Completely eliminate the lsass.exe process Virus

Source: Internet
Author: User

Lsass.exe is a system process used for the security mechanism of Microsoft Windows systems. It is used for local security and login policies. Note: lsass.exe may also be Windang. worm, irc. ratsou. b. Webus. b. MyDoom. l. Randex. AR, Nimos. A virus created by worm is transmitted through a floppy disk, group mail, and P2P file sharing.
Process file: lsass or lsass.exe
Process name: Local Security Authority Service
Process type: other processes
English description:

Lsass.exe is a system process of the Microsoft Windows security mechanisms. it specifically deals with local security and login policies. note: lsass.exe also relates to the Windang. worm, irc. ratsou. b, Webus. b, MyDoom. l, Randex. AR, Nimos. worm which

Chinese reference:
Sorry, there is no Chinese reference for the moment!
Prepared by: Microsoft Corp.
Microsoft Windows Operating System
System Process: Yes
Background Program: Yes
Network related: Yes
Common Errors: N/
Memory usage: N/
Security grade (0-5): 0
Spyware: No
Advertising software: No
Virus: No

Two virus files, command.com and autorun. inf, are generated under the root directory of drive d, and the system file association is damaged by the intrusion into the registry. Worker two executable files, which are run in the background. Lsass.exemanage execlass execution file, and the exert.exe Management Program exits.

Cancel the LSASS. EXE startup Item. Delete Files under C: Documents and SettingsAdministratorLocal Settingsempt and Temporary Internet Files, disconnect the network, and delete the C: Program FilesCommon Filesupdate folder. The exe file cannot be run. Create a New reg file, enter the following content:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINESOFTWAREClasses.exe]
@ = "Exefile"
"Content Type" = "% 1, % *"

[HKEY_LOCAL_MACHINESOFTWAREClasses.exe PersistentHandler]
@ = "{098f2470-bae0-11cd-b579-08002b30bfeb }"

Or use a tool to restore the registry.

Take WIN98 as an example:

Open ie to delete cookiesand all detaching features, start the processes lsass.exeand exert.exe, and delete these two files in the windows directory. These two files are hidden, and then go to D: delete command.com and autorun. inf files, and finally restart the computer to DOS to run, use the scanreg/restore command to restore the registry, (if not, or if the XP system cannot be used, you can use software such as the rising registry repair program to fix the registry.) After restarting, go to WINDOWS Desktop Anti-Virus Software (I use Kingsoft drug overlord 2006) to completely eliminate viruses, clear the remaining viruses!

Windows XP releases the lsass.exe process Virus

I. preparations:

Open "my computer" -- tools -- Folder Options -- View

A. Remove the preceding hooks for "Hiding protected operating system files (recommended)" and "Hiding extensions of known file types;

B. Check "show all files and folders"

Ii. Process Termination

When you use ctrlpolicaltincludelto invoke the Windows Server Manager, it is impossible to end the process by right hitting the lsass.exe of the previous user name. A prompt box is displayed, indicating that the process cannot end the system process;

 

Click Task Manager process Panel, click the menu, "View"-"Select column", select "PID (process identifier)" in the displayed dialog box, and click "OK ". Find the image name "LSASS.exe", and the user name is not "SYSTEM", remember its PID Number. click "start" -- run, enter "CMD", and click "OK" to open the command line console.

Enter "ntsd-c q-p (this red part is the LSASS you see in the task manager. the number in the PID column of EXE is the PID of the current user name process. Do not look at it.) ", for example, enter" ntsd-c q-p 1064 "on my computer ". the process ends. (If it appears again after the end, you should use the following method)

(In addition, I strongly recommend that you use Process Explorer, a powerful Process management tool, to directly end the Process you want to end. It will be very convenient to use in the future. use asp? BoardID = 16 & ID = 1303 page = 1 "> http://www.gypin.com/bbs/dispbbs.asp? BoardID = 16 & ID = 1303 page = 1)

3. Delete Virus files

Delete the following files: (different from the WIN2000 directory)

C: Program FilesCommon FilesINTEXPLORE. pif (some do not have. pif)
C: Program FilesInternet assumerintexplore.com
C: WINDOWSEXERT.exe
C: WINDOWSIO. SYS. BAK
C: WINDOWSLSASS.exe
C: WINDOWSDebugDebugProgram.exe
C: WINDOWSsystem32dxdiag.com
C: WINDOWSsystem32MSCONFIG. COM
C: WINDOWSsystem32egedit.com

Right-click the D: disk and select "open ". Delete the "Autorun. inf" and "command.com" files under the root directory of the partition.

4. delete other junk information in the Registry

Rename "regedit.exe" in the C: WINDOWS directory to "regedit.com" and run the command to delete the following items:

1. HKEY_CLASSES_ROOTWindowFiles
2. HKEY_CURRENT_USERSoftwareVB and VBA Program Settings
3. Check_Associations under HKEY_CURRENT_USERSoftwareMicrosoftInternet assumermain
4. HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternetINTEXPLORE.pif
5. ToP items under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun

5. Fixed tampered key values in the registry.

1、change the default value of hkey_classes_root.exe to "exefile" (originally windowsfile)

2. Change the default value of hkey_classes_rootapplicationsiexplore.exe shellopencommand to "C: Program FilesInternet ‑eristme.exe" % 1 (originally intexplore.com)

3. Change the default value of HKEY_CLASSES_ROOTCLSID {identifier} shellOpenHomePageCommand to "C: Program FilesInternet ‑eriexplore. EXE" (originally INTEXPLORE.com)

4. Set HKEY_CLASSES_ROOT ftpshellopencommand HKEY_CLASSES_ROOThtmlfileshellopennewcommand
To "C: Program FilesInternet ‑eristme.exe" % 1 (the original values are INTEXPLORE.com and INTEXPLORE. pif)

5. Change the default values of HKEY_CLASSES_ROOT htmlfileshellopencommand and HKEY_CLASSES_ROOTHTTPshellopencommand to "C: Program FilesInternet ‑eristme.exe"-nohome

 

6. Change the default value of HKEY_LOCAL_MACHINESOFTWAREClientsStartMenuInternet to "IEXPLORE. EXE". (originally INTEXPLORE. pif)

Vi. Final work

Turn Off Registry Editor

Change regedit.comin the C: Windows directory to regedit.exe.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.