LSA shell
V. Gyorgy
vgyke at freemail.hu
Thu Jun 30 11:52:30 CEST 2005
Vírus.
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=37320
"When executed, Agobot.Z creates a copy of itself in the System
directory: %System%\LSAS.EXE"
It also creates the following registry keys to ensure it is
run each time Windows is started:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Explorer="LSAS.EXE"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Windows Explorer="LSAS.EXE"
http://vil.nai.com/vil/content/Print100733.htm
Type: Virus
SubType: Internet Worm
Upon execution, the worm copies itself to %SysDir% as: LSAS.EXE (204800 bytes)
Gy.
Acs Gabor wrote:
> Sziasztok,
>
> Tudja valaki, mit csinál az XP-ben az Lsas.exe?
More information about the Elektro
mailing list