[CLOSED] lsass keeps returning

Container for RESOLVED incidents, queries SOLVED by the experts, EXPIRED topics or those that have been CLOSED by the users.
Locked
Asger
Registered user
Registered user
Posts: 2
Joined: Fri, 12 Feb 2016, 03:11

[CLOSED] lsass keeps returning

Post by Asger »

Hi

For some weeks every time my computer starts, Panda Antivitus free gives two warnings:

c:\windows\system32\config\systemprofile\a internet files\content.ie5\lsass[1].exe

c:\windows\temp\lsass.exe


Now, I know that lsass.exe is a system file when placed directly in the folder windows\system32 - but as you can see it is not.

Every day I tell Panda to neutralise it; it does and that's that. There is no lsass or strange CPU-using tasks listed in task manager, so I assume Panda stops the trouble before it can do real damage.


But ... it is regenerated at every restart, and that is at the very least an annoyance.

I suspect wherever it came from it probably dumped some changes to my registry, because this seems to be an issue in much older descriptions of the sasser virus which I guess this is.

But I can find no up to date tools or guides to help remove it completely.


Can you help me out here?
User avatar
VirusBuster
Official moderator
Official moderator
Posts: 7595
Joined: Mon, 02 Apr 2012, 18:53
Location: Panda HQ - Bilbao

Re: lsass keeps returning

Post by VirusBuster »

Have you tried running a full scan with the antivirus?
Try also running a scan with Panda Cloud Cleaner
Regards,

Image
Jorge Torre
TechSupport Department - Panda Security

I don't reply to private messages unless I have previously requested them
Asger
Registered user
Registered user
Posts: 2
Joined: Fri, 12 Feb 2016, 03:11

Re: lsass keeps returning

Post by Asger »

Hi VirusBuster


Thank you for the reply.

Yes, I have performed a full scan. After removing the the "lsass" ocurrences found at start-up nothing more is found.

I have tried a registry clean with CCleaner, and have also performed a full scan with malwarebytes antimalware.

What I need is to identify and remove the traces that cause the infection to regenerate.


Is Panda Cloud Cleaner my best option for this? I had rather hoped the problem was known and that a specific fix would be at hand.

Best,

Asger
User avatar
VirusBuster
Official moderator
Official moderator
Posts: 7595
Joined: Mon, 02 Apr 2012, 18:53
Location: Panda HQ - Bilbao

Re: lsass keeps returning

Post by VirusBuster »

Run a scan with Panda Cloud Cleaner in "Trusted Boot Mode" (advanced options) and let us know the results
Regards,

Image
Jorge Torre
TechSupport Department - Panda Security

I don't reply to private messages unless I have previously requested them
User avatar
VirusBuster
Official moderator
Official moderator
Posts: 7595
Joined: Mon, 02 Apr 2012, 18:53
Location: Panda HQ - Bilbao

Re: lsass keeps returning

Post by VirusBuster »

Closed due to lack of response
TOPIC CLOSED
Regards,

Image
Jorge Torre
TechSupport Department - Panda Security

I don't reply to private messages unless I have previously requested them
Locked

Return to “Virus - Archive Issues”