<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech Support Me &#187; virus</title>
	<atom:link href="http://www.techsupport.me.uk/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techsupport.me.uk</link>
	<description>Your one stop resource for free pc technical support</description>
	<lastBuildDate>Sun, 12 Jul 2009 21:27:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>lsass.exe Process &#8211; What is lsass.exe?</title>
		<link>http://www.techsupport.me.uk/2009/07/12/lsass-exe-process-what-is-lsass-exe/</link>
		<comments>http://www.techsupport.me.uk/2009/07/12/lsass-exe-process-what-is-lsass-exe/#comments</comments>
		<pubDate>Sun, 12 Jul 2009 21:27:56 +0000</pubDate>
		<dc:creator>robbrad</dc:creator>
				<category><![CDATA[Tech Support]]></category>
		<category><![CDATA[lsass exe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[sasser worm]]></category>
		<category><![CDATA[shutdown]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.techsupport.me.uk/?p=298</guid>
		<description><![CDATA[Some of you have requested we post an article on the Lsass.exe process &#8211; hope this helps!
What is lsass.exe?
&#8220;lsass.exe&#8221; is the Local Security Authentication Server. It verifies the validity of user logons to your PC or server. Lsass generates the process responsible for authenticating users for the Winlogon service. This is performed by using authentication [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you have requested we post an article on the Lsass.exe process &#8211; hope this helps!</p>
<h3><strong>What is lsass.exe?</strong></h3>
<p>&#8220;lsass.exe&#8221; is the Local Security Authentication Server. It verifies the validity of user logons to your PC or server. Lsass generates the process responsible for authenticating users for the Winlogon service. This is performed by using authentication packages such as the default, Msgina.dll. If authentication is successful, Lsass generates the user&#8217;s access token, which is used to launch the initial shell. Other processes that the user initiates then inherit this token.</p>
<h3><strong>Lsass.exe has been infected in the past</strong></h3>
<p>The Sasser worm exploited a vulnerability in LSASS  to spread via a remote buffer overflow in computers running Microsoft Windows XP and Windows 2000. The worm is particularly potent in that it can spread without any interaction with humans, nor does it &#8216;travel by email&#8217; like many other worms.</p>
<p>Should the lsass.exe program end, for example, by the Sasser worm&#8217;s effects, then a countdown timer will appear on the screen, advising the user to save his work and close all programs before Windows shuts down.<span id="more-298"></span></p>
<h3>When Is Lsass.exe dangourous?</h3>
<p>The lsass.exe file is located in the folder C:\Windows\System32. In other cases, lsass.exe is a virus, spyware, trojan or worm!</p>
<h3>What can I do to check Lsass.exe and stop my computer automatically rebooting?</h3>
<p>Forcible termination of lsass.exe will result in the Welcome screen losing its accounts and you will be prompted to restart your computer.</p>
<p><img class="aligncenter size-full wp-image-299" title="lsass.exe shutdown" src="http://www.techsupport.me.uk/wp-content/uploads/2009/07/sasser-shutdown.jpg" alt="lsass.exe shutdown" width="283" height="252" /><br />
In most cases, lsass.exe system error and lsass.exe application error make the computer unusable, because the user authentication token cannot be obtained from the server. In some cases, the error may be caused by a trojan, that camouflages itself as the lsass process. If the system is not infected, the error is caused by missing or corrupt configuration file and Registry entries. You can fix the Registry using the free Auslogics Registry Cleaner.</p>
<p>Malware often pretends to be lsass.exe. For example, the Sasser worm found a vulnerability in LSASS and spreads via a remote buffer overflow in Windows XP and Windows 2000 computers. This worm can spread without any interaction with humans, nor does it &#8216;travel by email&#8217; like many other worms.</p>
<p>If your computer enters a reboot loop because of an lsass.exe error, you get an lsass.exe error when trying to change your password, or the errors are caused by an infections, do the following:</p>
<p>1. After booting into Windows quickly click Start and then Run<br />
2. Type in shutdown -a and press Enter.</p>
<p>This will prevent your computer from restarting continuously.</p>
<p>Now try scanning your PC with an up-to-date anti-virus program in Safe Mode (tap F8 repeatedly during startup). Also make sure that you have all Windows updates installed. If this doesn&#8217;t help, you might need to do a Windows repair or a clean Windows install.</p>
<p>Note: The lsass.exe file should be in the C:\Windows\System32 folder. If you find it anywhere else, then lsass.exe is a virus, trojan, worm, or spyware!</p>
<h3>Virus with same name:</h3>
<p>W32.Nimos.Worm &#8211; Symantec Corporation<br />
W32.Sasser.E.Worm (Lsasss.exe) &#8211; McAfee<br />
W32.HLLW.Lovgate.C@mm &#8211; Symantec Corporation</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techsupport.me.uk/2009/07/12/lsass-exe-process-what-is-lsass-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker &#8211; April 1st Virus &#8211; April Fools Virus 2009 &#8211; W32.Downadup Worm &#124; The Conficker C Worm</title>
		<link>http://www.techsupport.me.uk/2009/04/01/conficker-april-1st-virus-april-fools-virus-2009-w32downadup-worm-the-conficker-c-worm/</link>
		<comments>http://www.techsupport.me.uk/2009/04/01/conficker-april-1st-virus-april-fools-virus-2009-w32downadup-worm-the-conficker-c-worm/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 08:13:12 +0000</pubDate>
		<dc:creator>robbrad</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Tech Support]]></category>
		<category><![CDATA[antivirus software]]></category>
		<category><![CDATA[april 1st]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[removal tool]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.techsupport.me.uk/?p=186</guid>
		<description><![CDATA[Do you have the April 1st Conficker worm?
The Conficker worm, sometimes called Downadup or Kido has managed to infect a large number of computers. Specifics are hard to come by, but some researchers estimate that millions of computers have been infected with this threat since January. If you are unable to reach certain web sites, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Do you have the April 1st Conficker worm?</strong></p>
<p>The Conficker worm, sometimes called Downadup or Kido has managed to infect a large number of computers. Specifics are hard to come by, but some researchers estimate that millions of computers have been infected with this threat since January. If you are unable to reach certain web sites, you may be infected. In that case you will need to get to a computer that is not infected, download the Conficker removal tool and run it on the infected machine before new antivirus software. Symantec has created a detailed technical analysis of the threat <a title="Conficker - April 1st Virus - April Fools Virus 2009 - W32.Downadup Worm | The Conficker C Worm" href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the_downadup_codex_ed1.pdf" target="_blank">here</a>.</p>
<p><strong>What does the Conficker worm do?</strong></p>
<p>The Conficker worm has created secure infrastructure for cybercrime. The worm allows its creators to remotely install software on infected machines. What will that software do? We don’t know. Most likely the worm will be used to create a botnet that will be rented out to criminals who want to send SPAM, steal IDs and direct users to online scams and phishing sites.</p>
<p>The Conficker worm mostly spreads across networks. If it finds a vulnerable computer, it turns off the automatic backup service, deletes previous restore points, disables many security services, blocks access to a number of security web sites and opens infected machines to receive additional programs from the malware’s creator. The worm then tries to spread itself to other computers on the same network.</p>
<p><strong>How does the worm infect a computer?</strong></p>
<p>The Downadup worm tries to take advantage of a problem with Windows (a vulnerability) called MS08-067 to quietly install itself. Users who automatically receive updates from Microsoft are already protected from this. The worm also tries to spread by copying itself into shared folders on networks and by infecting USB devices such as memory sticks.<span id="more-186"></span></p>
<p><strong>Who is at risk?</strong></p>
<p>Users whose computers are not configured to receive patches and updates from Microsoft and who are not running an up to date antivirus product are most at risk. Users who do not have a genuine version of Windows from Microsoft are most at risk since pirated system usually cannot get Microsoft updates and patches.</p>
<p>More infomation is avalible on  <a title="Conficker - April 1st Virus - April Fools Virus 2009 - W32.Downadup Worm | The Conficker C Worm" href="http://en.wikipedia.org/wiki/Conficker" target="_blank">Wikipedia</a>.</p>
<p><strong>The Fix</strong></p>
<p>If you have a computer that is infected, you will need to <strong>use an uninfected computer </strong>to download a specialised Conficker removal tool from <a title="Conficker - April 1st Virus - April Fools Virus 2009 - W32.Downadup Worm | The Conficker C Worm" href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDwndp.exe" target="_blank">here</a>.</p>
<p><strong>FAQ<br />
</strong>Q: What should I do if my PC is infected?</p>
<p>A: If you have a computer that is infected, you will need to use an uninfected computer to download a specialised Conficker removal tool from <a title="Conficker - April 1st Virus - April Fools Virus 2009 - W32.Downadup Worm | The Conficker C Worm" href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDwndp.exe" target="_blank">here</a>.</p>
<p>Q: Am I safe if I don’t go to questionable web sites?</p>
<p>A: No. The Conficker worm seeks out computers on the same network. You can be in a coffee shop, an airport or in the office and the worm will quietly try to attach to your computer and run itself.</p>
<p>Q: How do I know if I am infected?</p>
<p>A: The best way to know if you are infected is to run a good antivirus product. One symptom that may indicate you are infected is finding that your computer is blocked from accessing the web sites of most security companies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techsupport.me.uk/2009/04/01/conficker-april-1st-virus-april-fools-virus-2009-w32downadup-worm-the-conficker-c-worm/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>How to remove Trojan.Zlob.G</title>
		<link>http://www.techsupport.me.uk/2009/02/25/how-to-remove-trojanzlobg/</link>
		<comments>http://www.techsupport.me.uk/2009/02/25/how-to-remove-trojanzlobg/#comments</comments>
		<pubDate>Wed, 25 Feb 2009 23:26:50 +0000</pubDate>
		<dc:creator>robbrad</dc:creator>
				<category><![CDATA[Tech Support]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.techsupport.me.uk/?p=84</guid>
		<description><![CDATA[A few have requested this be posted as a fix so here you go&#8230;
Trojan.Zlob.G is another invention of Perfect Defender 2009 developers, that helps them to scare computer users and trick into installing and purchasing licensed version of Perfect Defender 2009. In fact Trojan.Zlob.G is imaginary application, main purpose of which is to mislead computer [...]]]></description>
			<content:encoded><![CDATA[<p>A few have requested this be posted as a fix so here you go&#8230;</p>
<p>Trojan.Zlob.G is another invention of Perfect Defender 2009 developers, that helps them to scare computer users and trick into installing and purchasing licensed version of Perfect Defender 2009. In fact Trojan.Zlob.G is imaginary application, main purpose of which is to mislead computer users. Usually Zlob or Vundo Trojan displays security alerts stating that your computer is seriously infected with Trojan.Zlob.G and your data and privacy are in danger. If you click on that alert you will be redirected to Perfect Defender 2009 download page.</p>
<p>Download SUPERAntiSpyware from <a rel="nofollow" href="http://www.superantispyware.com/">http://www.superantispyware.com/</a> or AdAware from <a rel="nofollow" href="http://www.lavasoft.com/products/ad_aware_free.php">http://www.lavasoft.com/products/ad_awar&#8230;</a> both are best at removing these Trojans&#8230;</p>
<p>How to remove Trojan.Zlob.G manually:</p>
<p>It&#8217;s possible to remove Trojan.Zlob.G manually, but you have to be very experienced in dealing with registry entries, program files and .dll files.</p>
<p>The files to be deleted:</p>
<p>* pd.dll<br />
* pdfndr.exe<br />
* pdmonitor.exe<br />
* PDInstall2009[1].exe<br />
* %WINDOWS%\system32\drivers\svchost.exe<br />
* %UserProfile%\Application Data\Google\ijdkq13324484.exe</p>
<p>Remove registry entries:</p>
<p>* HKEY_LOCAL_MACHINE\Software\Microsoft\Wi&#8230; Defender 2009</p>
<p>Please be careful because manual removal of Trojan.Zlob.G may seriously damage operational system and sensitive data. Also there is a big possibility of incomplete removal, because some files could be hidden and program could re-install itself after you delete files and registry entries. So I strongly recommend you to use automatic removal tool.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.techsupport.me.uk/2009/02/25/how-to-remove-trojanzlobg/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
