and Malwarebytes A-M, and I scanned the PC with all, but none of them found any malware (except some Cookies first).
    Thanks for the link about how to protect myself, I read it and kept one of the necessary programs.
    One last thing: I understand that you suggest Mozilla FireFox instead of Internet Explorer, but I am used to the Explorer, so I'd prefer to keep this. Before the last reinstallation I had Explorer 7, but I got back the PC with Explorer Version 6.0. Then the next automatic Microsoft update wanted to DL the Explorer 7, but it didn't manage. Since then I tried to download it manually, and after installing it I always get an error message, that it couldn't be installed, and I should restart the computer to delete the changes. I don't understand why I can't get it run.
    I think it's not a malware problem, but can you tell me where to turn to with this problem?
    Thanks a lot for everything! :)

    Aniko
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should post a detailed description of your problem in the Software Forum.

    Be careful with your choice of words. Explorer does not mean Internet Explorer to us. Explorer is Windows Explorer which is your Windows Shell which gives you a Desktop and allows you to navigate the file system. Internet Explorer (or IE for short) is your browser. So just say IE ( like IE6 or IE7 ) and everyone will be clear on what you are referring too. ;)
     
  19. Ancsi0909

    Ancsi0909 Private E-2

    All right, I'll do this, and thanks for telling me about the Internet - Explorer difference :)
    Thanks!
    Aniko
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds