Computing.Net > Forums > Security and Virus > Virus help

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Virus help

Reply to Message Icon

Name: _Dallas_
Date: August 18, 2004 at 07:17:01 Pacific
OS: Windows XP
CPU/Ram: 800 / 512
Comment:

Ok folks, this one has me baffled. I recently updgraded a PC (w/broadband) from 98 to XP, after running NAV. After manually installing SP1, I went online to DL and install the remaining service packs. Almost immediately it was infected with a virus and initiated a lsass.exe shutdown. Suspecting sasser or blaster I ran fixes from symantec and installed the recommended patches (in safe mode). Nothing was detected, but the shutdown sequence was eliminated. However, NAV is disabled, as is taskmgr, any security updates and regedit. I then ran almost every online scanner and Panda caught and killed 2 small.ak trojans, but still no reported viruses. I then was able to install Panda and Armor firewall. Panda caught an attempted re-install of the small.ak trojan. Armor started and blocked attempts outbound on port 135. In fact there were so many that it locked up the software so i could not shut it down.

These factors indicated to me it is most likely blaster, but nothing finds it or any other virus. HELP!

Sorry if there is not enough information or even too much information is included. Any assistance is greatly appreciated in advance.



Sponsored Link
Ads by Google

Response Number 1
Name: rmq924
Date: August 18, 2004 at 08:30:39 Pacific
Reply:

I had this issue at work, commonly referred to as "Udectable Sasser". I found nothing to identify it. I even tried (as fruitless as it was) to see if I could overwrite the lsass.exe file. What I did find though, is that whatever it is, is most likely specific to XP. I re-installed 2000 Professional on the infected machine and to this day have not seen the problem again.

Another tip I may give, is to keep your computer off the network untill you have already installed SP1 (or 2), Antivirus, and I suggest Spybot. Simply download the exacutable from Microsoft to your computer before you do a format and install of Windows. You can put the service pack on CD, and install it from CD when you're done. Next drop in your AV software, and then Spybot (blocks registry changes). Once that is said and done, I'd then try to single it out from your other PC's and update your Antivirus, spyware, and any security patches from Microsoft.


0

Response Number 2
Name: JPQ
Date: August 18, 2004 at 09:01:53 Pacific
Reply:
0

Response Number 3
Name: _Dallas_
Date: August 18, 2004 at 09:31:04 Pacific
Reply:

Qtip - The last thing I want to do is a reformat, however I will follow your advice on the re-install with the patches installed off-line if I go that route. I have probably spent 12 hours so far in research and removal techniques, and this is now more of a pride issue *snicker*, so any other suggestions for forum participants will be greatly appreciated.

JPQ - as I sais I tried almost all the detection tools including panda, norton, and stinger.

Does anyone know the link to the yet 'unreleased to the general public' SP2?

Thanks for the help and thanks in advance for any more that people are willing to submit :)


0

Response Number 4
Name: Wombat
Date: August 18, 2004 at 13:51:16 Pacific
Reply:

Here you go...

http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en

Iligitimi non carborundum est


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Virus help

Trojan.ByteVerify Virus Help www.computing.net/answers/security/trojanbyteverify-virus-help/6857.html

windows antivirus pro virus help www.computing.net/answers/security/windows-antivirus-pro-virus-help/27101.html

Virus! Help! Norton's not working.. www.computing.net/answers/security/virus-help-nortons-not-working/19332.html