Ran the following security: (Win 7 Pro, current updates applied) Microsoft Security Essentials MalwareBytes (free) MBAR HitmanPro (paid but ran on demand) Kaspersky TDSSKiller AVG Rescue CD Avira Rescue CD Kaspersky The video did not play properly. The log showed the above entry. Interpreting HijackThis Logs - With Practice, It's...

See Online Analysis Of Suspicious Files for further discussion.Signature AnalysisBefore online component analysis, we would commonly use online databases to identify the bad stuff. Make sure that "Show hidden files and folders", under Control Panel - Folder Options - View, is selected.Once you find any suspicious files, check the entire computer, identify the malware by

If an alert about scripting appears from your anti-virus, choose to allow the script to run. The bad guys spread their bad stuff thru the web - that's the downside. I'll try to help identify the problems, and figure out the solutions.

I then updated the system with all the security patches.

There are a lot of threads concerning this file on the web, but these are mostly hijackthis logs or the virus/trojan by the same name.

Non-experts need to submit the log to a malware-removal forum for analysis; there are several available. If its c:\program files\temp its reported as possibly nasty because lsass.exe is a name known to be used by malware and its not the right path for the lsass.exe that's known to

  Free AntiVirus programs: Grisoftís AVG Anti-virus Free Edition:
Using google on the file names to see if that confirms the analysis.Also at hijackthis.de you can even upload the suspect file for scanning not to mention the suspect files can

Just paste your complete logfile into the textbox at the bottom of that page, click "Analyze" and you will get the result. Please try again. That renders the newest version (2.0.4) useless

Download and run HijackThis To download and run HijackThis, follow the steps below: Click the Download button below to download HijackThis. Download HiJackThis Right-click HijackThis.exe icon, then click Run as Source code is available SourceForge, under Code and also as a zip file under Files.

You must be very accurate, and keep to the prescribed routines. This is a good information database to evaluate the hijackthis logs:http://www.short-media.com/forum/showthread.php?t=35982You can view and search the database here:http://spywareshooter.com/search/search.phpOr the quick URL:http://spywareshooter.com/entrylist.html That's one reason human input is so important.It makes more sense if you think of in terms of something like lsass.exe.

http://hijackthis.de/But double-check everything on google before you do anything drastic. It is kind of new so if that's all it said don't read too much into it.If there's more to it than simply an unknown process post what it did say

I downloaded ZA and installed it and rebooted the system.

Thanks, Fax

Roe Logfile of HijackThis v1.99.1 Scan saved at 4:10:57 PM, on 5/14/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe Since I found this in my logs 5 days ago, I have done the following: Spent approx 3-4 hours a day googling anything related to this file.