User Name Password Register
DaniWeb IT Discussion Community
All
What is DaniWeb IT Discussion Community?
You're currently browsing the Viruses, Spyware and other Nasties section within the Tech Talk category of DaniWeb, a massive community of 403,490 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 4,205 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Viruses, Spyware and other Nasties advertiser: Programming Forums
Views: 4384 | Replies: 17
Reply
Join Date: Feb 2004
Location: Oztralya
Posts: 7,712
Reputation: crunchie is a jewel in the rough crunchie is a jewel in the rough crunchie is a jewel in the rough 
Rep Power: 22
Solved Threads: 420
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: can't stay on line

  #11  
Jun 4th, 2004
lsass.exe is a legitimate Windows file. The file dropped by sasser is lsasss.exe
From answers that work:
LSASS is the Local Security Authentication Server. It verifies the validity of user logons to your PC/Server (in technical jargon : it generates the process that is responsible for authenticating users for the Winlogon service).

Recommendation :
An integral part of the operating system, leave alone provided that its full path as shown in The Ultimate Troubleshooter is either C:\WinNT\System32\LSASS.exe (Windows 2000) or C:\Windows\System32\LSASS.exe (Windows XP/2003). If the path is anything else then you may have a virus
Proud member of ASAP (Alliance of Security analysis Professionals).
Opera How you got infected AVAST anti-virus Comodo Firewall Spywareblaster

Please do not PM me for help. Instead, post in the public forum where others may benefit.
Reply With Quote  
Join Date: Aug 2003
Posts: 7,238
Reputation: caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light 
Rep Power: 24
Solved Threads: 311
Colleague
caperjack's Avatar
caperjack caperjack is offline Offline
Posting Sage

Re: can't stay on line

  #12  
Jun 4th, 2004
This looks funny ,note the 2.exe's
O4 - HKLM\..\Run: [rundll32.exe] C:\WINDOWS\System32\rundll32.exe.exe
Boo!!!!! Sarcastic Jack
Reply With Quote  
Join Date: Feb 2004
Location: Oztralya
Posts: 7,712
Reputation: crunchie is a jewel in the rough crunchie is a jewel in the rough crunchie is a jewel in the rough 
Rep Power: 22
Solved Threads: 420
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: can't stay on line

  #13  
Jun 4th, 2004
I think that DMR picked that up too. I think we need a fresh log to view.
Proud member of ASAP (Alliance of Security analysis Professionals).
Opera How you got infected AVAST anti-virus Comodo Firewall Spywareblaster

Please do not PM me for help. Instead, post in the public forum where others may benefit.
Reply With Quote  
Join Date: Aug 2003
Posts: 7,238
Reputation: caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light 
Rep Power: 24
Solved Threads: 311
Colleague
caperjack's Avatar
caperjack caperjack is offline Offline
Posting Sage

Re: can't stay on line

  #14  
Jun 4th, 2004
Originally Posted by crunchie
I think that DMR picked that up too. I think we need a fresh log to view.
you are right ,i need to stop speed reading.
Boo!!!!! Sarcastic Jack
Reply With Quote  
Join Date: Dec 2003
Location: Marin County, CA
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Rep Power: 18
Solved Threads: 340
Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: can't stay on line

  #15  
Jun 4th, 2004
Yeah, speed kills man. Remember- friends don't let friends speed and post.

:mrgreen:
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote  
Join Date: Mar 2004
Posts: 13
Reputation: moxin is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
moxin moxin is offline Offline
Newbie Poster

Re: can't stay on line

  #16  
Jun 5th, 2004
Logfile of HijackThis v1.97.7
Scan saved at 1:33:14 AM, on 6/5/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.aliant.net
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...AB?38004.94875
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by15fd.bay15.hotmail.msn.com/...x/HMAtchmt.ocx
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A25B4830-2FC7-47F1-9152-D66BEFBB37E7}: NameServer = 142.177.1.2 142.177.129.11

I know its not the sasser worm and I have norton
Reply With Quote  
Join Date: Aug 2003
Posts: 7,238
Reputation: caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light caperjack is a glorious beacon of light 
Rep Power: 24
Solved Threads: 311
Colleague
caperjack's Avatar
caperjack caperjack is offline Offline
Posting Sage

Re: can't stay on line

  #17  
Jun 5th, 2004
You need to contact you Internet service provider .There is nothing wrong with you log ,so it may be hardware/software ,Or maybe the Aliant stirke!!
Bad modem maybe or bad configuration somewhere .
Boo!!!!! Sarcastic Jack
Reply With Quote  
Join Date: Mar 2004
Posts: 13
Reputation: moxin is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
moxin moxin is offline Offline
Newbie Poster

Re: can't stay on line

  #18  
Jun 7th, 2004
Thats what my next step was thx for bringing it up though. Now I feel like thats the problem thx a bunch guys!!!
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

DaniWeb Viruses, Spyware and other Nasties Marketplace
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

Thread Tools Display Modes

Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum

All times are GMT -4. The time now is 12:15 pm.
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC