|  | 
| lsass.exe (5.1.2600.1106)
| Contenu dans le logiciel | 
|---|
 | Nom: | Windows XP Home Edition, Deutsch | 
|---|
 | Permis: | commercial | 
|---|
 | Lien de l'information: | http://www.microsoft.com/windowsxp/ | 
|---|
 | Détails de dossier | 
|---|
 | Chemin de dossier: | C:\WINDOWS\system32 \ lsass.exe | 
|---|
 | Date de dossier: | 2002-08-29 14:00:00 | 
|---|
 | Version: | 5.1.2600.1106 | 
|---|
 | Volume de fichier: | 11.776 bytes | 
|---|
 | La somme et le dossier hache | 
|---|
 | CRC32: | D2697D2E | 
|---|
 | MD5: | 5823 9984 742E 8FD4 CD3F CEEB 5453 66C1 | 
|---|
 | SHA1: | 7010 716E 0C17 E3B9 88FC 87A2 F079 AFF4 E3FD C33A | 
|---|
 | L'information de ressource de version | 
|---|
 | Nom de compagnie: | Microsoft Corporation | 
|---|
 | Description de dossier: | LSA Shell (Export Version) | 
|---|
 | Logiciel d'exploitation de dossier: | Windows NT, Windows 2000, Windows XP, Windows 2003 | 
|---|
 | Type de dossier: | Dynamic Link Library (DLL) | 
|---|
 | Version de dossier: | 5.1.2600.1106 | 
|---|
 | Nom interne: | lsass.exe | 
|---|
 | Copyright lĂ©gal: | © Microsoft Corporation. All rights reserved. | 
|---|
 | Nom de fichier original: | lsass.exe | 
|---|
 | Nom de produit: | Microsoft® Windows® Operating System | 
|---|
 | Version de produit: | 5.1.2600.1106 | 
|---|
 
 lsass.exe a été trouvé dans les rapports suivants:
|  | 
|---|
 | W32.Nimos.Worm | 
|---|
 | Détails techniques ...Copies itself as %Windows%SystemLsass.exe. Note: %Windir% is a variable....
 ..."System Handler"="%Windir%SystemLSASS.EXE" to the registry keys:...
 Instructions de déplacement
 ..."System Handler"="%Windir%SystemLSASS.EXE" Do one of the following:...
 ..."System Handler"="%Windir%SystemLSASS.EXE" Navigate to the registry key:...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.nimos.worm.html
 | 
|---|
 | Backdoor.IRC.Ratsou.D | 
|---|
 | Détails techniques ...Libparse.exe (A nonmalicious file) Lsass.exe (Detected as Backdoor.IRC.Ratsou.D)...
 ..."HID.EXE"="%windir%system32dsdn36lsass.exe" "lsass"="%windir%system32dsdn36lsass.exe"...
 ...which call %Windir%System32Dsdn36lsass.exe when chat files are opened....
 Instructions de déplacement
 ..."HID.EXE"="%windir%system32dsdn36lsass.exe" "lsass"="%windir%system32dsdn36lsass.exe"...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.ratsou.d.html
 | 
|---|
 | W32.Sasser.G | 
|---|
 | Au sujet du W32.Sasser.G ...W32.Sasser.G is a variant of W32.Sasser.Worm that attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011....
 Évaluation de menace
 ...Computer will restart when Lsass.exe process crashes. Releases confidential info:...
 ...Unpatched systems vulnerable to LSASS exploit - MS04-011 ...
 Détails techniques
 ...Note: The Lsass.exe process will crash after the worm exploits the Windows LSASS vulnerability....
 Instructions de déplacement
 ...following text in the Comment box: Delay Lsass.exe shutdown. Click OK....
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.g.html
 | 
|---|
 | Backdoor.Queen | 
|---|
 | Au sujet du W32.Sasser.G ...The Trojan attempts to disguise itself as the normal Windows process named "LSASS.EXE." The Trojan has two components:...
 Détails techniques
 ...Attempts to create a remote thread in "LSASS.EXE" and inject itself into it....
 Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.queen.html
 | 
|---|
 | Backdoor.Lassrv | 
|---|
 | Détails techniques ...This file injects lsasrv32.dll into the Windows file Lsass.exe. lsarv32.dll....
 ...If the .exe file is executed, it injects lsasrv32.dll as a thread into Lsass.exe. The thread connects to ports...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.lassrv.html
 | 
|---|
 | W32.HLLW.Lovgate.D@mm | 
|---|
 | Au sujet du W32.Sasser.G ...2000, or XP, the worm attempts to disguise itself as the normal Windows process, Lsass.exe. This threat is written in...
 Détails techniques
 ...Injects a thread into "LSASS.EXE" and starts a listening server that provides a command shell on port 20168,...
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate.d@mm.html
 | 
|---|
 | Backdoor.IRC.Ratsou.B | 
|---|
 | Détails techniques ...LibParse.exe, a process viewer, clean. Lsass.exe, hacked mIRC32 client, detected as Backdoor.IRC.Ratsou.B....
 ..."HID.EXE"="%System%HID.EXE" "lsass"="%Windir%DebugUserModelsass.exe"...
 ...extensions in HKEY_LOCAL_MACHINSoftwareClasses, which call %Windir%DebugUserModelsass.exe when chat files are opened....
 Instructions de déplacement
 ...HID.EXE lsass Exit the Registry Editor....
 Source: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.ratsou.b.html
 | 
|---|
 | Hacktool.Asni | 
|---|
 | Détails techniques ...When Hacktool.Asni is executed on a remote machine, it attempts to crash the LSASS.exe process, which handles some Windows log-on authentication tasks....
 Source: http://securityresponse.symantec.com/avcenter/venc/data/hacktool.asni.html
 | 
|---|
 | W32.Sasser.F.Worm | 
|---|
 | Au sujet du W32.Sasser.G ...This worm attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011....
 Évaluation de menace
 ...Unpatched systems vulnerable to LSASS exploit - MS04-011. ...
 Détails techniques
 ...For example, 74354_up.exe. The Lsass.exe process will crash after the worm exploits the Windows LSASS vulnerability....
 Instructions de déplacement
 ...following text in the Comment box: Delay Lsass.exe shutdown. Click OK....
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.f.worm.html
 | 
|---|
 | W32.HLLW.Lovgate@mm | 
|---|
 | Au sujet du W32.Sasser.G ...XP, the worm will attempt to disguise itself as the normal Windows process, "LSASS.EXE." W32.HLLW.Lovgate@mm is written...
 Détails techniques
 ...If the worm detects the process, "LSASS.EXE," it will attempt to create a remote thread in that particular process and...
 ...Injects another thread into "LSASS.EXE", which starts a listening server that provides a command shell on port 20168...
 ......
 Source: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lovgate@mm.html
 | 
|---|
 |  |