A remote administration utility which bypasses normal security mechanisms to secretly control a program, computer or network.
Small.H duplicates file names and processes of legitimate Windows applications.Windows Task Manager does not show distinctive details:
In order to determine the Small.H processes from the Windows processes, an enhanced Task Manager is needed. Process Explorer, freeware from Sysinternals, is one such application.
Note: This is a Third Party application, the link below will direct you away from F-Secure's website.
Find the latest advice in our Community Knowledge Base.
See the manual for your F-Secure product on the Help Center.
Submit a file or URL for further analysis.
Small.H is a virus with an internal spamming engine and backdoor functionality. Please see the sections below for more details.Small.H, originally named lsass.exe, spreads itself using an internal spaming-engine that is controlled through a previously set-up backdoor.It fools the user into executing its exe file by using a Windows folder icon and file names such as:
Small.H creates several copies of itself:
It creates a number of autostart keys in the registry such as: