PDA

View Full Version : A possible virus…


Topher
02-May-2004, 12:03 AM
A couple of minuets after logging on to the Internet I get an Error Report window appears, saying ‘LSA Shell (Export Version) has encountered a problem.....’ A System Shutdown window then says ‘LSA Shell (Export Version) has encountered a problem and needs to close. The system process C:\WINDOWS\SYSTEM32\Lsass.exe was terminated unexpectedly with status code 1073741819.

It appears the problem is file Lsass.exe (which i have no clue what is does). Has anyone else encountered this? Is it a virus or just a corrupt file?

(I am gonna email Microsoft, I am just wondered if this problem is just effecting me.)

Saz
02-May-2004, 12:05 AM
lsass.exe is a system file. Leave it well alone!

You could try restoring it, but that could cause all sorts of other problems with files attached to it. What version of windows do you have?

Topher
02-May-2004, 12:07 AM
lsass.exe is a system file. Leave it well alone!

You could try restoring it, but that could cause all sorts of other problems with files attached to it. What version of windows do you have?
XP Home

Saz
02-May-2004, 12:13 AM
Not sure about XP Home... If its causing MAJOR problems, try system restore to reinstall corrupt files. Back up your data first in case its not there when you're done.

When's it happening?

Topher
02-May-2004, 01:36 AM
When's it happening?


It happened every how and then, but todays it happens everytimes i go on the net, after a few minuets (1 to 10)

YODA
02-May-2004, 07:12 AM
I'm pretty sure you have a virus.

lsass.exe is a very common file that viri attack and replace, One of the more common ones is a hacked version of IRC.

Do a full virus/trojan scan at one of the many free online check sites.

Do a full spyware check too.

YODA
02-May-2004, 07:18 AM
I'm pretty sure you have a virus.

lsass.exe is a very common file that viri attack and replace, One of the more common ones is a hacked version of IRC.

Do a full virus/trojan scan at one of the many free online check sites.

Do a full spyware check too.
Check out this search on the SOPHOS website...

http://www.sophos.com/support/knowledgebase?search=lsass.exe&action=search&submit=Search

Topher
02-May-2004, 08:19 PM
I ran search & destroy, which only found a few dodgy Gator cookies. (I did zap a load of crap from search & destroy a few days ago.)

I used BitDefender and it found 4 files infected with:

Trojan.Killreg.Startpage.Y
Trojan.Downloader.Adroar.A
Trojan.Adware.Ruledor.C

BitDefender didn't find any viral code in file lsass.exe.

Anyway, I’m still getting the problem. I guess I’ll just email Microsoft on Tuesday to see what they say. A reinstall in the last thing I want to do though.

YODA, I went to that site and out of all the links listed in the page, I’m not to sure which one to use.

Topher
02-May-2004, 10:37 PM
I did a few system restores and created a new user acound and none resolved the problem :confused:

YODA
02-May-2004, 10:44 PM
Sounds like a reformat job :(

JohnnyX
02-May-2004, 10:58 PM
That sounds like a brand new Virus - NEW THIS WEEKEND.

See:

http://www3.ca.com/threatinfo/virusinfo/virus.aspx?ID=39012

Cheers.

Topher
02-May-2004, 10:59 PM
Sounds like a reformat job

Yeah, thats what i was dreading. I'll see what Microsoft says first.

Look like ill be backing up files into cd for a few days :(

JohnnyX
02-May-2004, 11:02 PM
See my post above - You missed it!

Cheers. :)

Topher
03-May-2004, 07:30 PM
.................ZAPPED! :woo: :woo: :woo:

Thank to everyone who helped :)