Lsass.exe - testmy.net resource / tool
Home
Welcome, Guest. Please login or register.
Did you miss your activation email?

 



donations help testmy.net pay for the very high cost to run the site. Any amount is greatly appreciated.
Click to read why...

  spcr
    
News : Before you post... try a Why don't you search? - Many simple questions have already been answered.  If your query turns up dry then post, we always have people waiting for your questions. azn December 03, 2008, 02:44:49 PM
testmy.net Broadband  |  Main Forum  |  HELP!  |  HELP! With Other Stuff  |  Topic: Lsass.exe Advanced search

Recommended Tests

Click here to run a free Performance Scan
  Test PC Performance:
     Click here to run a free Performance Scan
    Test PC Stability:
     Click here to run a free Registry Scan


Note: The links above are sponsored links
  0 Members and 1 Guest are viewing this topic. « previous next »
Pages 1 2 3 4 5 6 7 8 ... 42 Go Down
Author
Sticky Topic Topic: Lsass.exe  (Read 103933 times)
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« on: June 13, 2005, 07:40:59 PM »

I finally got the lsass.exe plague Saturday!!!!!!!!!!!!! The little window that pops up and tells you "Object Name Not Found" If clicked OK or X it out it will reboot. I did find out that if you wait maybe ten minutes or so that when you close the window it will not reboot. Still a pain. Sunday I went down and bought XP Pro and installed it and guess what? It's still there!!!!!!!!!!!!!!!!! Any ideas on how to rid myself of this pest?????????????? Mad Question Question Question Question Question angry5 angry5 angry5 angry5 angry3 angry3 angry3
Logged
peepnklown
Expert
*
Offline Offline

Gender: Male
Posts: 1312


Rabbi Minarchist


View Profile WWW
« Reply #1 on: June 13, 2005, 07:59:59 PM »

lsass.exe = Local Security Authority Service
It is a system process.

It can relate to the Windang.wrom, irc.ratsou.b, Webus B, MyDoom L, Randex AR, Nimos.wrom (so even if you removed these worms lsass.exe is a system process)
Logged

DEAD NUMBER 339 = Experimental Music
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #2 on: June 13, 2005, 10:12:17 PM »

Well, I have scanned my puter every which way but sideways including in safe mode. Can't find any virus. If I could just get rid of the dialogue box and not the lsass.exe for sure, then I would be in good shape!!!!!!!!!!!!!! confused4 confused4 confused4 confused4 confused3 confused3 confused3 confused2 confused2 confused2
Logged
helloimtim
Guest
« Reply #3 on: June 14, 2005, 12:40:25 AM »

I would guess there is something in your start up that would cause this. Start up inspector is a handy little free program that will tell you what is starting when your machine does. Hit the consult button and It will tell you what is important and what is not. Here is a link. http://www.windowsstartup.com/  You can disable the start up process useing this program as well. Alot of people will tell you to use msconfig. I do not recomend doing that unless your 100 percent sure you know what your doing You may by acident kill a start up that windows needs. Have you tried hijack this? Thats a really cool program. After you run it you can do 1 of 2 things. Post the log results in a forum and have someone read them. Or there are 2 auto mated sites that will read them for you and suggest what to delete. If you wish I can give you the links. I have used the automated sites for a year or more. Did what they recomended deleting and never crashed windows once.
Logged
peepnklown
Expert
*
Offline Offline

Gender: Male
Posts: 1312


Rabbi Minarchist


View Profile WWW
« Reply #4 on: June 14, 2005, 01:05:57 AM »

If you are using Windows XP you can disable all of the start up programs (using msconfig) without harming anything.
Logged

DEAD NUMBER 339 = Experimental Music
cholla
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2843


View Profile
« Reply #5 on: June 14, 2005, 11:42:45 AM »

69 RAT: I don't have XP but I did some web surfing here are some links that might help
http://www.2-spyware.com/file-lsass-exe.html
http://www.enigmasoftwaregroup.com/affiliate/link.php?ref=42&productid=4
http://www.computing.net/cgi-bin/AT-search.cgi?mode=concept&search=Lsass.exe&forum=WindowsXP&sp=sp&x=28&y=3
Logged
helloimtim
Guest
« Reply #6 on: June 14, 2005, 04:26:01 PM »

I should of said that a bit diffrent but still think the same. If your not sure what you are doing I really really dont recomend playing with msconfig. While yes chaning the startup will not hurt a thing. Some may tend to think they need to play with the boot files. That could turn into a bad thing. That is why I always try to stear thoes that are unsure away from msconfig.
Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #7 on: June 14, 2005, 04:43:28 PM »

Sounds like a sasser variant to me.  Heres a link to info on it.  http://vil.nai.com/vil/content/v_125008.htm#Symptoms
download and use this to scan and clean it out: http://download.nai.com/products/mcafee-avert/s-t-i-n-g-e-r.exe
If that doesn't work there is a manual workaround on the first link above. 
Sasser is a pain in the butt but I've removed it from a couple of systems.  If you want, watch the processes under ctrl+alt+delete then processes tab.  If you end the random numbered processes, more will appear.  avserve2.exe is the primary process, but the random processes also will restart avserve2.exe.  If you're quick enough, you can stop the shut down process.  Some systems boot, then auto shutdown within 30 seconds or so of the bootup.  EDIT:  This is what I had to do with one system that needed cleaning...........
« Last Edit: June 14, 2005, 04:49:59 PM by cak46 » Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #8 on: June 14, 2005, 07:05:47 PM »

Wow!!!! So much info!!!! Thank you all!!!!!!!  A little recap- I do have the latest S-t-i-n-g-e-r from McAfee and no virus, I have run all virus removal tools from McAfee and no virus. I ran a full system scan in safe mode-nothing. The weird thing is that this started on Saturday when I had XP Home and was still there on Sunday AFTER installing XP Pro!!!!! I also have a great utility called TUT (The Ultimate Troubleshooter) from Answers That Work.com, I think that's the URL. Anyhow, this program explains almost all tasks and services and startups that you have going on at any given time. It then suggests what to do, like delete or disable or don't touch, etc. I can't live without it!!!!!!!!!!!!!!! You do not need to go to Msconfig when you have this. There are tons of other things you can do from this utility. Check it out. In the meantime, I will keep everybody informed as I have just started a case right now with Microsoft on this Lsass.exe issue and they will getting back to me within 24 hrs. PS: Boot INI files, aw, no thanks not a place for me to go!!!!!!!!!!!!!!! Exclamation Exclamation Exclamation  Cak46-I checked and I do not have Avserve2.exe, not in windows or my registry : Smile Smile
« Last Edit: June 14, 2005, 07:36:41 PM by 69 RAT » Logged
netmasta
Inactive Moderator
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2879


Comcast 6Mb/384Kb using Firefox


View Profile WWW
« Reply #9 on: June 14, 2005, 07:35:17 PM »

From searching on http://support.microsoft.com, ity sounds like it could be related to the Sasser worm. More info here: http://www.microsoft.com/security/incident/sasser.mspx
Logged

Click here and here before posting speed related problems. These topics can be very useful.


Always remember, 'It could be worse'.
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #10 on: June 14, 2005, 07:41:45 PM »

From searching on http://support.microsoft.com, ity sounds like it could be related to the Sasser worm. More info here: http://www.microsoft.com/security/incident/sasser.mspx
Thought I already said that.... Rolling Eyes
Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #11 on: June 14, 2005, 08:02:29 PM »

Well, I just ran Microsoft's Malicious Software Removal Tool and came up with nada. Sad I sure hope that Microsoft comes  up with a suggestion that we're all not thinking about.  :!:Wow, what a learning curve that would be!!!!!!!!!! ;);) This issue is all over the net.  Exclamation :!:The LAST thing I wan't to hear from them is " You'll have to do a clean install" :haha: :haha: :haha: Not!!!!!!!!!!!  Shocked Shocked Shocked Shocked
« Last Edit: June 14, 2005, 08:06:47 PM by 69 RAT » Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #12 on: June 14, 2005, 08:06:42 PM »

If you want, download and run a scan with hijackthis then post the results.  Might be able to see something running at start up.
Edit:  Link to download hijackthis.... http://www.majorgeeks.com/download3155.html
« Last Edit: June 14, 2005, 08:12:05 PM by cak46 » Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #13 on: June 14, 2005, 08:13:59 PM »

OK, I'll give it a try. Back soon icon_study icon_study
Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #14 on: June 14, 2005, 09:27:43 PM »

StartupList report, 6/14/2005, 8:49:37 PM Exclamation I already got rid of "House Call Control" It is not something that I'm familiar with at all  Exclamation
StartupList version: 1.52.2
Started from : C:\Program Files\HIJACK\hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HIJACK\hijackthis\HijackThis.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Logitech Utility = Logi_MwX.Exe
MCUpdateExe = C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
MCAgentExe = c:\PROGRA~1\mcafee.com\agent\mcagent.exe
MPFExe = C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
VirusScan Online = "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
VSOCheckTask = "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=9vs7sxtxnn585u.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}

--------------------------------------------------

Enumerating Task Scheduler jobs:

McAfee.com Update Check (DAVE-Martine).job

--------------------------------------------------

Enumerating Download Program Files:

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

[{13E23C9E-3018-4AC1-B998-C08BF1814DB0}]
CODEBASE = http://ftp.gurunet.com/pub/cabs/GNInstaller.cab

[iCC Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\pcpConnCheck.dll
CODEBASE = http://www.pcpitstop.com/internet/pcpConnCheck.cab

[{3334504D-9980-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/0/C/8/0C8EDFAB-30BC-4792-898E-2DABE27B2C4D/mp43dmo.CAB

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB

[Microsoft.WinRep]
InProcServer32 = C:\WINDOWS\System32\Winrep.dll
CODEBASE = https://webresponse.one.microsoft.com/OAS/ActiveX/winrep.cab

[McAfee.com Operating System Class]
InProcServer32 = C:\WINDOWS\system32\mcinsctl.dll
CODEBASE = http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab

[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\xscan53.ocx
CODEBASE = http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab

[DwnldGroupMgr Class]
InProcServer32 = C:\WINDOWS\system32\McGDMgr.dll
CODEBASE = http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
End of report, 6,920 bytes
Report generated in 0.016 seconds

Command line options:
   /verbose  - to add additional info on each section
   /complete - to include empty sections and unsuspicious data
   /full     - to include several rarely-important sections
   /force9x  - to include Win9x-only startups even if running on WinNT
   /forcent  - to include WinNT-only startups even if running on Win9x
   /forceall - to include all Win9x and WinNT startups, regardless of platform
   /history  - to list version history only
« Last Edit: June 14, 2005, 09:59:06 PM by 69 RAT » Logged
Print  Pages 1 2 3 4 5 6 7 8 ... 42 Go Up
testmy.net Broadband  |  Main Forum  |  HELP!  |  HELP! With Other Stuff  |  Topic: Lsass.exe « previous next »
Jump to:  

    
testmy.net's forum is proudly Powered by SMF | SMF © 2006-2007, Simple Machines LLC
Bookmark: Del.icio.us    StumbleUpon
 
 

 

© 1999-2008 testmy.net - Contact - Legal - Facts & FAQs
Page Loading Stats: This forum Page created in 0.149 seconds with 54 queries.