WillShakespeare
MIS
Hi,
I have a friends PC, and I am an IT pro, but this one has got me stumped! The PC has been scanned and double scanned, from boot, Safe Mode, and full windows.
The symptoms include:
* Missing Turn Off Computer button in Start
* Regedit doesn't work from Run
* Can't right-click on MyComputer to get properties (System)
* 2 x lsass.exe running in Processes in Task Manager
* One of the lsass's is heavy on resources
* Registry contains MANY entries to windows\Fonts\lsass.exe
which seems to be a funky virus (maybe Sasser), but...
You cannot see this file for browsing to it, and you
cannot delete it using the full path, because the system
says it's not there!!
What I have tried:
* I fixed the Turn off computer thingy, by editing the
appropriate reg entry.
* Obviously I found a way into regedit, but only as a
workaround. This workaround being typing cmd at the Run
field, and then in the Command WIndow, typing "regedit"
* I have searched out and deleted the spurrious fonts\lsass
entries which include:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
among other entries, including (I think) the association
with exe extension. I have checked on my machine and there
should definitely ONLY be one lsass.exe process running!
* But, if I reboot, all these entries come back, and all the
other things happen like the disappearing Turn Off button
Apparently some files have also gone missing. A whole directory of invocies for this chap's business. But I wasn't aware the Sasser variants got rid of files... ?
Can anyone help?
Will
![[morning] [morning] [morning]](/data/assets/smilies/morning.gif)
I have a friends PC, and I am an IT pro, but this one has got me stumped! The PC has been scanned and double scanned, from boot, Safe Mode, and full windows.
The symptoms include:
* Missing Turn Off Computer button in Start
* Regedit doesn't work from Run
* Can't right-click on MyComputer to get properties (System)
* 2 x lsass.exe running in Processes in Task Manager
* One of the lsass's is heavy on resources
* Registry contains MANY entries to windows\Fonts\lsass.exe
which seems to be a funky virus (maybe Sasser), but...
You cannot see this file for browsing to it, and you
cannot delete it using the full path, because the system
says it's not there!!
What I have tried:
* I fixed the Turn off computer thingy, by editing the
appropriate reg entry.
* Obviously I found a way into regedit, but only as a
workaround. This workaround being typing cmd at the Run
field, and then in the Command WIndow, typing "regedit"
* I have searched out and deleted the spurrious fonts\lsass
entries which include:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
among other entries, including (I think) the association
with exe extension. I have checked on my machine and there
should definitely ONLY be one lsass.exe process running!
* But, if I reboot, all these entries come back, and all the
other things happen like the disappearing Turn Off button
Apparently some files have also gone missing. A whole directory of invocies for this chap's business. But I wasn't aware the Sasser variants got rid of files... ?
Can anyone help?
Will
![[morning] [morning] [morning]](/data/assets/smilies/morning.gif)