Lsass.exe - testmy.net resource / tool
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
Home
Download Test
Test Your Download Speed
Test Download AND Upload
Upload Test
Test Your Upload Speed
Test Upload AND Download
Community Forum
Community Forum Home
» Log-In
» Register
Internal Search
Google Powered Search
Computer & Net Guides
ISP Discussion
Forum Sitemap
Member List
Forum Stats
Forum Help and Info
Calendar & Birthdays
Database Stats
Host Stats
Member Stats
Share Score
Misc Tools
Conversion Calc.
Speed Chart
Conversion Table
Create a Test
Share Score
Automatic Test
Forum Archive
RSS and Blog Feeds
Score Database
trace/ping/whois/DNS
Wallpapers
Tweak Guide
!! Forum Search !!
!! Google Search !!
TMN Detailed Sitemap
News
News Home
Join
Theme
See Theme List
America the Beautiful
Blacken
Dark Blood Red
Blue
Blue Black Box
Blue Gray
Brown
Christmas
Dark Blue
ekaf
GL Series (default)
Gray Shades
Original Feel
Green
Greenhouse
Greenhouse Gray
Halloween Theme
Orange
Purple Darkness
Red/pink
Red 'n Black
TurkeyDay!
» Neuron (Default)
Neuron Black
Rise (New!)
Click to read why...
News
: Have you seen the guides section? It's an always growing section with tons of cool guides for subjects you might not even know about, check it out... it's a good read
December 03, 2008, 02:43:44 PM
testmy.net Broadband
|
Main Forum
|
HELP!
|
HELP! With Other Stuff
| Topic:
Lsass.exe
Recommended Tests
Test PC
Performance:
Click here to run a free Performance Scan
Test PC
Stability:
Click here to run a free Registry Scan
Note: The links above are sponsored links
0 Members and 1 Guest are viewing this topic.
« previous
next »
Topic Tools
Search this topic
Pages
1
2
3
4
5
6
7
8
9
...
42
Author
Topic: Lsass.exe (Read 103931 times)
helloimtim
Guest
Re: Lsass.exe
«
Reply #15 on:
June 15, 2005, 01:23:24 AM »
Try these 2 links. They are safe and really work great. I have trusted both for over a year and I have no idea how to read hijack this logs. Both sites do the for you. Never crashed my xp once.
http://www.hijackthis.de/
or
http://www.help2go.com/modules.php?name=HJTDetective
Logged
cak46
TMN Friend
Offline
Gender:
Posts: 996
Re: Lsass.exe
«
Reply #16 on:
June 15, 2005, 02:20:21 PM »
69Rat: Since you're working with MS, might want to show them this entry
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=9vs7sxtxnn585u.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll
Here is information on what the appinit_dlls does. Could possibly be the problem.
http://support.microsoft.com/default.aspx?scid=kb;en-us;197571
I'll continue to research......
Edit: Some viruses are know to use this entry in the registry to load on boot. Try searching for 9vs7sxtxnn585u.* with find/seach for files and see what comes up and where it is. Link for some information on viruses associated with this registry entry.....
http://www.google.com/search?hl=en&lr=&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&q=AppInit_DLLs+virus&btnG=Search
BTW: Make sure if you have rebooted since last hijackthis that you run it again and make sure the file name hasn't changed for this registry entry....
«
Last Edit: June 15, 2005, 05:15:27 PM by cak46
»
Logged
cholla
TMN Veteran
Offline
Gender:
Posts: 2843
Re: Lsass.exe
«
Reply #17 on:
June 15, 2005, 04:34:24 PM »
69 rat &cak46 I put in this link
http://www.enigmasoftwaregroup.com/affiliate/link.php?ref=42&productid=4
I tried it & it was a DL for Spy Hunter version 2.0.1086 the site said it would get rid of the
Lsass.exe.I ran it on my OS but I do not have the Lsass.exe virus so I can't say it will remove it .It looked like just another anti spyware program to me.
One thing I found said don't delete Lsass.exe from the system 32 folder
Logged
cak46
TMN Friend
Offline
Gender:
Posts: 996
Re: Lsass.exe
«
Reply #18 on:
June 15, 2005, 04:50:18 PM »
Quote from: cholla on June 15, 2005, 04:34:24 PM
69 rat &cak46 I put in this link
http://www.enigmasoftwaregroup.com/affiliate/link.php?ref=42&productid=4
I tried it & it was a DL for Spy Hunter version 2.0.1086 the site said it would get rid of the
Lsass.exe.I ran it on my OS but I do not have the Lsass.exe virus so I can't say it will remove it .It looked like just another anti spyware program to me.
One thing I found said don't delete Lsass.exe from the system 32 folder
Cholla: I don't think lsass.exe per se is running on your ME machine. I think it's an NT only program. Yeah, if you delete that program, you would be in a world of hurt. It's what authenticates (authorizes) you for access to files, etc for your machine. See:
http://www.iamnotageek.com/a/lsass.exe.php
for details.....
Logged
cholla
TMN Veteran
Offline
Gender:
Posts: 2843
Re: Lsass.exe
«
Reply #19 on:
June 15, 2005, 05:09:14 PM »
cak46 I didn't think it was on my ME but since I had DL a new anti spyware program I ran it anyway.It didn't find anything so I guess spybot & adaware are taking care of spyware alright for my os. Because some members were saying how good Kaspersky is I went to their site.The have a beta web search scan(this is not the same thing as their onlie scan for a single file) anyway it scans your pc for viruses like you had the Kaspersky program it just does it online.I ran it twice & it found zero viruses so I guess my AVG is finding everything.
Logged
cak46
TMN Friend
Offline
Gender:
Posts: 996
Re: Lsass.exe
«
Reply #20 on:
June 15, 2005, 05:15:05 PM »
Quote from: cholla on June 15, 2005, 05:09:14 PM
cak46 I didn't think it was on my ME but since I had DL a new anti spyware program I ran it anyway.It didn't find anything so I guess spybot & adaware are taking care of spyware alright for my os. Because some members were saying how good Kaspersky is I went to their site.The have a beta web search scan(this is not the same thing as their onlie scan for a single file) anyway it scans your pc for viruses like you had the Kaspersky program it just does it online.I ran it twice & it found zero viruses so I guess my AVG is finding everything.
Good deal. I've never seen a registry entry like the one 69Rat has. Very odd. All those .dll's on the end of the file name are very suspicious.
Logged
cholla
TMN Veteran
Offline
Gender:
Posts: 2843
Re: Lsass.exe
«
Reply #21 on:
June 15, 2005, 05:25:08 PM »
cak46 I haven't had the chance to look around in a xp registry but I never found anything like that in 98 or ME.I had a trojan that got in with a DL called Zipitfast an unzipping program.
I did some research & found that stinger would get rid of it in safe mode.Thats when I got stinger & it worked.I don't remember the name of the trojan now .
Logged
cak46
TMN Friend
Offline
Gender:
Posts: 996
Re: Lsass.exe
«
Reply #22 on:
June 15, 2005, 05:49:30 PM »
Quote from: cholla on June 15, 2005, 05:25:08 PM
cak46 I haven't had the chance to look around in a xp registry but I never found anything like that in 98 or ME.I had a trojan that got in with a DL called Zipitfast an unzipping program.
I did some research & found that stinger would get rid of it in safe mode.Thats when I got stinger & it worked.I don't remember the name of the trojan now .
It looks like that option was available as far back as win95, according to the MS KB article. Self-replicating viruses using RPC and other exploits are the worst. One virus I remember propogated between machines as fast as the virus could create random ip's and send itself out. In a matter of 30 seconds I went from 20 clean machines to 10 at work. Luckily, I had mostly '98 machines and the virus was built for nt2000 or above. Can't remember which one it was, but it was quick and efficient. Used Stinger to get rid of it, like you got rid of yours.
Logged
philp
Guest
Re: Lsass.exe
«
Reply #23 on:
June 15, 2005, 06:08:49 PM »
You guys should check this page out:
http://www.answersthatwork.com/
Click "Task List", click the "L" and then scroll down to "lsass".
Not saying it will fix anything, just saying it should be read first.
«
Last Edit: June 15, 2005, 06:11:01 PM by philp
»
Logged
cak46
TMN Friend
Offline
Gender:
Posts: 996
Re: Lsass.exe
«
Reply #24 on:
June 15, 2005, 06:19:31 PM »
Philp: That's a great resource! It looks like his lsass.exe is referenced correctly, only difference being that the lsass is not capitalized in his HJT list. Do you think that is significant?
Logged
69 RAT
TMN Friend
Offline
Gender:
Posts: 324
Re: Lsass.exe
«
Reply #25 on:
June 15, 2005, 06:36:38 PM »
Hey guys. Ya answersthatwork.com is the program that I was talking about. I have it and it is VERY helpful with MANY different things. It's called TUT ( The Ultimate Troubleshooter) I was also VERY suspicious about my entry that had all those dlls tagged on the end. Highjack This says that generally Trojan types use this for their dll initiation. I will copy and paste onto my mail to MS today.My first info from MS today was to try 3 different things. Enable Windows Firewall, Check for updates with McAfee and clear my restore points
I have run a full system scan in safe mode, I have the latest updates for my firewall and anti-virus and clearing the restore points didn't do anything, so for now I will at least send them the dll info cause I think there is something going on there that could help all of us understand this lsass.exe thing a little better
The irony is that this file MUST stay intact for us to use.
I ran a search for lsass.exe and came up with 4 files. Two are with SPack and one is for downloading purposes and of course the main one,,,,,,,,,,,,,,,stay tuned
Logged
69 RAT
TMN Friend
Offline
Gender:
Posts: 324
Re: Lsass.exe
«
Reply #26 on:
June 15, 2005, 06:46:41 PM »
Just a note: TUT says that if you have lsass.exe in your startups then you have a virus. Mine runs right where it's supposed to, in the tasks and the path is correct...............
Logged
cak46
TMN Friend
Offline
Gender:
Posts: 996
Re: Lsass.exe
«
Reply #27 on:
June 15, 2005, 06:57:14 PM »
Quote from: 69 RAT on June 15, 2005, 06:46:41 PM
Just a note: TUT says that if you have lsass.exe in your startups then you have a virus. Mine runs right where it's supposed to, in the tasks and the path is correct...............
Agreed. You can disable the funky registry entry in msconfig without deleting it. It would be a good idea to backup your registry first if you decide to do this..
Logged
69 RAT
TMN Friend
Offline
Gender:
Posts: 324
Re: Lsass.exe
«
Reply #28 on:
June 15, 2005, 07:18:39 PM »
Well, at least I have never found lsass.exe in my startups anywhere. I'm composing a letter to MS right now and I copied and pasted that goofy looking dll dlll...... thing in there to give them something to think about
Logged
69 RAT
TMN Friend
Offline
Gender:
Posts: 324
Re: Lsass.exe
«
Reply #29 on:
June 16, 2005, 07:32:06 PM »
Well-update, maybe. I told Microsoft yesterday that I had run an HT scan and that it had a suspicious multiple dll listing in the log. Well, they wrote me back and said to go ahead and download HT and run a scan/log and send it to them
Ah, HELLO, Microsoft, how did I run the scan if I didn't have HT in the first place>???
After I got done laughing I went ahead and sent them the same thing that I posted here in this forum. Sometimes I think that I am a day ahead of them
;) ;) ;)
Logged
Pages
1
2
3
4
5
6
7
8
9
...
42
testmy.net Broadband
|
Main Forum
|
HELP!
|
HELP! With Other Stuff
| Topic:
Lsass.exe
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Main Forum
-----------------------------
=> General Discussion
=> New Members
=> PC Security
===> Antivirus & Firewalls
===> Spyware & Malware
===> Viruses & Scams
===> Security Threats
=> Show off your scores!
=> Make it Faster...
=> HELP!
===> HELP! With Other Stuff
===> HELP! With Tests
===> HELP! With Forum
===> Programming and Website Help
=====> HTML
=====> PHP
=====> PERL
=====> Server Help
===> Networking and Hardware
===> Overclocking
===> Linux Help
=> News
===> testmy.net News and Updates
=> Online Gaming Discussion
===> Requests
===> America's Army
===> Battlefield
===> Call Of Duty 4
===> Counter-Strike 1.6
===> Counter-Strike : Source
===> Day of Defeat : Source
===> Diablo
===> F.E.A.R
===> Ghost Recon
===> Halo 2
===> Lineage 2
===> Quake
===> Rainbow Six 3
===> World of Warcraft
===> Tribes 2
===> Unreal Tournament
=> Graphics, Sigs and Pictures
===> Test Board
=> Guides
=> Got any ideas to make testmy.net better?
=> Off Topic Discussion
===> Politics & More
-----------------------------
Provider Discussion and Reviews
-----------------------------
=> Add a Provider
=> All Dial-up
=> North American Providers (Including Canada)
===> Canadian Providers
=====> teksavvy.com Canada
=====> xplornet.com Canada
=====> Persona Internet
=====> Rogers Communications
=====> Shaw Communications
=====> Sympatico (Bell Canada)
===> Adelphia Communications
===> ALLTEL Communications
===> AOL
===> AT&T
=====> SBC Global
=====> BellSouth
===> Cable One
===> Cavalier Telephone cavtel.net
===> cebridge.net
===> CenturyTel
===> Charter Communications
===> Clearwire
===> Comcast Cable Communications
===> Country Cablevision
===> Covad communications
===> Cox Communications
===> DMAX Puerto Rico
===> EarthLink
===> EMBARQ
===> Frontier Online
===> HughesNet (DIRECWAY)
=====> DW4000 Information
=====> DW6000 Information
=====> DW7000 Information
===> Insight Broadband
===> Mediacom Communications
===> Midcontinent Communications
===> mycingular.net
===> Namesco/NDO (ndo.com)
===> onelinkpr.net Puerto Rico
===> Optimum Online
===> Qwest Communications
===> RCN
===> RoadRunner (Time Warner Cable)
===> seidata.com
===> sigecom.net
===> SkyWay USA
===> Speakeasy
===> Sprint Nextel Corporation
===> Starband
===> Suddenlink
===> SureWest Communications
=====> SureWest Communications FIOS
===> SusCom - Susquehanna Communications
===> TDS - Telephone and Data Systems, Inc
===> Transedge.com
===> Verizon Online
===> Verizon Online FIOS
===> Wave Broadband
===> Wide Open West
===> Wildblue Communications, Inc
=> World Providers (Non-North American)
===> African Providers
===> Asian and Middle Eastern Providers
=====> Asian Providers
=====> Centennial
=====> Digitel
=====> PLDT myDSL
=====> Sify Broadband
=====> Streamyx
=====> Smart Bro (Wi-fi)
===> Australian Providers
=====> Digiplus
=====> Optusnet
=====> Telstra Bigpond
===> UK and European Providers
=====> Bredbandsbolaget
=======> Bredbandsbolaget Fiber
=======> Bredbandsbolaget ADSL, VDSL
=====> Virgin.net (old NTL)
=====> Tiscali
===> Central/South American Providers
-----------------------------
Miscellaneous
-----------------------------
=> Archives
===> Announcements
=> Public Polls
===> Not on index
Print
Advanced search
Loading...
testmy.net's forum is proudly
Powered by SMF
|
SMF © 2006-2007, Simple Machines LLC
© 1999-2008 testmy.net -
Contact
-
Legal
-
Facts & FAQs
Page Loading Stats: This forum Page created in 0.121 seconds with 54 queries.