J
Julian Hales
UPDATE
I tried to remove the Lsass virus off xp pro by doing a couple of things one
below in safe mode was below with trend sysclean, safe mode, restore off
etc, but get -error 94. until it got to the error it said no virus found.
I also went to grisoft and downloaded the tool for removal it said of
Sasser, about 157 virus checkd, just before the 60 sec countdown box appeard
once online, after reboot again in safemode etc ran it and said NO virus
found, also ran avg av normal with lated upsdate but said no av found.
My boss is called me a liar, even tho he saw it restart, he saw LSASS in tas
monitor etc etc.
Guys im stumped.
As soon as the machines online the windw pops up etc for reboot, but not if
not connected online.
help!
1) Download the following two items...
Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp
Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp
Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
Download SYSCLEAN.COM and place it in that directory.
Dowload the signature files (pattern files) by obtaining the ZIP file.
For example; lpt216.zip
Extract the contents of the ZIP file and place the contents in the same
directory as
SYSCLEAN.COM.
2) Disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
3) Reboot your PC into Safe Mode
4) Using the Trend Sysclean utility, perform a Full Scan of your
platform and
clean/delete any infectors found
5) Restart your PC and perform a "final" Full Scan of your platform
6) Re-enable System Restore and re-apply any System Restore preferences,
(e.g. HD space to use suggested 400 ~ 600MB),
7) Reboot your PC.
8) Create a new Restore point
9) Please report back your results
Dave
| Hi
|
| Bit of a story, hope your sitting comfortably.
|
| Boss bought a laptop, a 350mhz Dell sort of ok machine, came with XP pro.
|
| The type of guy who doesnt know, want to know and never listens when you
| tell him!
|
| Had no modem so he bought a usb, told him not to connect it until he put
| kerio on, anyway i ended up doing that......couldnt install the modem, so
i
| did that, and then explained how a firewall works.
|
| Hes over my shoulder, im telling him to shut up and let me concentrate,
but
| whats he do, whinge non stop, so when kerio pops up i hit allow rather
then
| deny, and your guessed it, infected with sasser!
|
| Brought it home, the pc not the boss, went to MS and came accross a couple
| of downloads, so downloaded them, says no sasser at all.
|
| Downloaded and installed AVG, comes up clean
|
| same again with Norton 2005 trail, which i tell people not to use, and it
| made the pc crawl along so slow my beard grew faster, again said no virus.
| (not sure if sasser stopped av installation)
|
| Online googling showed what to look for in task manager, and still reboots
| etc.
|
| Can anyone help? av nothing says its on, i know its on, pc knows its on
as
| it reboots but the others dont.
|
| I know no av can be made until a virus is out, and i cant see it being
such
| a new variant nothing picks it up.
|
| thanks.
|
|
I tried to remove the Lsass virus off xp pro by doing a couple of things one
below in safe mode was below with trend sysclean, safe mode, restore off
etc, but get -error 94. until it got to the error it said no virus found.
I also went to grisoft and downloaded the tool for removal it said of
Sasser, about 157 virus checkd, just before the 60 sec countdown box appeard
once online, after reboot again in safemode etc ran it and said NO virus
found, also ran avg av normal with lated upsdate but said no av found.
My boss is called me a liar, even tho he saw it restart, he saw LSASS in tas
monitor etc etc.
Guys im stumped.
As soon as the machines online the windw pops up etc for reboot, but not if
not connected online.
help!
1) Download the following two items...
Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp
Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp
Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
Download SYSCLEAN.COM and place it in that directory.
Dowload the signature files (pattern files) by obtaining the ZIP file.
For example; lpt216.zip
Extract the contents of the ZIP file and place the contents in the same
directory as
SYSCLEAN.COM.
2) Disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
3) Reboot your PC into Safe Mode
4) Using the Trend Sysclean utility, perform a Full Scan of your
platform and
clean/delete any infectors found
5) Restart your PC and perform a "final" Full Scan of your platform
6) Re-enable System Restore and re-apply any System Restore preferences,
(e.g. HD space to use suggested 400 ~ 600MB),
7) Reboot your PC.
8) Create a new Restore point
9) Please report back your results
Dave
| Hi
|
| Bit of a story, hope your sitting comfortably.
|
| Boss bought a laptop, a 350mhz Dell sort of ok machine, came with XP pro.
|
| The type of guy who doesnt know, want to know and never listens when you
| tell him!
|
| Had no modem so he bought a usb, told him not to connect it until he put
| kerio on, anyway i ended up doing that......couldnt install the modem, so
i
| did that, and then explained how a firewall works.
|
| Hes over my shoulder, im telling him to shut up and let me concentrate,
but
| whats he do, whinge non stop, so when kerio pops up i hit allow rather
then
| deny, and your guessed it, infected with sasser!
|
| Brought it home, the pc not the boss, went to MS and came accross a couple
| of downloads, so downloaded them, says no sasser at all.
|
| Downloaded and installed AVG, comes up clean
|
| same again with Norton 2005 trail, which i tell people not to use, and it
| made the pc crawl along so slow my beard grew faster, again said no virus.
| (not sure if sasser stopped av installation)
|
| Online googling showed what to look for in task manager, and still reboots
| etc.
|
| Can anyone help? av nothing says its on, i know its on, pc knows its on
as
| it reboots but the others dont.
|
| I know no av can be made until a virus is out, and i cant see it being
such
| a new variant nothing picks it up.
|
| thanks.
|
|