penfold Posted January 28, 2010 Posted January 28, 2010 OK, this has been bugging me all morning, and before I do a wipe and reinstall windows I am wondering if anyone can offer some suggestions for getting rid of this annoying virus/malware problem. I've got a new machine which is locking me out of the task manager and regedit (error msg - restricted by admin) and I have narrowed it down to lsass.exe which I have managed to get rid of it in safemode with malwarebytes. The problem I have is although I can then get into the registry and task manager, as soon as I try to log in normally the files have recreated themselves and the problem persists. What I want to know is where is this file being recreated from? I have also found reg entries for dido.exe and akaro.exo which seem to be linked, but I cant find any files which when deleted remove lsass permanently. Any ideas?
Jamo Posted January 28, 2010 Posted January 28, 2010 You mean the Microsoft Local Security Authentication Server service? Be wary as there is a trojan which has a process called Isass (the capial I in the default windows font looks the same)
thomass Posted January 28, 2010 Posted January 28, 2010 (edited) It may be the W32.Sasser worm, see here for removal instructionsW32.Sasser.Worm Removal - Removing Help | Symantec penfold - have you tried SuperAntispyware to remove the trojan Edited January 28, 2010 by thomass
penfold Posted January 28, 2010 Author Posted January 28, 2010 (edited) You mean the Microsoft Local Security Authentication Server service? Be wary as there is a trojan which has a process called Isass (the capial I in the default windows font looks the same) Nope, not unless MS creates a reg key which blocks you frmo accessing the registry and Taskmanager @thomass - I'll give that a go. Seems it might be easy for a rebuild but I wanted to avoid that. Edited January 28, 2010 by penfold
BJC Posted January 28, 2010 Posted January 28, 2010 did you disable system restore before running malwarebytes?
penfold Posted January 28, 2010 Author Posted January 28, 2010 did you disable system restore before running malwarebytes? Yup, although I forgot at first.
penfold Posted January 28, 2010 Author Posted January 28, 2010 Got it sorted now. The only thing I did differently was to also run an AVG removal software as the lsass.exe was showing as associated with AVG(even though AVG has never been installed) and I remember seeing some spyware like this before. Thanks for those with the suggestions anyway.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now