Fig: Location of lsass file in Windows
This type of network problem is most often caused by a virus called lsass. The original file is present in window\system 32\folder. In normal circumstances only one service of lsass should be executed i.e; default of windows. But moment when more than one service of lsass starts executing it would result in anetwork problem. This is nothing but a virus in the system similar to lsass file in windows/ system32 folder. In this situation, system behaves normally if anyone checks the ping response but internet would not open, unable to access mail server, other shared data & network printer. To identify this see window task manager ->processes if more than one prcocesses of lsass is executing then it is a virus. Another way, see the behaviour of icon of two smalll computers in startupbar resembling connectivity. If both are glowing simultaneously & constantly without any changes & problem is occuring then it means that it is affected by lsass virus. To resolve use systemrestore & update antivirus. Even third party combofix can also remove this virus but it cannot give gurantee because it deletes all files which it considers as virus which can result in loss of users useful data. To use combofix take backup of all important files & data.
Fig: Under normal circumstances only one process of lsass should be running
No comments:
Post a Comment