Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Dec 1st, 2008, 7:54pm
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   (matches PWSteal.LdPinch.100)
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: (matches PWSteal.LdPinch.100)  (Read 216 times)
harley-ann
Newbie
*





   


Gender: female
Posts: 1
(matches PWSteal.LdPinch.100)
« on: Dec 28th, 2006, 4:45am »
Quote Quote  Modify Modify

Hello all the smart people. I have run TH and it the following entry
 
Registry value exists: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows  LSASS Service (matches PWSteal.LdPinch.100)  
 
I have cleaned it but, it returns when I run a scan. How do I get rid of it?  
 
Also is this something to worry about?
 
 
ScriptChecker: Cannot open file "C:\Documents and Settings\my name\Local Settings\Temporary Internet Files\Content.IE5\GD8TAZS5\1139255660[1].htm". The process cannot access the file because it is being used by another process
 
The above mentioned I have two entries for.  
 
 
Thanks in advance for any and all help. HarleyAnn
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5815
Re: (matches PWSteal.LdPinch.100)
« Reply #1 on: Dec 28th, 2006, 5:37am »
Quote Quote  Modify Modify

Welcome to the forum harley-ann  Wink
 
Sorry that you are showing an infection with the LSASS service.  Let's try the following initial steps to attempt to correct this problem.  
 
1.  Open TH scanner:
 
-  Run LiveUpdate to ensure that you have the very latest rulesets.
 
-  Click on the Options icon on the left side of the TH scanner window.  This will open the scanning options.  Checkmark all the options in the list.  
 
-  Close TH scanner.  
 
2.  Install CCleaner to clean up junk files from your system.
 
-  Please go to the link below and download/install freebie program CCleaner.  This program will clean out all the temporary and junk files that are laying around on your system.  Let it install in its default directory on hard drive when you install it.
 
http://www.ccleaner.com
 
3.  Install freebie program HiJackthis.  Please follow closely the instructions provided in the link below.  
 
http://www.misec.net/forum/board/FAQ/1163329424
 
4.  Reboot your computer into SAFE MODE.  The link below provides info on how to boot into SAFE MODE if you do not know how.  
 
http://www.misec.net/forum/board/FAQ/1144043085
 
5.  Run the Cleaner component of CCleaner and let it clean out your temporary files.  Do not run the Issues component because this is a registry cleaner.  
 
6.  Run a FULL scan with TrojanHunter and let it clean what it detects.  Save a scan/cleaning log so that you can post it back it here when boot back into normal mode.  To save a log file, just click on File in the top menu bar and select the option to save the log.  
 
7.  Reboot your computer back into Normal mode.  
 
8.  Run a Hijackthis scan and post the scan log back here.
 
9.  Post the scan log from TrojanHunter also.  
 
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register