Whenever I see lsass.exe when used with Reveton, it is not infected. It is just rundll32.exe renamed so that an untrained eye cannot pick it up in the startup. If you open up the properties of the file, you will see that it still even says "Run Dll as an app" in the description. In my cases, it is still running exe/dll from the %temp% dir. Check properties of ctfmon shortcut to verify next time you see it. You will see that it starts up lsass.exe in the same way that rundll32.exe is invoked, then starts the file from %temp% with an argument.
but perhaps lsass.exe is used to load the malware, all copys i get from lsass.exe are only removed to the new folder and are clean
is this a pc you have at home or is it in a forum? if yes, can you post perhaps the link