Technology in terms you understand. Sign up for my weekly newsletter, "Confident Computing", for more solutions you can use to make your life easier. Click here.

What are "LSASS", "LSASS.EXE" and "Sasser" and how do I know if I'm infected? What do I do if I am?

What are “LSASS”, “LSASS.EXE” and “Sasser” and how do I know if I’m infected? What do I do if I am?

The Sasser worm is the most recent and one of the most virulent viruses to impact Windows-based systems. Unlike previous outbreaks, Sasser doesn’t even need you to use email or even be at your machine to infect your computer and continue spreading. It exploits a recently patched vulnerability in something called LSASS.EXE.

Yep, it’s a nasty one and an example of sophisticated virus attempts yet to come. Even if you’re not infected this is an opportunity to review and implement the steps to keep your computer safe.

Become a Patron of Ask Leo! and go ad-free!

First, how do you know you have it? Unfortunately, Sasser shares several behaviors common with other recent viruses. The most common sign is that your machine will indicate that there is a problem and will reboot in 60 seconds. The message caused by Sasser should indicate that the problem is in LSASS.EXE.

You should be able to abort the shutdown within those first 60 seconds by doing the following:

  • Press the Start button and then the Run menu item.
  • Type shutdown -a. That’s the “shutdown” command, with the “-a” option, which stands for “abort the pending shutdown”.
  • Press OK.
The bottom line is that it’s a practical reality that we all need to be vigilant about keeping our computers safe.

This doesn’t fix anything; it just lets you get on with the business of disinfecting your computer.

Then, take the following steps:

  • Use a firewall. This can be as simple as turning on the Internet Connection Firewall included in Windows XP, to purchasing and installing hardware devices such as a NAT router. Either of these solutions will likely protect you from Sasser and many other types of non-email-based threats.
  • Install the patch. This patch for your operating system can be found with Microsoft Security Bulletin MS04-011.
  • Update and run your Anti-Virus software. Make sure that both of those steps happen automatically in the future as well. For example, my virus scanner is configured to check for updates and run a scan nightly.
  • Stay up-to-date. There are several options but I endorse running Windows Automatic Update for Windows XP. My preference is to have it download and notify me of changes that are ready to install. In addition – or, if you prefer, instead – you should also visit Windows Update on a regular basis for additional updates to your system. I probably visit once a month.

The bottom line is that it’s a practical reality that we all need to be vigilant about keeping our computers safe. The steps you take to protect yourself from becoming infected are much less onerous than the potential hassle of recovering from a destructive virus. Sasser doesn’t appear to be destructive…

…but the next one certainly could be.

Update: Apparently the Sasser worm also modifies a configuration file that renders many Anti-Virus sites and the MicrosoftUpdate site unreachable. So if you can get to this site (Ask Leo!), but not your anti-virus vendor then this might be the problem. It’s easy to check.

Open the file “windowssystem32driversetchosts” in Notepad. (Press the Start button, click onRun, type Notepad windowssystem32driversetchosts, and press OK.) Normally, it will have one entry for something called “localhost”. If in addition you see a list of Anti-Virus sites such as Symantec, McAfee, and more, then the worm has struck.

I would take the following steps:
  • Close Notepad.
  • Open Windows Explorer on the directory containing the file “hosts” (A quick way to do this is to press the Start button, click on Run, typewindowssystem32driversetc, and press OK.)
  • Right Click on the file hosts and select Rename. Give it a new name, like “oldhosts”.
  • Run the command “nbtstat -R”. (Press the Start button, click on Run, type nbtstat -R, and press OK.) You should only see a window flash on the screen briefly, but this little bit of magic should force Windows to re-lookup any of those names it might be keeping in memory.

Now you should be able to get to your anti-virus sites until you reboot – apparently the Sasser worm will recreate these bogus host file entries each time you reboot. So download your updates and scan to clean up the virus right away.

Update: As was predicted, follow-on viruses that exploit the same vulnerabilities that Sasser exploits are starting to show up. Sasser removal tools may not work because they are different viruses, even though they share some of the same symptoms. I cannot stress enough the importance of using a firewall, keeping your virus definitions up to date and running virus scans on a regular basis.

290 comments on “What are "LSASS", "LSASS.EXE" and "Sasser" and how do I know if I'm infected? What do I do if I am?”

  1. have xp professional. everytime i want to open an application, outlook express/worddocument/pdf doc etc
    the computer is stuck. the cpu usage is 100%.

    thank you

  2. HEY, where do i find a patch to get rid of the sasser virus (lsass.exe) ??? WHat is the website ???


  3. Just found that my wife’s PC seems to be infected as you describe….reboots in 60 seconds etc,references to Lsass.exe. Unfortunately tried the ‘shutdown -a’ command but it didn’t work, and machine still shut down in the middle of running an on-line virus-check. Does this sound like a new Sasser variant….if so any more clues?

  4. When i open task manager, the list of processes does not not show. it is just a grey blank and i cannot check what processes are running. do you have any ideas?

  5. I know I have that sasser worm because it is just as you describe… an error message comes up about lsass.exe and shuts down in 60 seconds. However when i run the sasser remover tool, it says my computer is NOT infected with the sasser virus. What do I do now?

  6. Again when i clicked on the direct link for the process explorer my internet just closed down again. it seems to be when i try to reach a site to do with PC safety my browser closes down, and i cannot get to the Norton site to get an online virus check. Any ideas are greatly appreciated.

  7. As I expected. The article above talks about being able to reach some sites and not others, and how the virus can make that happen – and what to do. Look for the section that begins: “Update: Apparently the Sasser worm also modifies a configuration file …” and follow the instructions there.

  8. Im sorry for all the bother but i cannot find the section that you have reccomended. Do you have a link or something to get me there?

  9. I have done what the update has said to do but when i open the host file there is no list of sites. it just has the local host entry, but still i cannot get to any of the sites.

  10. EVERYONE: I just added an update to the article. There are Sasser varients running around that exploit the same vulnerability, may have similar symptoms, but won’t be removed by Sasser removal tools. Check the updated article ( ) for links to Symantec’s site where there is more information and removal instructions.

  11. Eoghan: I don’t have a good answer for you, I’m afraid. Right now the only thing that comes to mind is to get anti-virus software and updates onto your computer using another computer and a floppy disk or CD-Rom. I know that’s not an option for everyone. If I come up with more information I’ll post it here.

  12. O.k here’s a slightly odd occurance, Eoghan mentioned that their pc was shutting down anyway even after trying “shutdown -a”. Well it seems my pc is infected with sasser or a variant, and for some reason after copying ‘lsass.exe’ (from Windowssystem32), to my desktop and running it from there, it hasnt since terminated, and nor has my pc been forced to restart. Try that Eoghan, i have no idea if it is a fluke, but i guess it is worth a try.

  13. so leo,

    everything seems to be fine, but do i need lsass.exe for windows xp to operate or is this part of a potential problem?


  14. LSASS.EXE is a required system component. The viruses just happens to cause problems that are reported as having happened LSASS.EXE.

  15. Just out of curiosity. Does the sasser bug effect the disk defragmenter because after i got the bug off my PC i tried to defragment but nothing happens when i try to run it. Any ideas for this one?

  16. Leo:
    I have the same problem. Have every problem associated with the sasser virus, but when I scan or run the removal tool it finds nothing.I have updated my norton antivirus up to May 19. Could there be another virus? I’ve also checked for the Kibuv-B and Bobax, but they are not on the computer either. I even went as far as to check for the blaster worm, because I know it will start a computer shutdown too. I’ve had no luck. Please help!!

  17. Well, it’s certainly possible that you’re on the leading edge :-(. I just checked the Symantec website and just yesterday they posted another variant of Bobax. – Not sure if the Norton definitions are up to that or not yet. Definitely make sure that you’re patched so you avoid any new variants as well.

  18. Well according to symantec the updates for this virus are on the 19, so I am covered there. I’m actually working on my bosses computer, (he’s had this for a week) and I made sure that i updated and got the patch from windows. I’ve tried everything I can think of. If you have any ideas I would greatly apreciate it. (think I’ve got to the point of tearing out my hair hehehe)

  19. I have been having problems with Outlook Express. When downloading e-mail, I get a McAfee alert that a virus has been detected and deleted (exploit-objectdata). Outlook then times out. When I quit and restart, I get the same message. If I go to and download my email, all goes well. I delete all of the spam files then log on to Outlook Express and can access my files again.

    I am also having problems sending files with attachments. Outlook times out and the file is not sent.

    I am useing McAfee firewall and virus scan.

  20. To me it really sounds like McAfee is interfering with attachments, both coming and going. Is it the latest version? Can you send properly if it’s turned off? I’d be very tempted to go to their support site on the web and see if they have anything on this.

  21. my computer is automaticaly shutdown problem

    basically when i have connected my internet explorer or my outlook experss that time my computer is automatically shutdown the problem is sasser virus problem how to remove that virus tell me that solved problme

  22. HI GUYZ,

    OMG HELP!! LOL!!!!

    Im an idiot, so save your breath, lol. I have found the last week to be very entretaining indeed. It all ocurred on the 18th of May. I got hit by sasser… Well, i didnt have a virus scaner and that is because i had just recently accured this computer from my mum (Dont laugh) and it was the first time i had connected to the internet from it. Bad timing i guess…

    So your proabably wondering why im rambeling on and when im gona get to the point right? Well, after a tremendous and epic battle with 5 viruses on my computer i have not yet succeded in banishing these criters from my computer!! LOL, im having fun but i definately would like a bit of advice if there is any to be given.

    The viruses i have after a week of fighting are:


    Im not sure if i still have the sasser virus, i happened to have had 2 different strains, both the Sasser.C and the Sasser.E. I have run symantecs “W32.Sasser.Worm Fix Tool” and it has not found them. I know i still have both Bobax.A and Ronoper.U viruses as i have instaled “AVG 6.0 Anti-Virus System” which does not run but it has a scan shell of somesort which warns me of the presence of these 2 viruses.

    I cant instal the Mirosoft Security Update as i cannot run it. I cannot run registry ither. I have tried just about all avenues that i know of and have had no results.

    So, any tips?



  23. Domen: well, have you followed all the steps in the article, including the firewall? That should help prevent further infections of this sort. Next, I’d keep hitting the symantec site and search for those specific viruses by name … even when the scanner doesn’t fix ’em, they almost always include manual “hot to remove” steps for each specific virus.

    Good luck!

  24. Right now, in addition to Sasser I also got something that seem even worse…it will kill most fixes that I am trying to apply to my XP Pro system! When I tried to install XP SP1, or Sassor fix, the pop-up dialog will get killed, so that I cannot apply the fix or SP1…some fixes goes through, but most will get kill…anyone know what to do to fix this? I upgraded from XP Home to XP Pro–didn’t help…I re-install the MS installer, didn’t help either….. PLEASE HELP.

  25. Have you run virus and spyware checks? Do you have another machine you can use to get the latest virus signatures down? That’d be my approach … try a couple of different anti-virus programs with the absolute latest signatures. Recommendations: . Given that you seem to have multiple problems, that seems the mostly effective bet.

  26. there r a process “dirote.exe”,”dorod.exe” appear in my win2000 professional PC,I know it’s the Troj virus and serach the website all,but still donnot know what’s the effect way to clean the virus?is it only the “Sophos Anti-vius” can do so?i donnot use such software before,please gice me more advice,thanks more!!!

  27. Sophos is certainly a fine package, though I don’t know if it’s the only one that can deal with this specific virus. Regardless, using SOME kind of anti-virus software is the right thing to do. If the Sophos web site has information on that specific virus, then I’d certainly suggest downloading and using their virus scanner. And then continue to scan regularly to avoid future infections.

  28. Hey, if you’re not trusting your own AV, there’s always online scans, such as the one at Trend Micro (though you need to use IE for it… one of the few things I use it for instead of Mozilla.)

    You may also (for future use) want to go to Microsoft’s website and get their update CD – they shipped it to me, free of charge (along with Computer Associates’ AV and firewall package, which I don’t use – I’m happy with AVG Antivirus and Zonealarm.)

    Good Luck…

  29. Hi Leo,

    Well, im still trying!! I got a big brake when i downloaded SpyBot!! I scaned my hd which only took about 2hrs and its found 52 files of which it couldnt delete 2 of them. one of them is the bridge.dll which im preaty sure is the ronoper.U virus doing its bad deeds. Now, i cannot find anything on the net that can help me rid myself of this pest!! The only thing is on symatec but it means i have to buy it, please tell me there is another way! Im a student, or soon to be, and im real short of cash!! lol. I will keep you up to date 🙂

    Thank you so much for the help you have given me so far, even if it hasnt worked yet, im sure it will soon.


  30. Hi Leo,

    Im still battleing away although i have a feeling i am aproaching the light. I found hijakthis before i posted on here but it would not run. I have tried it again and now it runs for about 4sec before dissapearing into thin air, enogh time for me to creat a log. I will keep you up to date with how im going. This might be the brake i was looking for.

    Thanks heaps for your help, even though i dont like crying victory before im in the clear.



  31. Hi Leo

    I rescently installed windows XP Prof in my laptop and I bought macfee internet security software (Virus Scanner/Firewall/Privacy Protection/SpamKiller) and installed in my laptop and when i connected to the internet using a DSL my system is going Crazy. after five minutes in the internet the name in the start button “START” will disappear and that it am unable to do anything I have to hard boot my system and restart to work for five minutes in the internet and again boom its gone. what should i do. I first thought its a SASSER virus so i downloaded Nortorn AV in a different M/c (My friends computer)and installed in my computer and scanned it didnt detect any virus. I badly need help / suggestion. all my work is in that laptop and am stuck now with no options.

  32. While I might not suspect Sasser, I think your instincts on a virus infection feel right on. I’d be tempted to try a virus scan with a different product as well. (Recommendations: ). There’s an outside chance this could be caused by spyware, so check this article: . And finally, if the machine will run long enough while not connected to a network, a System File Check might also be appropriate: .

    Good luck!

  33. Hi Leo
    I recently found a company laptop which kept attempting a dial up connection.
    After hunting around a bit I found a program called ‘wave eggs.exe’.
    I managed to get rid of it, but couldnt find anything on the net about it.
    Have you encountered it before and how can I protect against it?

  34. hey,
    I am infected with the virus lsass.exe, it restarts the computers contigously.
    i dont know how to cure myself from that. please help me, i cant connect to the internet. because as i connect , in the very next 15 minutes it restarts. please help me.

  35. Hi Leo,

    I got the LSASS.exe infected on my computer (running window 2000). When I saw the error message, I renamed the “lsass.exe” to “lsass_old.exe”. Now, I can’t start my computer (not even in safe mode). The hd is in “NTFS” format, is there any way I can rename the file back and following the right path to clean the virus?


  36. If you made a recovery disk when you installed your OS (or if a recovery disk came with the system), you should be able to boot from that and rename the file.

    You might also be able to create a bootable floppy that supports reading NTFS – one such example: – I’ve never used such a beastie, but it should get you access to the partition long enough for you to rename your lsass.exe back and reboot from the hard drive.

    Let me know how it goes…

  37. I am not sure if LSASS is infected or not! My monitoring system merely tells me (on boot up) that LSASS has changed since the last time I booted and wants to access the internet. I continually answer no, but wonder now if it’s a problem. Really want to know how to stop it from changing and how to get rid of this continually asking to access internet.

  38. Lsass.exe: This is definitely the nastiest piece of work I’ve come across in the last decade. Absolutely nothing I do gets rid of it.
    You can reformat in ntfs or Fat32 use Fdisk /MBR
    install win ME and then revert back to XP with Fat 32..enter with a boot disk and delete the file..and what happens? no reboot…so it’s reformat, reinstall, and everything is back to sqare one again. You can try any virus scanner available symantec, AVG, housecall, the microsoft tools. They don’t even recognise it. This thing was developed to make XP obsolete and as far as I’m concerned it’s gonna succeed. I’m going back to to ME, won’t even consider getting a new hard disk. This thing sits somewhere else.

  39. My Win2k (Prof.) system had a probem of the sort , it removed the dialup networking connection automaticaly and while I tried to add a new connection it says that the Connection name is invalid (its not accepting any name). Hence I applied SP4..this started giving me more trouble. Now I can’t start my PC. It boot well and comes almost near to the login screen and suddenly reboots, I tried to boot it in safe mode and in debug mode.. still its not allowing me to boot the system. Pl. help me to solve this problem.


  40. Charlie: remember that LSASS.EXE is, in fact, a *required system component*. You can’t just “get rid of it”. What you can do is disinfect your system from the viruses that manifest as LSASS.EXE errors, and protect yourself from further attacks, all as outlined in the accompanying article.

    But I definitely agree that this particular vulnerability, and the viruses that are attacking, are some of the nastiest we’ve seen to date.

  41. Harry: the best I can offer at this point is that you’ll need to boot from a floppy or CD, possibly your recovery floppies if you made them, and then run a virus scan on the machine. You *may* need to reinstall Win2k and SP4 to fully recover. You should do all this either not connected to the interner, or *after* having installed a firewall to protect you from vulnerabilities while you are scanning/reinstalling.

  42. Leo, you have brought my sanity back, I bought a new laptop over the weekend, and that day got infected, this thing is rife! I followed your steps and now I seem clear. I’m not at all technical, but you showed me the way – respect! Good Luck to all the rest, Leo’s the one!
    Thank you


  43. Mr. Leo….. My computer definately has this bug you speak of… I was soooooo relieved to see that it wasnt just me being a complete idiot, and was so happy that this site shows me what i can do. I am downloading the q317636i.exe file thingy. My computer also has a few more problems. Not just lsass.exe but i was having trouble with my internet explorer, iexplore.exe, which seems to have miraculously ended, because i have been connected to explorer much longer than it would let me. I also get an error with this file, something like ftupd.exe or something. When i was completely clueless of what the problem was, i did the system recovery, (i have no disk) and now i cannon install my symantec firewall. I am sure this is a bad thing. What would you recommend that i do? Is my norton anti-virus running properly? It seems to be but when i scan it finds nothing. Although it has said that it caught this threat; w32.spybot.worm or something very close to that. Please help my situation

  44. My guess is you are infected with something. My first place to look would be the hosts file I mention in the article. If it’s there and full of the addresses of lots of anti-virus sites, that’s what’s preventing you from accessing those sites. I’d rename it, reboot, and see if you can get the latest set of virus definitions downloaded. As an alternative, you can try some of the alternative on-line virus checkers I mention in my recommendations pages:

    Good luck!

  45. Thank you for all the links to anti virus’s and all that, it will be helpful. I attempted to check the hosts file, i found it, but i cannon open it. A messege says it cant open it, because it doesnt know what created it, so it says it can go online and check, and i get a page cannot be found, it tries to go to HTTP 400- Bad Request- Microsoft Internet Explorer… I was very convinced it was this sasser thing that ive got, but ive probably got a whole collection … Ill start with trying the download for the sasser worm. If problems continue ill move on from there… Well… thanks again- Beau

  46. Instead of double clicking on the hosts file, run notepad, and then use File, Open to open the file directly. That should let you see what’s inside.

  47. Sometimes when I connect to the Internet (dialup), my McAfee firewall alerts me that the program LSASS.EXE has changed since the last time it accessed the Internet. I do not seem to have any of the symptoms of Sasser, and the file “C:windowssystem32driversetchosts” does not exist. Should I allow LSASS.EXE to connect to the Internet whenever it asks? I am running Win2K.

    Also, a separate question. May I place a link to your website on mine?

  48. I’m suspicious about your LSASS issue. You may be infected with somthing – perhaps not sasser, but similar. I’d make very sure that you’re running an up to date virus scanner regularly. I would not let lsass connect out – I’m not aware of any reason that it should.

    And yes, thanks for any link!

  49. Leo,
    When I type in the “windowssystem32driversetcHOSTS” my computer only goes to the the etc part and does not have a “HOSTS” ? ?

    What does this mean? Has the hole already been patched by my automatic updates? If the file HOSTS is missing is it a problem ? I don’t think I have sasser because I have never had the rebooting problem but was just going to fix it so I don’t get it. Then try and figure out how to turn on the firewall in my XP. I have a Dell Demension 2400 series.

    Is it a bad thing that the HOSTS doesn’t exist?
    Hope I have given you enuf info ? ?

    Gary Wade

  50. While a lack of “hosts” is unusual, it shouldn’t in itself cause a problem. Basicly I’d simply double check, probably in a command prompt, by going to that directory and looking. Since I don’t know *where* you’re typing the filename, I don’t know that it’s really telling you that the file doesn’t exist.

  51. I have had the worst time with viruses lately. I have removed the sasser worm 3X and had a Sdbot worm and have the bobax worm. I used trend micro Housecall to delete these files . My norton anti virus protection is somehow disabled and I cannot acess it for very long and it closes shortly after opening it .it is no longer on my desktop tool bar ( bottom right hand corner near the time) and it indicates in the norton for the few seconds I can open it that my email scan is in error. It will only stay open for a few seconds. I have removed and reinstalled this program twice and have two firewalls in place now. I am using the housecall trail protection for now but i want my Norton back.
    Any suggestions. And I want to check my registry so I don’t reinfect the PC each time any help?

  52. Hello. I dont know what is wrong with my computer. I cannot do basically anything on it anymore, so i am using a different one for now. Every time i log on, it waits a few seconds, then does the 60 second shut down thing. I downloaded the fxsasser.exe tool from the symantec site, but it said i didnt have sasser. I also cannot scan my computer with symantec, because whenever i press “scan”, the application blows up. I went into the hosts file mentioned above, and there was only the one normal entry. I would apprecciate any help. Thanks

  53. It certainly sounds like you’re infected with one of the related viruses. I’d perform as many of the steps as you can from this article, and also run a system file checker ( ). You may need to disconnect from the network, and possibly boot into safe mode or from a floppy of CD in order to run a virus check on your system.

  54. I have the lsass.exe worm and i am trying to remove it but every website i go to and use their virus removal tool says i am not infected. HELP

  55. You’re correct Jasmin, LSASS.EXE is a part of Windows – it’s a required system file that happens to show up in the error message when you are infected with any of a number of different viruses. You list two, there’s also Sasser and several others. THe best thing to do it to keep your virus signatures up to date, run virus scans periodically, and even scan with a second AV program from time to time. And of course follow the other steps in the article.

  56. I was wondering if totally wiping your harddrive and reinstalling xp pro will get rid of the sasser virus? If it does will previous files i saved on a cd when i had the virus still be potential infectors?

  57. It depends on the files, but the short answer is probably yes. The safest thing to do is to run a virus scan on those files before you copy them back. And make sure that when you reinstall you’re protected by a firewall so you don’t immediately get the virus again over the net.

  58. Can someone post a link with a list of possible virusses and trojans that uses lsass.exe?

    I try to find out wich one my friend has. I tried Sasser, Blaster, Sober and Lovegate, but I didn’t found the right one.

  59. There’s not much point as the list changes almost daily. My recommendation is to use a virus scanner and it will report which one.

  60. i have a problem with my computer it shuting of after one minute and massaig comes “lsass.exe” some writing is there also.

  61. hey leo, similar to sasser, i get an error lsass.exe-system error, invalid parameter etc…but my comp shutdowns immediately. plus i was running windows xp repair/blanket install, so its permanently stuck at installation splash screen. any ideas? thanks.

  62. Hey leo if you are completely updated with nortan antivirus and scan your harddrive should it detect the sasser virus? I am completely updated but i originally installed nortan 2002. Also i am expiriencing another problem. At some point a system file called svchost.exe starts to sap my cpu usually taking as much of the processing power as it can and my other programs run like molassas. If I end the process It will display the shutdown in 60seconds window. If i run shutdown -a it will stop but the taskmanager items retain their user identity instead of reverting to unknown and i regain my cpu power Is this the sasser virus?

  63. Hi, I am not sure what I have and how to get rid of it. I get a pop up box when my PC is booting that says “Lsass.exe” at the top in the blue bar and then in the box itself it says “Item not found”. I get this before my PC fully boots so I am not able to go to my start menu or anything. Best I can do is hit F1 and go into setup. Is there anything under setup I can do to stop this from happening so my PC will fully boot?

  64. Chris: I’d try booting in safe mode to see if it’ll get further, but ultimately I think you’re going to have to boot from a floppy or CD so you can run an AV scan and repair your system.

  65. Brice: yes and no. The problem is that new variants are coming out every day, and the AV software manufacturer;s are constantly playing catch-up. Definitely keep your virus signatures up to date – I check for new virus definitions daily. The SVCHOST issue also sounds like yet another virus –

  66. Jen: if it’s the setup I think it is, no. You’re in the same boat as Chris – you’ll need to boot from floppy or CD-ROM to repair your system. Perhaps even reinstalling it will be neccessary. Be sure that a firewall is in place before you connect to the network to avoid getting immediately reinfected.

  67. I got the sasser virus, but I had no idea what it was. I cut the lass.exe file (removed it from windows) and pasted it on my desktop. I restarted the computer, but now it go at all. All I get is a black screen and the cursor works and that it. What can I do to solve this problem?

  68. Thank for the heads up, but I have the viruses in my Pc right now. But this viruses is just making me reboot I don’t know alote about PC.

    That (start -a) work for me and I thank you for that, but I don’t know how to kill this viruses.
    Or I just did’t get what you said sorry about that, Can you help me ,one more thing you where sayying there a way to save my PC from viruses like that can you tell me again how to do that.

    Thank You!^-^

  69. Leo, in the version I have, the command is: shutdown /A
    not: shutdown -a
    which just shuts down the workstation.


  70. During the start up of windows (status bar at 100%) and the login screen popping up, I got a message that said my computer will shut down in 40secs because of lsass.exe.

    I ran the removal tool and no sasser worm was found. I look at my registry under the Windows/CurrentVersion/Run and no sign of sasser.

    Am I infected with the sasser worm?

    Also during Windows loading up and Login Screen, is my computer vulnerable? For example, can people hack to my computer or can virus and worms attack my computer during the Login Screen (before I log in)?


  71. You’re probably infected with one of the varients that the article talks about. Standard advice: make sure you have an up-to-date virus program, with up-to-date virus definitions, and scan.

    And to answer your question: YES the vulnerability that sasser and related viruses take advantage of does NOT require you to be logged in. That’s why I’ve been continually recommending the use of a firewall, such as a NAT router or XP’s built in firewall. Either of those will block this vulnerability.

  72. Leo,

    The crash only happened once. How can I be sure that I am infected with sasser worm?

    I ran symatec and microsoft removal tool and found no sasser worm. I went through the registry and found no sign of the sasser worm.

    I do have the zone alarm firewall, its that not enough?


  73. I’m not talking about sasser specific removal tools – I mean that you should run a full Anti-virus scanner that looks for all viruses and removes, or at least alerts you to the ones you may have. It may not be Sasser that you have – there are several viruses now that have similar symptoms. That’s why you want a AV package that looks for many viruses. I have recommendations here –

    And if it only happened once, you may not be infected at all.

    I *believe* zonealarm will protect you before logging in.

  74. Thanks for the great info you have here. I am recieving the LSASS error and thought it was sasser, but the removal tool said i didnt have it. I checked the hosts file in system32 and everythings fine there, but i cannot sign into hotmail,and ive been having problems with an exponentially slow dialup, after 40 seconds of connecting to the internet, it completely stops. I cannot find what, if anything is taking my bandwidth. Because i cant sign into hotmail, i cant continue to dl Norton antivirus. What antivirus software do you suggest i dl, and does this just sound like a sasser variant, or more than 1 virus? The registry looks fine under “run once.. run hidden etc”.

  75. I have yahoo dsl and have located the lsass.exe I am having issues connecting to the internet. I reset my modem and it connects for a short time then disconnects. I have updated my virus scan and ran it. I was wondering if this is virus related?

  76. Trin: Your best bet is to get an Anti-Virus product and current definitions on a CD-Rom – then disconnect your machine from the internet and run the scan. Any of the major scanners should do, but if you’re burning a CD-ROM, I’d go ahead and put two on there, and run them both, each in turn. Recommendations here:

  77. David: it’s hard to say. It could be any of a number of things. When you say “located the lsass.exe” what do you mean? It’s a valid system file on every Windows XP machine, so it’s presence does not mean anything.

  78. Hi all,
    I have up-to-date Zone-Alarm, and got the signs of the SASSER virus, but it never got to do it’s nasty thing.
    There was an instance of something like “Lsass (Export Version)” but it asked me if I wanted it to talk to the outside world: Fortunately being a wary kind of guy I said no, and disaster was averted.
    Do what Leo says, keep your AV software BANG UP TO DATE! Yes, a software firewall will help and give a certain peace of mind, but it may not be bombproof.
    If you run a tight ship, you’ll be the least likely to get stung.

  79. I have Norton Personal Firewall 2004. I got a message asking me if I wanted to let the program LSASS.EXE access the internet. It RECOMMENDED that I allow it to do so! Haha. But I said NO, and told it to block all attempts, because I was not sure what LSASS.EXE was. I am glad I did! But at least the firewall brought it to my attention. I feel a bit safer now.

  80. My PC is shuting down every 15min it is showing error of your windows going to shutdown within 50seconds ther is some error in lsass.exe please help me in this regards

  81. When my PC boots it tells me that LSASS has changed since the last time I used it. My firewall asks if I want to continue. Is this a sign that LSASS has been infected??

  82. hi,
    my pcs been infected by sasser and i deleted the lsass.exe file,now the pc wont boot in xp(i have dual boot option).kindly tell me if pasting lsass.exe file from a friends pc would solve the problem of booting or do i have to install xp again.

  83. Sorry i don’t think this is about the sasser virus but I have this system component called winsecurity.exe start when windows does. It appears in my task manager and starts to sap all cpu power. I can end the task and get all my speed back but the next time i reboot it appears again. Does anyone know what virus this is and how to stop it? Will it get worse? I am completely up to date with nortan but it doesn’t seem to catch it. Help!

  84. I have a laptop (acer) and at windows start up => i have the following alert(before even the case withe the password and the user name): “lsass.exe” -system error. i have to press ok and the pc restarts and so on. It is very probable that sasser has overwrited the file lsass.exe.
    Please help me: what can i do, because i can’t event start the windos completely, i can’t acces the menu, i can’t start the safe modde either. please help me.

  85. Nen: I’d double check your browser settings, perhaps run the system file checker and a spyware scan. If you can use messenger applications and were able to download the patch, then you *are* accessing the internet … this looks more like a browser-specific issue.

  86. emm hi I get no error on my pc but in in the task manager(win xp) theres a lot of processes called 1-lssas.exe 2-lssas.exe 3-lsass.exe…and so on I dont know if my pc is infected what should I do?

  87. I am attempting to download the patch and use the removal tool, however shutdown -a does not stop the shutdown process on my system. I am running Windows 2000.

    I get a message saying “Cannot find the file ‘shutdown’ (or one of it’s components) Make sure the path and filename are correct andt that all required libraries are available.

    Thank you.

  88. Hello I believe I have sasser or some variant. I have formatted my C drive and deleted all partitions several times but as soon as I reinstall the Operating system (windows 2000 or Xp) I get a reboot error within 60secs and error from lsass.exe Also as soon as I connect to internet all bandwith is used by some thing on my pc. It is incredibile. I though that a format C: would have got rid of this virus. Do you have any help for me? I have tries Norton, Mcaffe , Grisoft AVG and Avast antivirus and also spybot none of these software detect my virus. I am despeate. Please help.


  89. Are you on a LAN with other machines? If one of those is infected, then it could be that you’re getting reinfected immidiately upon connecting to your LAN. Physically unplug from the network and see if that allows you to get further.

  90. I keep getting the shutdown screen in 60 seconds when I am using a modem (only when I’m on the road – usually I’m on a network). Norton does not detect the presence of a virus of any sort. Can you help me?


  91. You’re probably being attacked, and don’t have the latest patches. Make sure windows is up to date, and if you’re running Windows XP, enable the firewall when on the road.

  92. Hello, i had the same troubles, i love to spit in my machine and i found lsass.exe en dirote.exe, it was hard to delete it, i killed it with ewido security site, search it on Google, and look at your processes after you installed the freeware program, i tried also to rewrite the file dirote.exe after ewido found it in my registry and it succeed, after that I had bought a norton internet security installed and al my problems are now over…can i say with my fingers crossed, and when someone has questions email me, it works and i will help.

    Greetings from the Netherlands.

  93. I’m used to reading English written by the Dutch, since my relatives are all in Holland … but I hopt that “i love to spit in my machine” means something other than it actually says. 🙂

    Leo (Notenboom – a very Dutch name 🙂

  94. Oh Leo,

    Yes i see what you mean, pardon me, i love my machine, and sometimes with troubles i hate him, but i ment to say DIG, look around, yes and Leo a really Dutch name, so i hope my info was interesting enough, bye and in Dutch,

    Een hele goedenavond en tot ziens !!

  95. I have just installed WinXP and the first thing that troubled me is this lsass.exe it forces me to reboot in 60 secs. What will i do? Will the security update solve this problem? Also the svchost, it eats a lot of my cpu power when I stay online for a while, what shall I do with this?
    Thanks for taking time reading this problem.

  96. I also get the lsass.exe error. It either gets to the windows loading screen, then 3 seconds later the blue screen of death and the computer restarts. OR is gets to the windows startup screen and says something about I/O and registry files. I also cannot get into safe mode at all to download the microsoft patch/fix. I was able to do that with my other computer on my network, and everything worked again. I am now trying to use it as a slave w/ another harddrive as my main drive, and it wont even read from the drive. It detects it in BIOS and in windows but all it does is automatically ask me if I want to format it and that is it. Lastly, I also tried fixmbr bootcfg/rebuild and chkdsk drive /r in the recovery console but neither of those worked. Im basically at the last straw here, but I know it can be an easy fix if I can just get into windows or safe mode somehow. Can you help?!?

  97. I have had this problem for a while now. And thanks to you guys i have just figured a way to get rid of it. BUT….. i have reformatted a 2 times since i got this “virus”. Is it possible that this virus stays in the hd even after i reformat? Because thats what happened to me.
    The virus stayed on my hd and in my comp even though i reformated :S. Can someone tell me why this happens or does sasser always do that? Please email me or whatever.

  98. Usually that means you’re getting reinfected immediately on reconnect to the network. Get behind a firewall.

    And to answer your question … no, viruses do not survive a format of your system drive.

  99. thanks for the very straightforward directions. unfortunately i am unable to abort shutdown with ‘shutdown -a’. any advice??

  100. m: what happens when you use “shutdown -a” ? Any error messages? Nothing? Looks like it works but nothing happens? I need some details to try and help you :-).

  101. My computer showed those symptoms a few days ago just after I reformatted so I hadn’t even installed my antivirus. By the time I needed to use yahoo messenger so I installed it first and the problem showed up when I was connected, now I have reformatted again and even after my norton antivirus was up-to-date, problem showed up again. I was using the same yahoo id, so is there a way I can be ‘recognized’ by someone even though they’re supposed not to see me connected so my computer was reinfected deliberately?

  102. This virus spreads from computer to computer automatically. So it’s possible to get reinfected within minutes of simply connecting to the internet. That’s why the article talks about using a firewall. A firewall will protect you from that immediate reinfection. Then you can go about updating and patching your system appropriately.

  103. I just got a notification from Norton Internet Security telling me that a remote computer (IP was attempting to open ‘lsass.exe’. It was recommended by NIS to allow, so I did, not knowing this was possibly related to the virus. Am I infected? Virus Scan says no, but can this be a coincidence?

  104. I’d simply make sure to keep your virus scanning database up to date, and scan regularly. It’s hard to say whether you’ve been infected or not, so I’d simply stay extra cautious for a bit.

  105. After updating Windows XP and then scanning and cleaning a computer with several viruses including the Sasser Worm and Blaster Worm I have lost the Ctrl+Alt+Del task manager function. Also I cant access msconfig or regedit from the Run command anymore. What has been knocked out and how can I fix it? Help!!!


  106. First thing I noticed is on startup, a popup that says: you or a program is trying to access www. .ru (forgot the name of the site but the site doesnt exist) then after a few days the computer starts automaticly connecting to the internet without my authorization and if i hit cancle it does it again in a few minutes. I tried Ad-aware and 4 other simular programs to ditect it but couldnt ditect any spyware. Also I noticed this new prosses: the lsass.exe and the alg.exe and it doesnt let me terminate the lsass.exe, saying that: “This is a critical system process. Task Manager cannot end this process.”

    any suggestions? I need help

  107. Are you up to date on running virus scans? Sounds like a virus. As this article points out, lsass.exe IS a require system component.

  108. nbtstat -R reloads the netbios name cache, not the DNS cache, which is what will stop resolution of web sites.

    ipconfig /flushdns is the command you’ll want.

  109. just i have to got the error message of lsass.exe file and it will reboot after 60 seconds. i tried a lot and i have to make changes in active directory sites and services option and there it will show the replication time and i have change replication. i didn’t get any solution for that. please give me solution of that and just one dialogue box appear and it will restarted and from run if i give command shutdown -a it is not working in windows 2000 server operating system with domain.
    Please kindly inform me the solution of these. first it was restarted within 15 to 20 minutes but now it will restarted after 1 and half day.

    URL Software Pvt. Ltd.

  110. Hi Leo

    I think I am free of the sasser exploit virus but I am not sure. I have a pc with xp professional and a search shows that I have lsass.exe in the following two places locations:
    [1] c:windowssystem32lsass.exe – (size 12K type: application)
    [2] c:windowsservicepackfilesi386lsass.exe – (size:12 type: application.

    On my Laptop with xp home edition, I also have lsass.exe and LSASS.EXE in the following locations:
    [1] c:I386LSASS.EXE – (size: 9k type: EX_file)
    [2] c:windowssystem32lsass.exe – (size: 12k type: application)

    I looked at the host file on my laptop but only saw one line in it for the localhost and it’s relevant IP.

    My problem is I got internet security pro. 2004 and sygate pro firewall, but time and time again I get a message from sygate firewall saying it has blocked a buffer overflow attempt on LSASS.EXE.

    I am concerned if I have the virus and not know about it. I did a scan yesterday and all seems well. I also updated the KB835732 hotfix but I read on the web that LSASS.EXE and lsass.exe are two different files and the capitalised version is a suspect. in otherwords the:
    lsass.exe is innocent
    LSASS.EXE could be a suspicious file and the fact that it doesn’t reside within the windows/sytem directory??

    Can you shed any light on this?

  111. Jon: The other locations for lsass.exe seem fine .. they’re probably in a copy of your installation CD or service pack that’s been copied to your hard drive. The buffer overflow attack is probably a report of an external attempt from the internet to exploit your system. Sounds like your firewall is catching it, as it should.

    For the record, in Windows capitalization does NOT count – lsass.exe and LSASS.EXE are the same.

  112. Thanks Leo

    I got the Lsass.exe mixed up with Lsasss.exe. I copied and pasted a comment from a forum I stumbled across today.

    Lsass.exe is a normal system file on XP. However, it was the target of the Sasser worm and if the system wasn’t up to date on security patches it could have gotten hit by that worm. In fact, if the system isn’t up to date on security patches there are quite a few baddies that will eat it alive.

    Careful of the spelling too since about version #5 of Sasser (W32.Sasser.E.) places a file on the PC called Lsasss.exe (note the extra letter ‘s’).

    If Norton won’t scan she has probably been hit. You can take a look Here and download a removal tool Symantec (Norton) has developed. It should work even if the normal AV won’t run.

    Also be a very good idea to run an online scan at one of the sites that offer the feature. RAV is good.

    Since this now looks pretty much like a virus issue, moving the thread to Security.

  113. Just wondering what the lasting effects of Sasser are. I bought a new laptop and went to windows update to get the patch (ironicaly to protect it from sasser) and in about 10 min of being online got hit. I run a firewall at home so I never had any problems.

    I’m on the road right now and can’t get to my installation disks to reformat and start fresh (with an antivirus program and a firewall). Right now the lap top is powered down with the battery removed, over time will the virus do any more damage?

  114. Once cleaned and patched, there should be no lasting affects. As you note, you definitely want to be running a firewall. On the road, I’d enable XP’s built-in firewall.

  115. Hi there, it appears I’ve been hit with the sasser bug. My problem is that the virus seems to have struck my administrative rights. It is a personal home computer with only one user- me- yet I can’t seem to find the virus with the removal files because it’s hiding in system restore, which I can’t disable because I don’t have “administrative rights”. I’ve been struggling with this one for awhile now, but don’t seem to be able to get over this problem. I can’t restore either, because again I don’t have the right. If you can help, that would be great, thanks!

  116. ok my problems start like this
    I’m browsing the net and then the comp just restarts and says that WinXp has recovered from a serious error. Then a little while later I get a message saying that Remote Procedure call has terminated unexpectedly & shuts down in one min. I thought it was MSBLAST but the Symantec remover tool didn’t find anything. I was on the internet during both cases. I patched up RPC after running the remover.
    Nothing seems wrong until about a week or two later when the computer won’t boot and keeps restarting. I don’t know what’s going on. This has happened two or three times & reinstalling WinXP is the only way out. Please help.

  117. I’d make sure you were behind a firewall … sounds like you’re getting re-infected fairly quickly. Also sounds like you’re not completely patched and/or up to date.

  118. I had troubles with Sasser in June, cleaned my computer and now it’s OK.
    I’m now looking through my computer and find in WindowsPCHealthErrorRepUserDump more than 100 files named : “lsass.exe.20040505-191212-00.hdmp” (264 MB!!!!). Can I delete these files?

  119. I sure would. If you’re at all concerned, first copy them to some off-line storage (i.e. burn them to a CD-ROM) in case for some reason they’d need to be replaced, but it seems unlikely.

  120. I have a runaway task: lsass.exe and I can’t get it to stop. My task manager shows my cpu usage to be a constant 75-100%. Lsass.exe as a process is using 84,904K of memory. I don’t think I am infected with a virus: I have been running updated antivirus and firewall. Are there any known problems with this program other than virus infection? Any help would be greatly appreciated.

  121. All the cases I’ve heard about so far has been virus related – either being infected, or being under attack. So I don’t really have any good answers for you. If that’s a hardware firewall, and there are other machines behind it with you, you might double check that one of them isn’t infected and attacking. Might also be good to use an additional different virus scanner, and double check that you’re up to date at windows update.

  122. hi there, every time i run my virus checker, it runs for so long and then restarts my computer. is there anything i can do to stop it shutting down so as i can run the full virus checker??

  123. I have computer running with Windows 2000 Professional. Now the problem is that, when i start computer it will automatically
    shut down after some time and searched for this is error and it is due to lsass.exe worm problem.
    I am really frustrating of getting this error. I also found that this error due to lsass.exe virus. Is this true? My computer shutdown due to this lsass.exe shutdown error. Suggest me how do fix this lsass.exe error?

    I am very thankful to you if you will suggest me any solution.

  124. I just experienced it a while ago. I dunno if I’m correct but it has got to do something with the window updates. I’ve noticed that everytime I connect to the internet, the windows update shows up on the taskbar and automatically downloads and so is the lsass.exe error message. So what I did, I finished DL-ing the latest windows update first then changed the windows update setting to “notify first blah blah blah” and it worked…. for now.

  125. The short version is that LSASS.EXE is simply one of the files that make up part of the Windows operating system itself. LSASS stands for “Local Security Authority Subsystem Service”. Windows can’t run without it.

  126. I have several protecting programs running, (i.e. Norton’s Internet Security, SpySweeper, Spybot S&D, GhostSurf2005, Adaware, Panda, and Pest Patrol) all of which are updated every few days. None of these seem to be able to detect anything relating to the lsass, but I am constantly getting the system shutdown notice from the lsass file. I barely have time to run them before the pc shuts off, and even when I run them in time, they still do not detect any threats. Help??
    Any ideas would be greatly appreciated.

  127. My guess is that you’re not behind a firewall and or you may be under attack from another machine that is infected. Make sure you’re fully patched, and get behind a firewall if you can.

  128. Hi, Leo

    My problem is different as above comments.

    My Win2K server (SP4) is a DC. When it was set up about 3 years ago, I installed NAV Ver 5.0. After a year, I removed NAV.which made the system un-stable. One year ago, the system started rebooting by itself occasionary. In November ’03, I installed NOD32 AV and found Nimda.E virus. Then AV scan everyday.

    The reboot have carried on for more than a year and show me this error,

    Application exception occurred:
    App: lsass.exe (pid=264)
    When: 2/8/2004 @ 15:44:10.814
    Exception number: c0000005 (access violation)

    I don’t think it was affected by Sasser because it happended before Sasser was found. It rebooted randomly from once two weeks to 3 times a day. No particular process/log happened before the reboot. Then I found lsass.exe caused it.

    I searched the Net but none of them matched my case so far. I guess it could be the result of the removal of Norton AV.

    I did install the MS Sasser update and scanned the system with MS and Norton remove tool. No virus found.

    Any comment would be appreciated.

    Thanks, Yuggie

  129. Given the instability caused by NAV, I’d be really tempted to reinstall Win2k – at least a repair install on top of your existing install. It’s too difficult at this point to really diagnose as there are so many unknowns.

  130. shutdown controls your system shutdown. The “-a” command instructs it to “abort any shutdown already in progress”. When you are ready to realy shutdown or reboot your system, just use the Start menu, Shutdown option as normal.

  131. Dear Leo,
    My friend’s computer had ALL the symptoms of the Sasser worm. We followed your instructiions up to the point of worm removal. She could not find any of the avserve, avserve2, netsky, etc. processes. Her computer no longer shuts down. We installed Stinger which found and destroyed W32/NACHILTFTPD.VIRUS, also referred to as the Natchi worm. I thought this worm was self-destructing January 1, 2004. She now has installed firewall and is updating all her anti-virus applications……YET, I still suspect she has a variant of the Sasser worm there somewhere. Any suggestions?

  132. Norman virus control seems not to recognize the sasser worm regarding lsass.exe
    My company has got a lot a trouble with it,
    and we are considering to use Symantec in the future.


  133. I think I have the sasser virus. I rebooted my laptop this morning and I am now getting the following error: lsass.exe – System Error Object name not found. I cannot get my laptop to boot in normal or safe mode. Do I have any options available to me other than rebooting from the recovery CD and loosing everything on my HD?

  134. hi,i have one problem,my laptop is suddenly shutdown in the middle of the happeninig daily,my work is pending.what is problem.

  135. There are so many possible reasons for this it’s hard to say. Have you done a virus and spyware scan? How does it shutdown: crash, turn off or does it go into standby? What version of Windows? Is Windows fully up to date with patches? Is there any consistancy with what you’re doing at the time it shuts down? Have you added or removed any hardware or software recently?

  136. lsass.exe – unable to locate component
    this application has failed to start because
    LSASRV.dll was not found
    re-installing may fix this problem.

    Any ideas Leo? Thanks for any help!

  137. I have just now managed to recover from the Sasser worm. My antivirus “caught” the worm by deleting lsass.exe. Deleting this caused my computer to be unbootable. I had to use the recovery CD from Dell. I pressed F12 to boot from CD and then I had to press F8 to accept the service agreement. Next I pressed enter not R. On the next page I pressed R to re-install and the healing process began. My data was preserved and twelve and a half hours later my system is functioning again. Six hours of that was re-installing the windows service packs and updates!

  138. As the article says, the “proper patch” is to run an up to date anti-virus program, and to make sure that you have all patches installed from Windows Update.


  140. hi buddy
    this is solutionof LSASS.exe
    write downSpecify Executable Files to be Lauched by Winlogon (Windows NT/2000/XP)
    Category: Home > Security > System

    This tweak can be easily applied using WinGuides Tweak Manager.
    Download a free trial now!

    This setting specifies a list of executable files to be run by Winlogon in the system context when Windows starts.

    Open your registry and find the key below.

    Create a new String value, or modify the existing value called ‘System’ using the settings below.

    Exit your registry, you may need to restart or log out of Windows for the change to take effect.

    (Default) REG_SZ (value not set)
    System REG_SZ “lsass.exe”

    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon

    System Key: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon]
    Name: System
    Type: REG_SZ (String Value)
    Value: (default = lsass.exe)

    mail me

  141. my system shutdowns showing an error that NT authority has initiated the shutdown because of the error in c:windowssystem32lsass.exe

    can you suggest me how to over come this problem?

  142. I have the same problem on windows 2003 SBS….is there any hope to fix without a reload?

    I have the error msg “Lsass.exe “When trying to update a password the return status indicates that the value provided as the current password is not correct”. I can not apply any of the fixes from the “start” “Run” or C prompt as the pc shutsdown and restarts and shutsdown and…..
    before the taskbar has a chance to come up. Is all hope lost? I would be grateful for any advice.

    Posted by: Shelby at July 25, 2005 01:04 AM

  143. I would try rebooting in safe mode, or booting from the CD-ROM into the recovery console. If that doesn’t work, then I’d boot from CD and attempt a repair install.

  144. hi

    my computer before the windows is up is showing the lsass message and then immidiatly reboots so i cant access the start button and stop the shutdown in the way you indicated !!
    what to do?

  145. Gee: You’ll need to boot into safe mode, or boot from floppy or CD and move the file back. It’s a required system component.

  146. Hi,

    I know I was dumb when I went to regedit and deleted all keys related to “lsass”..Now the system crashes … started with only blue screen… I am using Window XP…what should I do?

    Many thanks in advance!


    PS: I am trying to search article in this site but the link is disable…If you dont mind, pls help me this time.

  147. im getting a lsass.exe – unable to locate component
    this application has failed to start because LSASRV.dll was not found. Re-installing the application may fix this problem.

    i get this everytime i turn on my computer and once i click ok the screen just stays black. Starting under safe mode it does the same thing. Could use a little help please.

  148. Anybody can use CA’s e-Trust anti virus, version 7.1 to got rid off lsass.exe

    Just install the s/w and scan ur machine with latest definition file. Ur problem is resolved.


  149. Leo:
    regarding the instruction to lookup hosts file with notepad, mine only works if I enter (Start – Run) C:windows… and then select notepad from the “what to open with” window that pops up. Also, I use SpySweeper which keeps all its list of sites etc – appended with “SpySweeperCSS” – in the hosts file, following the top entry of “local host”.

    I’m using Windows XP Pro SP2.

    Thought you’d like to know. Others may be experiencing the same difficulty, or variation with access through Start/Run menu.



  150. DO NOT DELETE LSASS.EXE it is a vital system component. Follow the recovery instructions from the article you just commented on … which boils down to: run an up-to-date anti-virus scan.

  151. As soon as I run my computer, windows attempts to load and I get the following error, “lsass.exe – Unable to locate component

    This application has failed to start because LSASRV.dll was not found. Re-installing the application may fix this problem.”

    When I click OK the screen goes blank. I cannot get to any XP screen or function; same goes for safe mode boot up, same error. How can I boot up to a cmd screen ?

  152. You need to perform a repair install from your Windows XP CD-ROM. Do not connect to the internet until you’ve run a complete and up-to-date anti-virus scan.

  153. hi Leo i would like to reccomend a simple step for sasser and blaster worm or lsass error when system shuts down, restart the system in safe mode and turn off the port 445, then run stinger and sasser and blaster worm will be removed, to close port 445 one has to go to right click on my computer then click on manage select device manager click on view go to show hidden devices now under non-plug and play drivers select net-bios over TCP/IP right click on it and select disable system needs to restart, this has helped me a lot in troubleshooting sasser worm,

  154. hello i dont know if the comutper has the sasser virus or not but at start up it goies to an error message
    isass.exe system error
    An I/O operation initiated by the registery
    unrecoverable the registry could not read in or read out,or flush one of the filesthat contained the system image of the registy.
    press ok
    then it goes to starting window then restarts the computer a loops like this for a while and every so ofton it will boot up like nothing happens i have a registery fixer did the scan and it comes up with nothing does this sound like the sassy oh yea at first i thought it was a hard drive failure so i replaced that setup windows did all he download of updates and then it stated it
    marcus thanks

  155. Leo,

    ref Gils Post on 27th – I have two laptops both running MS auto updates warnings (all security patches are loaded) and McFee auto updates on the full security centre, I run adware, spywareblaster and spybot on both laptops.
    like Gil’s we just started to have problems around the 27th. One laptop won’t boot up (my son’s)! we try and turn on, it starts Windows then freezes with a windows error box “lsass.exe – system error – insufficient system resources exist to complete the API”

    if we click okay – like Gils – it starts all over again. It just keeps cycling the same error each time windows tries to boot up.

    so I’m confused, I’m computer literate, no reason why the real Lsass should fail overnight, all protective measures in place on both PCs for virus, spyware, malware, but at the roughly the same time as Gil’s problem we also have a problem –

    but it does not match with news – if this was a new problem / variant millions would have been hit by now – and they have not – so !!! is it a fluke / coincidence and I need to reinstall windows ?

  156. Leo,

    One of my Win 2k3 is giving this lsass.exe error with the status code 1073740972. I don’t know why this is happening. It wont even let me in through safemode. It restarts when I try to go on safemode. I got McAfee as my virus scan and ISA as my firewall. What is the port this lsass is getting infected? How to get rid of this situation? I followed your steps and I installed all the hotfixes. I hope I will not get this issue in future after these hotfix installation. But what if I get the problem again? What should I do?


  157. I got LSASS.exe message every time in my windows 2000 prof. system when I’m plugging my internet cable.Pls give suggetion how to rectify that prob. as soon as possible.

    Thanking You,
    SK Rana

  158. My computer completely lost everything. I restores Windows and then purchase McAfee AntiVirus and Firewall. When I try to load both I get this stupid lsass.exe and it won’t let me quaratine, clean or delete. How do I fix?

  159. I would install Windows from scratch, and install both of those programs *before* connecting to the internet or your local network. It sounds like you’re getting infected immediately, so stay disconnected until you’ve got the firewall up and running.

  160. Here is the fix that I have discovered. There are two main differences in the way your computer behaves, I have yet to discover what decides these differences. The first type is the one where your computer comes on but turns back off after about a minute. The second type is the one that most of the past few people have been describing (The one I got as well), which is the error box that comes up right after the XP screen, and clicking OK will cause a reboot. If you have the second type, start from step one, if you have the first type, follow the instructions in the article to delay the shutdown.

    1. Pop in your XP CD-ROM. Boot your computer from that CD-ROM. On the screen that comes up asking what you want to do, select the option to install windows. Follow the instructions, but DO NOT let it format your hard drive. Instead, just install windows a second time to another folder (I put mine in C:Windows2). This will provide you a way to get on your computer to fix your worm virus. Reboot your computer, not from the CD-ROM, but from the Hard Drive, selecting the Windows XP installation that you just installed.

    2. Download the Windows XP patch that will prevent it from finding you again. I cannot stress this enough, this virus seems to reinstate itself on computers that have had it previously, but this patch seems to fix this problem. It can be found at Restart your computer, once again, loading on the second installation of XP.

    3. Run the Symantec W32.Sasser.Worm removal tool. Symantec did a fantastic job of finding a way to get rid of this virus and has made it available for free. You can download it at

    4. Restart your computer, this time try loading your old version of windows XP, it should load without a problem.

    5. In order to make sure you don’t get this virus again, be sure to follow the instructions given in the article about getting AntiVirus and Firewall Programs installed on your computer.

    God Bless!
    – Andy Hudson

  161. I’ve downloaded everything to perform Andy’s fix as listed above. However, my HP machine didn’t come with an XP cd. My manual says “for a small shipping fee, we’ll ship you the cd’s” (?!?!!). So, since I’m in a hurry to fix my pc, and don’t want to wait on HP to ship me the cd’s, can I use XP cd’s that came with an E-machine desktop at work? Or some other brand if I can find one?

  162. I got my hands on an OEM XP cd and was able to boot with it. I was able to go through Andy’s steps to repair the lsass.exe problem, however the Symantec tool didn’t find Sasser (I ran it twice). So I’m back to square one. Any suggestions of other things to try?

  163. I should have read your article closer the first time. I saw your reference to the KIBUV and BOBAX viruses this time. Does anyone have experience removing either of these two? If so did you use Symantec? I use AVG Free, but I haven’t found much evidence that AVG will remove any of the LSASS.exe related viruses.

  164. Hi, I have the second type of this problem as referred to in the Tech Mens fix above; I have followed the procedure for removal to the letter (several times), but with no luck. All of the Anti virus/worm tools including Symantec come up that the system is clear? I have tried deleting the LSASS.exe file from the corrupted version of XP and replacing it from the newly installed XP, but no joy. Any suggestions as to what I can do next would be gratefully received.

  165. Simon, it sounds like we’re working on an identical problem. You mention using Symantec, do you mean you’ve scanned with Norton AntiVirus, or you’ve just used Symantec’s specific Sasser removal tool? The reason I ask is that I was about to go out and purchase Norton.

  166. Murph yes it does sound the same, very frustrating, I have used several Spycatcher, Symantec’s specific Sasser tool, Xoftspy and Microsoft Malicious Software remover tool I have not used Norton yet!!

  167. I have windows xp pro and i just got the message:
    lsass.exe, and It will not boot up, can’t even get to the system to do any work, is there any hope? I was thinking if there’s a way I could download the info to a cd and maybe run it on this computer. any chance of that?
    Any help will be deeply appreciated, if your idea helps, I’ll send you a cool T-shirt

    Dok Washington

  168. I have Windows XP home edition. On start up i get a system error saying lsass.exe “Object name not found” and on pressing OK the machine reboots. This goes on and on. I cant even start in any of the safe modes. I am totally clueless as there is no mention of this error even on Microsofts website. Please help!

  169. Thanks for your prompt reply but my problem is that i cannot access the files at all and thus cannot take back up. The error message appears immediately on windows loading and on pressing OK the machine rebots so there is no way I can take a back up. What are the other ways of taking back up before reinstalling windows? Thank you.

  170. Well, a repair install should install without destroying things. I agree a backup first is advisable, but not always practical. I’d look into and see if you can come up with a disk you can boot from that perhaps woudl allow you to back up across the network.

  171. Ashutosh, it sounds like you’ve got the same problem I’ve got. If you’ll go to page 35 of the posts to this article and follow Andy Hudson’s instructions to install a second copy of XP to Windows2 folder, you’ll be able to find your files that need backing up. You can then burn a cd or save them to a jump drive. You’ll have to enter BIOS by pressing (probably)F1 immediately after startup and set your machine to boot from cd first. I still haven’t got my pc fixed, but I was able to retrieve all my data. If you’ll read this entire article, you’ll find all sorts of good ideas to try, it just seems some infections are harder to recover from. My next step is to format and reinstall.

  172. I have learned a lot from these pages but the instructions do not go all the way for those of us not cumputer “savants.” For example, I can follow the logic of re-installing Windows XP in a different folder to bypass the “lsass.exe” worm virus I somehow got, but it did not tell me SPECIFICALLY how to do this. I am working with a laptop for the first time & it got into some terminology about partions and UNpartitioned space. If someone could walk us ignorant folk on which options to choose and how to actually DO the re-install into a different folder, it would be much more helpful. I will continue to write comments tonight as I try to work through this very inconvenient problem. Thanks for hearing me vent!! —CC in Seattle

  173. Are most of the viruses corporate-based? Dont u think Microsoft and Norton are the biggest viral organization? Its a shifty marketing strategy to create your own enemy and then destroy it!

  174. If you cannot boot into XP you can resintall XP over the top of itself by booting off the CD and using the reapir feature. Conversely, if you have a HP or Compaq you can press F10 on boot up and use the non destructive recovery option to repair Xp. This usually leaves all of your non system files intact


  175. I have been searching the internet for over 3 hours now, (from a laptop that is not suffering from the following)… and no where have I been able to find an answer that shows the fix to the problem: I am UNABLE to access windows through any mode (including, safe, last known good configuration etc….). for once I did not back up my data before shutting down and am now unable to access my computer. I seem unable to locate the c: so that at the very least I could delete lsass.exe through DOS, (NOT the system32 file), but any others. I am a network engineer not a computer engineer so I have a basic-intermediate knowledge of computers. I REALLY need to fix this problem but trying to use a boot disk I am unable to locate my c:, (I am unsure as to whether this is due to me being ignorant or the problem I have or is part of the problem iteself). I recently have had a few viruses, (thanks to the wife, 🙁 ), and I had downloaded hijackthis and a couple of other anti spyware/virus etc programmes. I was running ad-aware and avast antivirus on their own before this. I now have the same problem that others seem to have posted and I am unable to re-install my OS as I no longer have a windows disk. I feel I am in way over my head with this one as I have been changing BIOS settings etc, surely there is a boot disk somewhere that will fix this problem?

    It is the standard error message on boot: : “when trying to update password the return value indicates that the current value provided as the current password is not correct”. The computer then restarts and does the same again.

    If anyone could give me an answer to this I would be very greatful.

    many thanks and kidest regards


  176. Your hard disk is probably formatted NTFS and thus inaccessible to plain old DOS. You’ll need to come up with another boot media that includes NTFS support. You might consider something Knoppix (if you’re Linux literate), or using BartPE to build a boot CD for Windows (using another machine, of course). You might also try, or look for a DOS based NTFS driver that you can add to a normal DOS boot disk.

  177. I see your problem, the reason you cannot access C: from a floppy is because the hard drive is in NTFS format, meaning, it does not support Dos Mode on boot, only through shell from within Windows Xp or better.

    There is a fix though, there are various NTFS bootable files for creating a Disk which emulates NTFS boot, now these arent the best by any means, but they do work, try this link which will hopefully explain what to do,

    Also I see you mention lsass.exe thats a file which Windows makes a lot of reference to, in fact it can render the internet unusable, I dont know a lot about it, unfortunately the hackers do, I dont think deleting it from Dos will resolve the problem, if you need further assistance, please email me and I will try to ellaborate some more.

  178. I apologize if this specific error has been addressed, but a search of the site turned up nothing for the “endpoint format error.”

    A buddy of mine is now experiencing the following error upon bootup of his Dell Dimension 8200 running Windows XP Home: “LSASS.exe System Error – The endpoint format is invalid.”

    There is an OK button displayed in the error-message box. Pressing it reboots the machine before the Windows Desktop is displayed. (So it’s not possible to click Start, Run, shutdown -a.) This error persists in every mode, including Safe Mode.

    I found in the Dell knowledge base an article for restoring LSASS.exe from a Windows installation CD, although the error message in the article is not identical to the one my buddy is experiencing. We tried it, and it failed to resolve the problem. For those Dell owners who have nothing left to lose, here’s the link to the Dell article:

    Has anyone else experienced the endpoint-format version of this error? If so, did you have any luck repairing it?

  179. All my attempts to fix the “LSASS.exe System Error — The endpoint format in invalid” error have failed spectacularly.

    A bit of good news, tho: I booted from the CD dive using a Knoppix CD. I was able to copy all the important data to a portable hard drive. I then formatted and re-installed.

    Nothing like a format & re-install to clear your PC of problems. So, I guess not ALL my attempts to fix the problem failed.

  180. Hey Schnazola! I read your comment about using Knoppix. I am pretty new on the whole Linux system, so I will try it and also hope to save my data from my desktop. I got the “An invalid parameter was passed to a service or function” for the lsass.exe and it is extremely frustrating to not find a quick solution for it. O well.

  181. Hi Leo:

    I am wondering if you know what my computer might be infected with – the symptoms are that my desktop icons simply go out of control every now and then. They open and close as if possessed and the mouse pointer goes out of my control too. It is as if someone is remote controlling my desktop and has made my control ineffectual. After about 15-20 seconds my desktop goes back to normal. But in the process some programs or webpages I was on get shut down.

    Any ideas what could be going on??

    Thanks in advance for any help you can give,


  182. W2K -I deleted the entries for lsass from the registry, don’t ask. I did not delete the file from c:winntsystem32. I replaced all, i believe, the entries but I am getting RPC errors, there are no icons in Networkplaces, It says I have no admin rights to do anything. MC>manage> user & groups won’t run because RPC is not available, net start rpcss does not fix the issue HELP!!! Where can I get a list of entries that I deleted? How do I get RPC back up?

  183. Given that we don’t know everything that’s now happened to your registry, the only think I can suggest it is a reinstall of Windows.

  184. Leo,
    About the LSASS.EXE article. This can be a trojan, but it is also a very necessary Windows component file. No one should delete it without knowing the location as this has a lot to do with whether it is a virus or not. Spyware uses this file, also. Microsoft claims that WinTasks 5.0 can help with this problem.

  185. Ok, so this regards to the lsass.exe error endpoint format is invalid…
    It seems as though I have fixed the problem though it took quite sometime (I use SP2 Win XP Pro)
    1) boot your comp w/ the win xp cd in and repair windows
    2) once there I did a chkdsk /r which took about an hour but found several errors on the disk and fixed them
    3) I rebooted by typing exit but found no error msg but STILL rebooted by itself
    4) tried to reboot into safe mode by pressing F8 but decided to go into debugger mode which is like safe mode i guess..?
    5) installed registry mechanic full ver. on the compe and ran a full deep scan — found over 900 bloody errors on the registry!!!!!!!!!!
    6) rebooted. and work impeccably.
    i hope this helps anyone with this problem, it was not fun and i thought i was gonna lose everything but found a workaround
    Have fun,

  186. My son’s PC was infected by LSASS.EXE. I removed from my system by access the registry (regedit). used the “Find” option under the edit menu and located the all of the key values that contained lsass.exe and deleted them. It solved my problem. Good luck..

  187. Windows is complete garbage, but unfortunately we are almost required to use it nowadays. What the other people say is true; you will end up having to format your HD and install Windows XP again. I had that error before, as well. What none of the Microsoft Techs, or most other advocates of this horrible OS, will tell you is that there is a way to get the data off that you need.

    You use something called a LiveCD / LiveDVD. It is a version of Linux that is booted from the disk itself. You can use it anytime that you would like. Hell, my Windows works fine and I use it my computer occasionally just for kicks. By booting the computer while this disc is in the drive, you can boot into Linux before Windows. This will allow you to use a CD/DVD burner (internal or external) or a flash drive to get all of your data off and onto discs or another computer temporarily. Just be sure that all peripheral devices (including removable media) are plugged in prior to booting into Linux, otherwise Linux may not recognize it.

  188. I clicked on a link in some search results and was immediately notified that a program was trying to access the internet. I blocked it. Still, a program called “lsass.exe” was loaded into my start-up programs. My anti-spyware allowed me to disable them right away. I then ran scans that said my computer is not infected. Still, what a scare. Never click on links and I recommend SpySweeper!

  189. Just don’t use “spyware stormer”… That is how I ended up with the System Error “The endpoint format is invalid”…It deleted registry values, and now my puter is FUBAR.

  190. leo, when I have searched thru and opend the hosts file in note pad, I see somany web addresses there. Many of which are links to porn sites. Does this mean I cant access those sites, I mean; what are the links doing there?

  191. ralph those sites u see in notepad mean you are infected, from what ive read online already, im stuc with similar prob, just dont have that variant !

  192. i had the same virus but my anti virus software disinfected it…all of it. ive done all the checks and nothing seems to be left of the sasser worm. i use panda titanium antivirus software. hope this helps, otherwise the instructions given are accurate in disinfcting your computer.

  193. If your computer keeps booting after your get the lsass.exe error, your security registry hive could be corrupt.

    ****Do This To Fix It****
    You can use your XP disk to boot into recovery mode (recovery mode is just a DOS prompt, there’s no reinstallation), or if you don’t have an XP CD (and you can’t borrow one)


    rename “c:windowssytem32configsecurity” to security.bak

    then copy c:windowsrepairsecurity to the location above.

    This should get you back into your Windows Installation, update your antivirus progam and start a virus scan to make sure the virus has been cleaned. you might have to re-activate your copy of Windows. I did

  194. i had the same problem couple of weeks ago about the message that appears after windows starts. Here’s what i did (by the way im using winxpsp2 on a pc). I simply copied lsass.exe from system32 folder, paste it to windows folder and the error message disappear. I dont know what lsass.exe does but until now i havent encounter any side effects whatsoever, so iguess it works. hope this help.

  195. Everyony should be aware that Lsass is a virus, lsass is Windows system file that has something to do with logging on. Don’t delete it.

  196. how can I do this if my windows would not load anymore.. after boot up, the screen just displays an error message about lsass.exe is restricted then my pc restarts.. this happens again and again.

    Hash: SHA1

    If Windows won’t load, you’ll need to perform an repair
    install of Windows. More here:



    Version: GnuPG v1.4.7 (MingW32)


  198. Thanks for the above article:
    When starting up my laptop I get the Windows loading screen and then I am getting a message prior to Windows login screen. The message box sits on a blue back ground and the header reads “lsass.exe – Application Error”, and the txt in the message box reads “The Application Failed to Initialize Properly (0Xc0000006) Click on OK to Terminate the Application”. When I click “OK” my laptop sits there with a blue screen and nothing happens, but I can see and move the cursor. I know this isn’t a great deal differnt to the other issues posted but it seems like Windows is loading and I am hoping not to have to re-install Windows. Thanks.

  199. If you still get the C:WINDOWSCursorslsass.exe is not found after removing the infection it is because the file has been placed in the registry. If you run regedit (and back it up before changing anything!) Navigate to HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWinlogon. Within this key you will see “Shell”=”Explorer.exe C:\WINDOWS\Cursors\lsass.exe” Delete the C:\WINDOWS\Cursors\lsass.exe portion and exit the registry. hat will stop the popup error on startup.

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.