Symptoms
- Presence of the following files:
%windows%\lsasss.exe
c:\ftplog.txt
- Presence of the following registry key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\lsasss.exe
with value
%windows%\lsasss.exe
where %windows% is the windows folder. Usually it is C:\windows\
The display of a message box described in the technical description
Removal instructions:
Let BitDefender delete all files found infected by this worm.
Analyzed By
Sorin Victor Dudea BitDefender AntiVirus Researcher
SHARE
THIS ON