lsass.exe – Fake Antivirus SecurityTool

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

lsass.exe – Fake Antivirus SecurityTool removal

File Virus Alias
lsass.exe Fake Antivirus SecurityTool
lsass.exe Trojan Kryptik
lsass.exe Trojan Agent
lsass.exe Trojan FakeAV
lsass.exe Trojan CI

Created files:

%Program Files%\MSN Gaming Zone\Windows\lsass.exe – Fake Antivirus SecurityTool
%WinDir%\install.exe – Fake Antivirus SecurityTool

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SonyAgent: %Program Files%\MSN Gaming Zone\Windows\lsass.exe

Detected by UnHackMe:

lsass.exe
Default location: %Program Files%\MSN Gaming Zone\Windows\lsass.exe

Dropper information:
SHA256: 26b9b6a2d1ec48603785ef9cea99aadf5f49a8d954899ab33e5c3e0036dad27c
SHA1: 172a0b96f77af7ffc03841b052fd7c966f0e71ea
MD5: 5106c97ec3edc9f6d0aa1ca217b8c8de
File size: 833536 bytes

Leave a Reply