LSA Shell

  • Thread starter Thread starter Cláudio Moreira da Rocha
  • Start date Start date
It is either the W32.sasser worm or the womourge worm.
Clean your system!
 
LSA Shell (Export Version) is lsass.exe.
[[This is the local security authentication server, and it generates the
process responsible for authenticating users for the Winlogon service. This
process is performed by using authentication packages such as the default
Msgina.dll. If authentication is successful, Lsass generates the user's
access token, which is used to launch the initial shell. Other processes
that the user initiates inherit this token.]]

[[Note: lsass.exe also relates to the Windang.worm, irc.ratsou.b, Webus.B,
MyDoom.L, Randex.AR, Nimos.worm which spread via floppy disk drives,
mass-mailing and peer-to-peer sharing.]]

If it's trying to access the internet block it.

Update your antivirus software and run a fullsystem scan just in case.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Back
Top