cannot remove malware lsass.exe file from my pc

January 30, 2012 at 01:46:38
Specs: Windows XP, 512
cannot remove lsass.exe file from my pc

See More: cannot remove malware lsass.exe file from my pc

Report •


#1
January 30, 2012 at 02:11:22
Hi vikneshxl
"lsass.exe" is the Local Security Authentication Server. It verifies the validity of user logons to your PC or server. Lsass generates the process responsible for authenticating users for the Winlogon service.
What makes you think it's malware?
Download and run Malwarebytes from this link;
http://www.malwarebytes.org/product...
Update it and run a quick scan.

Report •

#2
January 31, 2012 at 14:13:27
Be a bit careful.

LSASS.EXE is a genuine Windows file and should not be removed, see description in response #1.

ISASS.EXE is a Virus. It is so named to make you think it is a genuine file - see below.

When they are in lower case they look identical. See where the file appears in the alphabetical list of files and look in Properties for info. While you are there you could Copy the name from the General tab (Ctrl+C) then paste it into NotePad. The difference between "L" and "I" is obvious there because of the font used.

No harm running MalwareBytes, whatever your situation.

EDIT:
Just found this
http://www.softwarepatch.com/tips/i...

Always pop back and let us know the outcome - thanks


Report •

#3
January 31, 2012 at 16:40:09
It was written as Lsass.exe in the title and lsass.exe in the post. So thought it wise just to run Malwarebytes to be sure.
As Derek points out, a lot of malware now days is using our lazy reading skills to trick us into loading malware on to our pc's.

Report •

Related Solutions

#4
February 3, 2012 at 04:53:16
lsass.exe is either Windows process or might be a malware. So, you need to check where it loads from. It should be from C:\Windows\System32.

There are different files with the same name:
•"MicrosoftSourceSafe" definitely not required. Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process, which should not appear in Msconfig/Startup!
•"lsass" definitely not required. Added by the RATSOU.B TROJAN! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
•"Microsoft UPDATER32" definitely not required. Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
•"System Handler" definitely not required. Added by the NIMOS WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!
•"Traybar" definitely not required. Added by the MYDOOM.L WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!

What is lsass.exe?


Report •


Ask Question