FLYN,
Hi and welcome to the Daniweb forums :).
===============
Please go to Jotti's and have this file scanned. Post the results back here.
C:\WINNT\lsass.exe
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Regarding redir.exe. I did a google and the results are inconclusive. You would have to get the file scanned, or go to it's properties and find out when it was installed and who the manufacturer is.
C:\WINNT\lsass.exe will need to be deleted. Make note that there is a legitimate file of the same name in the system32 folder :).
Run hijackthis and hit the Open the Misc Tools Section and then the Open Uninstall Manager.
Run HiJackThis then:
1. Click "Open the Misc Tools Section"
2. Click "Open Process manager"
-
Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:
C:\WINNT\lsass.exe
Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain.
Now manually delete the file. Post another log when you have rebooted.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Download the Pocket KillBox
Unzip the file to your desktop.
Run Pocket Killbox and paste the full file path of the below file in the box and click on Standard File Kill and End Explorer Shell While Killing File. Click on the button with the red circle and an X in the middle after you the file.
C:\WINNT\lsass.exe
Reboot afterwards if the file is successfully deleted.
If the file is not deleted, do not reboot yet. Run Pocket Killbox again and paste the full file path in the box and click on Delete on Reboot. Next click on the button with the red circle and an X in the middle. You will get a message saying "File with be deleted on next reboot, Process and Reboot now?" Click "Yes" to reboot.
That should do it.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
Clear out your Temporary internet files and other temp files.
Go to Start > Settings > Control Panel >Internet Options.
Under the General tab click the Delete temporary internet files,
delete all Offline content as well. Clear out Cookies.
Also, go to Start > Find/search > Files or folders > in the named box, type: *.tmp and choose Edit > select all -> File > delete.
Empty/delete the entire contents of the C:\Windows\temp folder and C:\temp folder, if you have one. (Contents but not the folder itself.)
C:\Documents and Settings\username\Local Settings\Temp\
In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.
Empty the Recycle Bin.
Definitely get a firewall :)
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
When I went to C:\Documents and Settings\username\Local Settings. I found a temp folder and temporary internet files folder. Should I delete both?
Do not delete the actual folders, just the contents. All temp files can safely be deleted, although some may be in use and cannot be deleted immediately.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
how do i prevent any more infestations on the pc if i go back to kazaa.
That's like asking how you can go back to a poker table but not lose money this time.
There are measures that you can take to minimize the chances that malicious programs will be downloaded and/or installed on your system, as well as measures you can take to minimize damage should those programs actually manage to install themselves. However, none of the methods are foolproof or comprehensive, and the makers of the malicious programs are constantly finding new security holes to exploit and new ways to bypass current protections.
P2P Filesharing networks are some of the most notorious distribution vehicles for malware, and it's getting much harder to find a P2P network that is known to be "clean" of such nasties. Throw in the fact that a large amount of the content shared on P2P networks is copyrighted material, and you've got some pretty good reasons to give filesharing a miss entirely.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370