Getting rid of Lsas.Blaster.Keyloger win 7

Closed
beck - Mar 10, 2010 at 08:37 PM
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Apr 10, 2010 at 04:49 AM
Hello,
I have tried the task manager and it comes up and then disappears. how do i get it to stay open long enough to get rid of this virus?
Related:

5 responses

Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,163
Mar 11, 2010 at 05:51 AM
Hello,

First, see if your have the latest Windows security updates and come back to us.

Best regards
1
Thank you for all your help, when i was in the proccess i didnt see anything that had alot of numbers, but did find something that ended with las so i ended it and it seem to do the trick.
0
closeup22 Posts 8923 Registration date Friday May 15, 2009 Status Member Last seen October 7, 2010 2,099
Mar 11, 2010 at 08:18 AM
Hi there,

For removal please refer to Faq and get instructions:

http://ccm.net/faq/4148-victim-of-scam-lsas-blaster-keylogger

Thanks
0
Yes everything is brand new. We have only had the computer for a month.
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,163
Mar 12, 2010 at 06:35 AM
Hello Becky,

The reason why I asked is because Windows published security updates and patches to prevent Blaster infections.

Anyhow, to remove this virus, you can follow Closeup22's instructions, which are:

•To remove Lsas.Blaster.Keylogger manually:
•Press CTRL+ALT+DEL to open Task Manager

Kill Spyware Processes:

692527612.exe, 1313928688.exe, 1806188250.exe•

Delete these Files and Folders:

C:\Documents and Settings\All Users\Application Data\1929146152\1313928688.exe
C:\Documents and Settings\All Users\Application Data\1372029626\1806188250.exe
C:\Documents and Settings\All Users\Application Data\870894309\692527612.exe

Restart your machine.

If you need further assistance, please come back
0
now the problem is i try the task manager thing, and everytime i try to bring it up it dissapears before i can do anything. any idea how to keep it on top so i have time to use it? I tried holding down ctrl like it was a pop up thing but it still dissapears.
0

Didn't find the answer you are looking for?

Ask a question
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,163
Mar 13, 2010 at 10:49 AM
Hello Becky,

The virus is probably preventing you to access the Taks Manager, just to protect itself. Let outwit it!

Download Process Explorer to your desktop:

https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer

In the link below there is some instructions as how to use it.

Before you launch Process Explorer, again to outwit the little rascal beast, click right on the Icon and rename Process Explorer Explorer.exe

Run it and remove the process.

Let me know how it worked for you.

Best regards
0
Renamed a couple of times and unable to unwit it. Any more suggestions?
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,163
Apr 4, 2010 at 04:58 AM
To kill the processes:

Download to your desktop and RKill:

https://download.bleepingcomputer.com/grinler/rkill.com

Run RKill

Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step. If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning .

Good luck
0
im haviing the same problem.. windows 7 unable to get rid of this virus
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,163
Apr 10, 2010 at 04:49 AM
Hello,
Essentially the processes and files to be deleted would be the same.
What have you tried to get rid of it?
0