How to remove lsass.exe

lsass.exe

The module lsass.exe has been detected as Trojan.Agent

lsass.exe
MD5: 3b9b717ef412a5d28f93aac63835fa52
Size: 289 KB
First Published: 2017-05-30 14:05:21 (6 years ago)
Latest Published: 2020-02-25 12:00:00 (4 years ago)
Status: Trojan.Agent (on last analysis)
Analysis Date: 2020-02-25 12:00:00 (4 years ago)
%sysdrive%\windows
%windir%\system
%sysdrive%\$recycle.bin\s-1-5-21-2926708769-3922989499-4082492279-1001\$rlhdf4w\quantriweb_b2_30_8_2017\nukeviet\nukeviet\admin\editors\ckeditor\plugins\uicolor\yui
%sysdrive%\$recycle.bin\s-1-5-21-554643229-148930606-191412425-1001\$r6pmjws\mauh2s_fix_bkav
%sysdrive%\$recycle.bin\s-1-5-21-554643229-148930606-191412425-1001\$r6pmjws\mauh2s_fix_bkav
%sysdrive%\$recycle.bin\s-1-5-21-554643229-148930606-191412425-1001\$r6pmjws\mauh2s_fix_bkav
%windir%
%windir%
%windir%
%windir%
scout.exe
lsass.exe
pikachu.exe
PHAN MEM.exe
$RECYCLE.BIN.exe
iphone.exe
$RSMWBDY.exe
HOCTIENGANH.exe
thu.exe
PICTURE OF PHUONG.exe
MS Office 2010.exe
My Ebook.exe
OLS.exe
esl-tab.exe
picter of me.exe
elight.exe
System Volume Information.exe
$RDSPC46.exe
Grammar.exe
$RKYLM0D.exe
practise English.exe
~WanDrv6.Temp.FsJw3.exe
~WanDrv6.Temp.l55kO.exe
oro english.exe
$RLIL7ET.exe
$R3HKMQ7.exe
$R2SU5L9.exe
~WanDrv6.Temp.r76SU.exe
Canon LBP2900.exe
userinit.exe
Hoa.exe
imases_newstar.exe
dialogs.exe
specialchar.exe
images.exe
js.exe
image.exe
siteinfo.exe
layout.exe
youtube.exe
filter.exe
Images.exe
vdcssmoi.exe
_notes.exe
media.exe
hinhnen.exe
css.exe
link.exe
themes.exe
dialog.exe
styles.exe
image2.exe
Chim-Buom.exe
hidpi.exe
settings.exe
pastetext.exe
codesnippet.exe
uicolor.exe
freecontent.exe
jquery-ui.exe
star-rating.exe
pagebreak.exe
cache.exe
icons.exe
v2.exe
templates.exe
quantriweb_b2_30_8_2017.exe
find.exe
video.exe
style.exe
highlight.exe
ckeditor.exe
Style.exe
HinhDong.exe
du lieu.exe
superfish.exe
showblocks.exe
moono.exe
admin.exe
webtools.exe
lang.exe
editors.exe
tabletools.exe
div.exe
adapters.exe
plugins.exe
liststyle.exe
HinhNho.exe
clipboard.exe
kama.exe
complete.exe
wsc.exe
hinh.exe
yui.exe
nukeviet.exe
dulieuthem.exe
tbvdownload.exe
forms.exe
moono-lisa.exe
database.exe
tango.exe
modules.exe
language.exe
seotools.exe
pastefromword.exe
skins.exe
autorun.inf.bak.exe
switchbar.exe
default.exe
i18n.exe
eqneditor.exe
fonts.exe
about.exe
select2.exe
upload.exe
widget.exe
codecogs.exe
authors.exe
smiley.exe
DATA.exe
office2003.exe
flash.exe
autogrow.exe
colordialog.exe
New folder.exe
googledocs.exe
du lieubt4.exe
plupload.exe
2016_01.exe
du lieubt2.exe
FLASH.exe
iframedialog.exe
a11yhelp.exe
cleanlink.exe
layout - Copy.exe
placeholder.exe
cursors.exe
tableresize.exe
rank.exe
news.exe
copyformatting.exe
extensions.exe
scayt.exe
autosave.exe
iframe.exe
jquery.exe
tableselection.exe
balloonpanel.exe
table.exe
lib.exe
5-9-17.exe
topics.exe
magicline.exe
cropper.exe
assets.exe
tpl.exe
funcs.exe
phpmailer.exe
Tokenizer.exe
statistics.exe
dump_backup.exe
Token.exe
two-step-verification.exe
Exceptions.exe
blocks.exe
system.exe
url.exe
Gregwar.exe
src.exe
comment.exe
errors256.exe
Parser.exe
Authentication.exe
banners.exe
Arguments.exe
captcha.exe
Factory.exe
temp_pic.exe
page.exe
Exception.exe
Http.exe
Extension.exe
users.exe
mobile.exe
feeds.exe
PseudoRandomString.exe
facebook.exe
contact.exe
menu.exe
buzz.exe
Facebook.exe
2017_08.exe
data_logs.exe
Client.exe
Getters.exe
Message.exe
Consumer.exe
Cache.exe
polyfill-mbstring.exe
configurators.exe
XPath.exe
xdoc.exe
FileUpload.exe
seek.exe
Node.exe
pattern.exe
Service.exe
logos.exe
Rules.exe
PersistentData.exe
unidata.exe
mobile_default.exe
GraphNodes.exe
Image.exe
apache.exe
Compat.exe
ip6.exe
pclzip.exe
punycode.exe
xml.exe
Util.exe
Url.exe
ip_logs.exe
apt.exe
UserData.exe
Resources.exe
and.exe
Core.exe
assembly.exe
Handler.exe
login.exe
Utils.exe
kriswallsmith.exe
composer.exe
utf8.exe
site.exe
source.exe
Font.exe
certs.exe
old.exe
ip.exe
OAuth1.exe
error_logs.exe
endroid.exe
options-resolver.exe
arrows.exe
HttpClients.exe
renderers.exe
History.exe
main.exe
font.exe
keywords.exe
gregwar.exe
vinades.exe
Extractor.exe
Form.exe
voting.exe
config.exe
css-selector.exe
league.exe
groups.exe
Ftp.exe
voting_logs.exe
fr.exe
admin_default.exe
OAuth2.exe
php.exe
resources.exe
qrcode.exe
filters.exe
ElasticSearch.exe
Components.exe
tmp.exe
Elements.exe
files.exe
true.exe
ref_logs.exe
facebook-instant-articles-sdk-php.exe
changes.exe
Source.exe
symfony.exe
logs.exe
ini.exe
Controller.exe
Files.exe
en.exe
data.exe
Bundle.exe
appenders.exe
certificates.exe
Warnings.exe
Storage.exe
Adapter.exe
Validators.exe
log4php.exe
core.exe
siteterms.exe
Listener.exe
Twig.exe
graph-sdk.exe
Shortcut.exe
DependencyInjection.exe
oauth.exe
Signature.exe
Helpers.exe
Buzz.exe
cronjobs.exe
plugin.exe
helpers.exe
InstantArticles.exe
vi.exe
layouts.exe
Common.exe
img.exe
Transformer.exe
Xml.exe
layout_framework.exe
dist.exe
bootstrap-3.3.0-dist(1).exe
du lieu-c16dho.exe
dan trang dtu.exe
dan trang dien tu-cohoa.exe
autocad.exe
thietkegiaodienweb_12_9_2017.exe
DULIEUKETOAN.exe
DULIEUKETOANccc.exe
100.0%
Windows 8.1 97.9%
Windows 7 1.4%
Windows XP 0.5%
Windows 10 0.3%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0004cac0

PE Sections:

Name Size of data MD5
UPX0 0 00000000000000000000000000000000
UPX1 44544 905f5df2be44804a70c2367ecee9de07
.rsrc 180736 ea10fd637c6ecc24203ef1232fba8771

More information:

Download GridinSoft Anti-Malware - Removal tool for lsass.exe