W32.Sasser

Discussion in 'adware, spyware & hijack cleaning' started by LukaszJ, May 9, 2004.

Thread Status:
Not open for further replies.
  1. LukaszJ

    LukaszJ Registered Member

    W32.Sasser HELP

    I run the symantec fix tool but im 100% sure it didnt delete all of it and also installed the microsoft patch.

    Heres my log:
    Help :(
     
    Last edited: May 9, 2004
  2. snowbound

    snowbound Retired Moderator

    Hi LukaszJ :)

    I moved your thread to the hijack cleaning forums for better attention. ;)



    snowbound
     
  3. LukaszJ

    LukaszJ Registered Member

    Thank you. Still need help though :(.
     
  4. snowbound

    snowbound Retired Moderator

    I understand. ;)

    One of the experts will be along to help u. :)


    snowbound
     
  5. cybertech

    cybertech Spyware Fighter

  6. LukaszJ

    LukaszJ Registered Member

    Here it is:

     
  7. cybertech

    cybertech Spyware Fighter

    Great! Please go do the M$ fix and then in control panel, add/remove programs remove new.net

    Reboot and post another log.
     
  8. LukaszJ

    LukaszJ Registered Member

    I also scanned all with AVirus and it got like 40 sasser infected files... WTF!

    Heres the log:
     
  9. LukaszJ

    LukaszJ Registered Member

    O4 - HKLM\..\Run: [lsasss.exe] C:\WINDOWS\lsasss.exe

    There is no file like this on the HD or in the processes, wth o_O
     
  10. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    The file could be hidden.

    Please download TheKillbox from here: http://download.broadbandmedic.com/VbStuff/KillBox.zip

    Unzip the files to a folder, then double-click on Killbox.exe to run it. In the "Paste Full Path of File to Delete" box, copy and paste the following:

    C:\WINDOWS\lsasss.exe

    Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". On the next screen, click on the File menu and choose "Add File". The filenameand path should show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to reboot, do so.

    Regards,

    Pieter
     
  11. LukaszJ

    LukaszJ Registered Member

    Done.

     
  12. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Hi LukaszJ,

    Check the following items in HijackThis.
    Close all windows except HijackThis and click Fix checked:

    O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL

    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

    O4 - HKLM\..\Run: [msbb] c:\program files\n-case\msbb.exe
    O4 - HKLM\..\Run: [vuryf] C:\WINDOWS\vuryf.exe
    O4 - HKLM\..\Run: [lsasss.exe] C:\WINDOWS\lsasss.exe

    Then reboot into safe mode and delete:
    c:\program files\n-case <= entire folder
    C:\WINDOWS\vuryf.exe
    C:\Program Files\MyWay <= entire folder

    Then run HijackThis again and post a new log.

    Regards,

    Pieter
     
  13. LukaszJ

    LukaszJ Registered Member

    Here it is:
     
  14. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

  15. LukaszJ

    LukaszJ Registered Member

    No such folder, sorry.
     
  16. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Ah well. Curiosity.... ;)

    Pieter
     
  17. LukaszJ

    LukaszJ Registered Member

    How was this fodler sopossed to be created ? with the killbox ?
     
  18. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Yes. The Killbox creates a folder if you use the backup option which is checked by default.

    Regards,

    Pieter
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice