Re: Isass.exe application error at log on in windows xp



From: <ming.photographer@xxxxxxxxx>


|
| I've got problems with Isass.exe. It's a nasty virus that won't budge.
| It all started with my AV (Sophos) found a file called DDCCB.DLL.
|
| I've tried deleting it manually, CMD, in Safe Mode, everything. I even
| used Processor Explorer from Microsoft to find out what was running it
| and it turns out to be Isass.exe. When you try and kill it, it shuts
| down the whole machine.
|
| Sophos managed to quarantine the ddccb.dll file but isass.exe is still
| running. I've submitted a copy to them and just waiting to hear back
| from them.
|
| I'm stumped at how to remove isass.exe. I'm not a geek and I haven't
| got time to spend hours downloading AV, running scans, reading
| reports. If anyone knows a simpler way of being able to remove this
| pest, please, please let us know!!!

As was stated before is this ISASS.EXE or LSASS.EXE ?

DDCCB.DLL sounds like a Vundo Trojan. Is it C:\windows\system32\ddccb.dll ?



3 phase answer...

Perform Part 1, Part 2 and Part 3

It is suggested that you execute each tool in Normal Mode then in Safe Mode.


If you are using any version of Sun Java that is prior to JRE Version 6.0,
then you are strongly urged to remove any/all versions.
There are numerous vulnerabilities in them and they are actively being exploited.

It is highly suggested that you update to the latest version which is Sun Java JRE/JSE
Version 6.0 update 4 (jre 6u4)

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.

Such as...
C:\Program Files\Java\jre1.6.0_04

http://java.sun.com/javase/downloads/index.jsp
http://www.java.com/en/download/manual.jsp

FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102622-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102732-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1



Part 1
------------
Download Adware-Virtumundo Removal Tool --
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe


Part 2
------------
Download Atribune's VUNDOFIX.EXE
http://www.atribune.org/ccount/click.php?id=4

Save VUNDOFIX.EXE to "C:\" ( C:\VUNDOFIX.EXE ) and execute it from there.

Part 3
------------
Malwarebytes Anti-Malware 1.05
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

* * * Please report back your results * * *



--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


.



Relevant Pages

  • Re: Cant update AdAWare,SpyBot,AVG
    ... I disabled the Windows Firewall, ... When I went to Safe Mode, ... Sophos, and I had to D/L again in Normal Mode. ... > FireWall to allow it to download the needed AV vendor related files. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Problems in restoring the laptop after installing sp2
    ... The only folder under that folder should be the latest version... ... install and update the following software... ... I suggest scanning the system in Safe Mode. ... FireWall to allow it to download the needed AV vendor related files. ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: ie,...again
    ... How to take ownership of a file or folder in Windows XP ... In XP Home you have to boot in safe mode to see the security tab. ... other computer called HOLD, download the programs to ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Suspected virus/high jack
    ... (e.g., "c:\New Folder") ... Download sysclean.com and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode ...
    (microsoft.public.security.virus)
  • Re: virus problem
    ... He was the one who gave me sophos (think he paid them an amount ... >> prompts me to this virus but cannot delete it. ... Create a new folder on your Desktop or the C: ... Restart your computer in Safe Mode. ...
    (microsoft.public.windowsxp.security_admin)