lsass.exe - Dangerous
%sysdir%\uyt\lsass.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
%SysDir%\uyt\lsass.exe is Trojan/Backdoor.
Kill the process %SysDir%\uyt\lsass.exe and remove %SysDir%\uyt\lsass.exe from Windows startup.
Malware: C:\sand-box\7.exe
Removed: C:\WINDOWS\system32\uyt\lsass.exe
C:\WINDOWS\system32\abfmokf.dll
Classification:Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.01.09 Trojan.Generic.2915706
Kaspersky 7.0.0.125 2010.01.09 Trojan-Downloader.Win32.Agent.cwnu
McAfee 5856 2010.01.09 -
Microsoft 1.5302 2010.01.09 -
NOD32 4757 2010.01.09 a variant of Win32/TrojanDownloader.Agent.PPB
Symantec 20091.2.0.41 2010.01.09 Downloader
Additional information
File size: 12288 bytes
MD5 : b2f3958a9429612c5e07885ee7886f7f
SHA1 : f609f0963b7e9eac95c491daae059ea29bbf28d7
SHA256: e4ce6863c7468802dc2e29dea7691554f884fef4d2d32e100ac2af5d97b93588
http://greatis.com/blog/how-to-remove-ma...