Branding_print


Go Back   Web User Forums > Security > Security & Privacy Help and Discussions

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 25-10-09, 13:18
gareth5506 gareth5506 is offline
256Kbps
 
Join Date: Feb 2009
Posts: 67
Default lsass.exe

In the last couple of days, when I boot up my computer, I have been getting a message that says lsass.exe cannot be found. My AVG Free kicked in and told me this was a threat. Having not heard of the file before, I thought it was best to quarantine the file, instead of clicking 'Heal'. However, I am still getting this message when I boot up.

After doing some research, I discovered this could be a trojan and one website suggested that I should scan the lsass.exe file. Making sure AVG was up to date first, I scanned the file and it said the file wasn't infected.

There has been no changes to my computer's behaviour apart from the message that pops up during boot up.

How can I solve this please?

Thank you in advance,

Gareth
Reply With Quote
  #2  
Old 26-10-09, 09:02
bricat's Avatar
bricat bricat is offline
Global Moderator
256Tbps
 
Join Date: Jun 2003
Location: belfast
Posts: 32,357
Default Re: lsass.exe

please go HERE

At the top, click on BROWSE. AND BROWSE TO this file on your computer :-

C:\windows\system32\lsass.exe

click on it to highlite it and then click SUBMIT.

the file will be scanned by various virus scanners.

please wait until the results come up, then post the results back here.
__________________
IF I HAVE SAVED YOU MONEY, PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.

Those are my principles. If you don't like them I have others
Reply With Quote
  #3  
Old 26-10-09, 12:15
gareth5506 gareth5506 is offline
256Kbps
 
Join Date: Feb 2009
Posts: 67
Default Re: lsass.exe

Thanks Bricat, but the website you told me to go to says it cannot be found. I tried to go to their homepage, but still get the same message!

Also, I read the dialogue box message I get on boot up before coming on here and it said the file missing was located at C:\WINDOWS\Config not C:\windows\system32\lsass.exe like you said, although I do have the file lsass.exe located at C:\windows\system32

I hope that all makes sense and that you or someone else can help me further.

Thank you,

Gareth
Reply With Quote
  #4  
Old 26-10-09, 16:51
bricat's Avatar
bricat bricat is offline
Global Moderator
256Tbps
 
Join Date: Jun 2003
Location: belfast
Posts: 32,357
Default Re: lsass.exe

[ QUOTE ]
but the website you told me to go to says it cannot be found

[/ QUOTE ]

does that mean the WEBSITE can't be found or the FILE can't be found ?

if it's the website that can't be found :-

Download the <font color="#FF0000">HostsXpert 4.2 - Hosts File Manager</font>.
<ul type="square">[*]Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager[*]Run HostsXpert 4.2 - Hosts File Manager from its new home[*]Click on "File Handling".[*]Click on "Restore MS Hosts File".[*]Click OK on the Confirmation box.[*]Click on "Make Read Only?"[*]Click the X to exit the program.[*]Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.[/list]
then try the site again
__________________
IF I HAVE SAVED YOU MONEY, PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.

Those are my principles. If you don't like them I have others
Reply With Quote
  #5  
Old 27-10-09, 11:29
gareth5506 gareth5506 is offline
256Kbps
 
Join Date: Feb 2009
Posts: 67
Default Re: lsass.exe

It just said Requested URL "/en-GB" was not found on this server. Tried to go to http://virusscan.jotti.org but got the same message.

Thanks,

Gareth
Reply With Quote
  #6  
Old 27-10-09, 14:49
bricat's Avatar
bricat bricat is offline
Global Moderator
256Tbps
 
Join Date: Jun 2003
Location: belfast
Posts: 32,357
Default Re: lsass.exe

did you install HOSTEXPERT and try again ?
__________________
IF I HAVE SAVED YOU MONEY, PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.

Those are my principles. If you don't like them I have others
Reply With Quote
  #7  
Old 28-10-09, 10:18
gareth5506 gareth5506 is offline
256Kbps
 
Join Date: Feb 2009
Posts: 67
Default Re: lsass.exe

No because I don't understand what you mean by "Note: If you were using a custom Hosts file you will need to replace any of those entries yourself."

Sorry but I'm new to all this and don't want to do something that will cause further problems.

Thanks,

Reply With Quote
  #8  
Old 28-10-09, 10:38
bricat's Avatar
bricat bricat is offline
Global Moderator
256Tbps
 
Join Date: Jun 2003
Location: belfast
Posts: 32,357
Default Re: lsass.exe

[ QUOTE ]
"Note: If you were using a custom Hosts file you will need to replace any of those entries yourself."

[/ QUOTE ]

If you don't know what a custom hosts file is then you obviously aren't using one, because you would have to install it yourself.
so it is ok to install HOSTEXPERT.
__________________
IF I HAVE SAVED YOU MONEY, PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.

Those are my principles. If you don't like them I have others
Reply With Quote
  #9  
Old 28-10-09, 11:48
gareth5506 gareth5506 is offline
256Kbps
 
Join Date: Feb 2009
Posts: 67
Default Re: lsass.exe

Dowloaded and installed the program, followed your easy step by step instructions, went back to the website and still got the same message saying the website cannot be found. I tried in both Opera and IE, but no luck!

I did find this website if it's any use http://ask-leo.com/what_are_lsass_lsasse...do_if_i_am.html

Although I'm only getting a dialogue box saying the file is missing. I'm not getting the countdown or being asked to shutdown.

Sorry for all the hastle.

Thanks,

Reply With Quote
  #10  
Old 28-10-09, 14:05
bricat's Avatar
bricat bricat is offline
Global Moderator
256Tbps
 
Join Date: Jun 2003
Location: belfast
Posts: 32,357
Default Re: lsass.exe

I doubt very much it is the sasser virus, that one isn't around anymore.

Please download ComboFix from Here or Here to your Desktop.

<font color="Blue">**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**</font>
  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    <ul type="square">
  4. <font color="red">Very Important!</font> Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  5. <font color="green">Click on</font> this link <font color="green">to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.</font>
<ul type="square">[*]Close any open browsers.[*]<font color="Red">WARNING:</font> Combofix will disconnect your machine from the Internet as soon as it starts[*]Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.[*]If there is no internet connection after running Combofix, then restart your computer to restore back your connection.[/list][*]Double click on combofix.exe &amp; follow the prompts.[*]When finished, it will produce a report for you. [*]Please post the "C:\ComboFix.txt" In the HJT forum[/list]<font color="blue">**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**</font>

P.S

can you please STOP putting your website at the bottom of your posts.
advertising is not allowed on the forum.
__________________
IF I HAVE SAVED YOU MONEY, PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST MALWARE.

Those are my principles. If you don't like them I have others
Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Search

Search

© Copyright IPC Media Limited 2009, All rights reserved





All times are GMT. The time now is 12:52.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
© Copyright IPC Media Limited 2010, All rights reserved