LCASS.EXE is associated with the malware groups Cloaked Malware, System Back Door, Malicious Software.
LCASS.EXE has been seen to perform the following behavior :
- Adds a Registry Key (RUN) to auto start Programs on system start up
- This process creates other processes on disk
- Executes a Process
- Writes to another Process’s Virtual Memory (Process Hijacking)
- This Process Deletes Other Processes From Disk
- Creates a TCP port which listens and is available for communication initiated by other computers
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Uses DNS to retrieve the IP address for web sites
- Uses your PC to connect to Chat rooms
- Found on infected systems and resists interrogation by security products
- Can make outbound communication to other computers, IM chat rooms and other services using IRC protocols
- This Process Disables Other Security Products
- This Process Contains User Mode Rootkit Functionality and can hide itself from the running process list
- The Process is packed and/or encrypted using a software packing process
- Executes Processes stored in Temporary Folders
- The Process is polymorphic and can change its structure
LCASS.EXE has been the subject of the following behavior:
- Added as a Registry auto start to load Program on Boot up
- Created as a process on disk
- Has code inserted into its Virtual Memory space by other programs
- Executed as a Process
- Copied to multiple locations on the system
- Deleted as a process from disk
- Terminated as a Process
- Created as a new Background Service on the machine
- Executed from Temporary Folders
- Registered as a Dynamic Link Library File
LCASS.EXE can also use the following file names:
..- REWT.EXE
- 94349093.DAT
- 85516615.EXE
- 88635257.EXE
- 37779156.EXE
- WH674EW7H47H.EXE
- 15439842.EXE
- 81972445.EXE
The following file size has been seen:
- 104,498 bytes
- 263,232 bytes
- 491,548 bytes
- 193,024 bytes
- 9,728 bytes
- 188,928 bytes
Files with the name LCASS.EXE have been seen to have the following Vendor, Product and Version Information in the file header:
- Miorosoft; ?????; 1.00.0185
- Miorosoft; ?????; 1.00.0185
- Miorosoft; ?????; 1.00.0199
- Usb Brower; ?????; 1.00.0032
- Usb Brower; 9fbae7a180e7b1bbe7a88be5ba8fM0; 1.00.0032
One or more files with the name LCASS.EXE creates, deletes, copies or moves the following files and folders:
Opens/modifes c:autoexec.bat
One or more files with the name LCASS.EXE creates or modifies the following registry keys and values:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun LCASS lcass.exe
One or more files with the name LCASS.EXE performs the following network events:
DNS Lookup213.251.161.68 rage.hackparty.com
One or more files with the name LCASS.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
TCP:213.251.161.68:81 Port:17
Remove
- Remove LCASS.EXE from memory. Use Task Manager, select LCASS, click End Process
- Remove LCASS.EXE following files from autoexec.bat, registry keys
- Remove LCASS.EXE file from Recycle Bin, %SystemRoot%system32
- Restart PC
Search Engine Visit :
update avira 10 , facebook via blackberry , flash games , remove v2 exe virusArtikel lain yang berhubungan :
- Remove Virus Downadup.C , Conficker , Kido
- Malwarebytes Anti-Malware Lifetime
- Malwarebytes Anti-Malware, Top, Best & Popular Spyware Remover
- Remove AV.exe Virus – Get an AV.exe Removal
- Messenger – nhattruongquang.0catch.com
- YahElite – Yahoo Messenger Alternatif
- Remove Trojan-Dropper:W32/Stuxnet by f-secure
- Remove Virus / worm W32.Downadup.B
- Top, Best & Popular Spyware Remover Downloads
- Portable Virus Alman / Almanahe Remover & Cleaner
- Google Search Results Redirected? It is a Virus!
- Varian Virus Downadup.C , Conficker , Kido
- Remove Virus / Worm VBS
- Remove Downadup , Kido dan Conficker di Network
- Testing Report Between Opera Mini 5.0, UC Browser 7.2 and Bolt 2.1
- Free Antivirus for Windows 7
- Cara Remove & Repair Virus Stuxnet Winsta
- Opera Mini Mod v.3.11
- Samsung NC10-13GB 10.1-Inch Blue Netbook – Up to 6 Hours of Battery Life
- Norton Internet Security 2010 1-User/3PC
Artikel Remove Malware LCASS.EXE yang terkait di situs lainnya:
Remove Malware LCASS.EXE | catatanku di website
LCASS.EXE is associated with the malware groups Cloaked Malware, System Back Door, Malicious Software. LCASS.EXE has been seen to perform the following
http://ariefew.com/virus/remove-malware-lcass-exe/
Remove lcass.exe With Easy Remover software | Instant Scan And ...
Risk Level: lcass.exe is a stealthy malware file programmed to appear as a legit program and perform various harmful activities on your compromised PC. lcass.exe is most likely ...
http://www.freespycheck.com/malware-removal/remove-lcass-exe.html
lcass.exe - Dangerous
... rootkits is best done from the "clean" Windows! Malware Removal Blog - everyday malware tests. lcass.exe ... Kill the process Lcass.exe and remove Lcass.exe from Windows ...
http://www.greatis.com/appdata/d/l/lcass.exe.htm
Lcass - Lcass.exe - Program Information
Lcass.exe: Command: C:\Windows\System32\Lcass.exe: Description: Added by the ... System32 for Windows XP/Vista/7. Removal Instructions: How to remove a Trojan, Virus, Worm, or other Malware
http://www.bleepingcomputer.com/startups/Lcass.exe-17515.html
lcass.exe - Dangerous
Kill the process Lcass.exe and remove Lcass.exe from Windows startup using RegRun ... Is it serious? The programs is known as malware. Item name: lcass.exe
http://www.greatis.com/appdata/d/l/lcass.exe_Removal.htm








Thank you for you tutorial, I will try it now..
.-= download ansav´s last blog ..Theme Ansav Black Edition =-.
[Reply]
ariefew Reply:
July 21st, 2009 at 11:26 am
ansav can’t detect this malware. PCmAV can detected.
[Reply]
Oh gitu ya…. <<< Lagi pura tahu aja padahal gak gak begitu ngerti bahasa nya aku om
.-= Johar´s last blog ..Anti Virus FlashDisk =-.
[Reply]
ariefew Reply:
July 24th, 2009 at 6:57 pm
Kapan2 bahasa Blitar ah…….
nb :
malware ini walaupun tdk bahaya, tapi menggangu juga. Windows kita waktu login sering hilang mouse nya….
[Reply]