LSA shell

V. Gyorgy vgyke at freemail.hu
Thu Jun 30 11:52:30 CEST 2005


Vírus.


http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=37320

"When executed, Agobot.Z creates a copy of itself in the System
directory: %System%\LSAS.EXE"

It also creates the following registry keys to ensure it is
run each time Windows is started:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Explorer="LSAS.EXE"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Windows Explorer="LSAS.EXE"


http://vil.nai.com/vil/content/Print100733.htm

Type:		Virus
SubType:	Internet Worm

Upon execution, the worm copies itself to %SysDir% as: LSAS.EXE  (204800 bytes)


Gy.



Acs Gabor wrote:
> Sziasztok,
> 
> Tudja valaki, mit csinál az XP-ben az Lsas.exe?




More information about the Elektro mailing list