Re: Virus?

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 10/06/04


Date: Tue, 5 Oct 2004 20:37:36 -0400

1) Download the following three items...

         Trend Sysclean Package
         http://www.trendmicro.com/download/dcs.asp

         Latest Trend signature files.
         http://www.trendmicro.com/download/pattern.asp

         Adaware SE
         http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download sysclean.com and place it in that directory.
Dowload the signature files (pattern files) by obtaining the ZIP file.
For example; lpt186.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) If you are using WinME or WinXP, disable System Restore
            http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
3) Reboot your PC into Safe Mode
4) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
        platform and clean/delete any infectors/parasites found.
5) Restart your PC and perform a "final" Full Scan of your platform using both the
        Trend Sysclean utility and Adaware
6) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
            System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
7) Reboot your PC.
8) If you are using WinME or WinXP, create a new Restore point
9) Please report back your results

Dave

"kim" <anonymous@discussions.microsoft.com> wrote in message
news:3ca101c4ab3a$c61738c0$a301280a@phx.gbl...
| I rebuilt a system for a staff member last week, XP Pro,
| all win updates (except SP2) Norton corp, all dat files,
| Office 2003 and all updates, ad aware and updates, and
| ran scans for virus and apy/adware. returnd the system
| and it ran fine for a week.
|
| Today the teacher called me back, said she updated new
| windows updates, and the system now reboots with a
| typical sasser message on start up. "The system is
| shutting down,......." gives me 60 seconds countdown and
| the system process is C:\WINDOWS\system32\lsass.exe.
|
| I can not get past this to stop the timeout as the system
| gets to select the log on name to continue (with the
| lsass.exe box in front of it) and there is no name in
| which to choose to continue the log on. I have to power
| off to do anything except reboot when the system times
| out.
|
| I tried safe mode, same thing, I tried safe mode with
| command prompt, and can not get past that log on screen
| with nothing to choose! I was hoping to get to the cmd
| prompt to stop the timeout and then repair the system.
|
| I slaved the HD to another system and ran a sasser fix
| tool, it found nothing.
|
| I am not really wanting to rebuild this system again, it
| is for a special needs teacher and she has tons of
| programs for kids with special handicaps and needs.
| Takes days to get it working.
|
| Any ideas or help greatly appreciated.
|
| Thank you in advance,
| Kim



Relevant Pages

  • Re: 100% CPU Usage
    ... folder probably caused by interference by an AV scan during the Update ... Stop and Disable Automatic Updates, ... Now Reboot Again. ... Go to http://wiki.djlizard.net/Dial-a-fix and download Dial-a-fix ...
    (microsoft.public.windowsupdate)
  • Re: updates and error messages
    ... Clean out the Downloader folder ... If having problems with Windows Defender Definitions Updates, ... I guess this is the reason I can no longer download any Windows ...
    (microsoft.public.windowsupdate)
  • Re: IE6 crashing!
    ... Download Sysclean.com, from Trend Micro, here: ... Create a folder on the hard drive of the other computer called ... > I ran Windows Update and I now have all the current updates, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Incomplete Mail Downloads in OE
    ... I went to Windows update, and after having to install several updates to Update, I successfully downloaded and installed several updates. ... Messages without saving the message to Drafts folder first. ... Have you *hidden* the SP2 download at Windows Updates? ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: "about:blank" home page
    ... THEN REBOOT AND RUN THEM AGAIN TO BE SURE ALL FILES ... > Unzip the Download file in a NEW FOLDER that you can create before you start ... > DO NOT install in your Desktop folder. ... > Download Registrar Lite 2.0, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)