Lsass.exe - testmy.net resource / tool
Home
Welcome, Guest. Please login or register.
Did you miss your activation email?

 



donations help testmy.net pay for the very high cost to run the site. Any amount is greatly appreciated.
Click to read why...

  spcr
    
News : undecided Is blue NOT your favorite color?  Well why not customize testmy.net to your liking?!  We offer over 25 theme variations, there is sure to be at least one that suits your personal style, choose one here cool December 02, 2008, 03:06:00 AM
testmy.net Broadband  |  Main Forum  |  HELP!  |  HELP! With Other Stuff  |  Topic: Lsass.exe Advanced search

Recommended Tests

Click here to run a free Performance Scan
  Test PC Performance:
     Click here to run a free Performance Scan
    Test PC Stability:
     Click here to run a free Registry Scan


Note: The links above are sponsored links
  0 Members and 1 Guest are viewing this topic. « previous next »
Pages 1 2 3 4 5 6 7 8 9 ... 42 Go Down
Author
Sticky Topic Topic: Lsass.exe  (Read 103692 times)
helloimtim
Guest
« Reply #15 on: June 15, 2005, 01:23:24 AM »

Try these 2 links. They are safe and really work great. I have trusted both for over a year and I have no idea how to read hijack this logs. Both sites do the for you.  Never crashed my xp once.   http://www.hijackthis.de/  or  http://www.help2go.com/modules.php?name=HJTDetective 
Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #16 on: June 15, 2005, 02:20:21 PM »

69Rat:  Since you're working with MS, might want to show them this entry
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=9vs7sxtxnn585u.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll
Here is information on what the appinit_dlls does.  Could possibly be the problem.
http://support.microsoft.com/default.aspx?scid=kb;en-us;197571
I'll continue to research......

Edit:  Some viruses are know to use this entry in the registry to load on boot.  Try searching for  9vs7sxtxnn585u.*  with  find/seach for files and see what comes up and where it is.   Link for some information on viruses associated with this registry entry..... http://www.google.com/search?hl=en&lr=&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&q=AppInit_DLLs+virus&btnG=Search
BTW:  Make sure if you have rebooted since last hijackthis that you run it again and make sure the file name hasn't changed for this registry entry....
« Last Edit: June 15, 2005, 05:15:27 PM by cak46 » Logged
cholla
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2843


View Profile
« Reply #17 on: June 15, 2005, 04:34:24 PM »

69 rat &cak46 I put in this link http://www.enigmasoftwaregroup.com/affiliate/link.php?ref=42&productid=4
I tried it  & it was a DL for Spy Hunter version 2.0.1086 the  site said it would get rid of the
Lsass.exe.I  ran it on my OS but I do not have the Lsass.exe  virus   so I can't say it will remove it .It looked like just another anti spyware program to me.
One thing  I found said don't delete Lsass.exe  from the system 32 folder
Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #18 on: June 15, 2005, 04:50:18 PM »

69 rat &cak46 I put in this link http://www.enigmasoftwaregroup.com/affiliate/link.php?ref=42&productid=4
I tried it & it was a DL for Spy Hunter version 2.0.1086 the site said it would get rid of the
Lsass.exe.I ran it on my OS but I do not have the Lsass.exe virus so I can't say it will remove it .It looked like just another anti spyware program to me.
One thing I found said don't delete Lsass.exe from the system 32 folder
Cholla:  I don't think lsass.exe per se is running on your ME machine.  I think it's an NT only program.  Yeah, if you delete that program, you would be in a world of hurt.  It's what authenticates (authorizes) you for access to files, etc for your machine.  See: http://www.iamnotageek.com/a/lsass.exe.php for details.....
Logged
cholla
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2843


View Profile
« Reply #19 on: June 15, 2005, 05:09:14 PM »

cak46 I didn't think it was on my ME but since I had DL a new anti spyware program I ran it anyway.It didn't find anything so I guess spybot & adaware are taking care of spyware alright for my os. Because some members were saying how good Kaspersky is I went to their site.The have a beta web search scan(this is not the same thing as their onlie scan for a single file) anyway it scans your pc for viruses like you had the Kaspersky program it just does it online.I ran it twice & it found zero viruses  so I guess my AVG is finding everything.
Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #20 on: June 15, 2005, 05:15:05 PM »

cak46 I didn't think it was on my ME but since I had DL a new anti spyware program I ran it anyway.It didn't find anything so I guess spybot & adaware are taking care of spyware alright for my os. Because some members were saying how good Kaspersky is I went to their site.The have a beta web search scan(this is not the same thing as their onlie scan for a single file) anyway it scans your pc for viruses like you had the Kaspersky program it just does it online.I ran it twice & it found zero viruses so I guess my AVG is finding everything.
Good deal.  I've never seen a registry entry like the one 69Rat has.  Very odd.  All those .dll's on the end of the file name are very suspicious.
Logged
cholla
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2843


View Profile
« Reply #21 on: June 15, 2005, 05:25:08 PM »

cak46 I haven't had the chance to look around in a xp registry but I never found anything like that in 98 or ME.I had a trojan that got in with a DL  called Zipitfast an unzipping program.
I did some research & found that stinger would get rid of it in safe mode.Thats when I got stinger & it worked.I don't remember the name of the trojan now .
Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #22 on: June 15, 2005, 05:49:30 PM »

cak46 I haven't had the chance to look around in a xp registry but I never found anything like that in 98 or ME.I had a trojan that got in with a DL called Zipitfast an unzipping program.
I did some research & found that stinger would get rid of it in safe mode.Thats when I got stinger & it worked.I don't remember the name of the trojan now .
It looks like that option was available as far back as win95, according to the MS KB article.  Self-replicating viruses using RPC and other exploits  are the worst.  One virus I remember propogated between machines as fast as the virus could create random ip's and send itself out.  In a matter of 30 seconds I went from 20 clean machines to 10 at work.  Luckily, I had mostly '98 machines and the virus was built for nt2000 or above.  Can't remember which one it was, but it was quick and efficient.  Used Stinger to get rid of it, like you got rid of yours.
Logged
philp
Guest
« Reply #23 on: June 15, 2005, 06:08:49 PM »

You guys should check this page out: http://www.answersthatwork.com/

Click "Task List", click the "L" and then scroll down to "lsass".

Not saying it will fix anything, just saying it should be read first.
« Last Edit: June 15, 2005, 06:11:01 PM by philp » Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #24 on: June 15, 2005, 06:19:31 PM »

Philp:  That's a great resource!  It looks like his lsass.exe is referenced correctly, only difference being that the lsass is not capitalized in his HJT list.  Do you think that is significant?
Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #25 on: June 15, 2005, 06:36:38 PM »

Hey guys. Ya answersthatwork.com is the program that I was talking about. I have it and it is VERY helpful with MANY different things. It's called TUT ( The Ultimate Troubleshooter) I was also VERY suspicious about my entry that had all those dlls tagged on the end. Highjack This says that generally Trojan types use this  for their dll initiation. I will copy and paste onto my mail to MS today.My first info from MS today was to try 3 different things. Enable Windows Firewall, Check for updates with McAfee and clear my restore points Exclamation I have run a full system scan in safe mode, I have the latest updates for my firewall and anti-virus and clearing the restore points didn't do anything, so for now I will at least send them the dll info cause I think there is something going on there that could help all of us understand this lsass.exe thing a little better Exclamation The irony is that this file MUST stay intact for us to use. Exclamation I ran a search for lsass.exe and came up with 4 files. Two are with SPack and one is for downloading purposes and of course the main one,,,,,,,,,,,,,,,stay tuned
Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #26 on: June 15, 2005, 06:46:41 PM »

Just a note: TUT says that if you have lsass.exe in your startups then you have a virus. Mine runs right where it's supposed to, in the tasks and the path is correct...............
Logged
cak46
TMN Friend
*
Offline Offline

Gender: Male
Posts: 996


View Profile
« Reply #27 on: June 15, 2005, 06:57:14 PM »

Just a note: TUT says that if you have lsass.exe in your startups then you have a virus. Mine runs right where it's supposed to, in the tasks and the path is correct...............
Agreed.  You can disable the funky registry entry in msconfig without deleting it.  It would be a good idea to backup your registry first if you decide to do this..
Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #28 on: June 15, 2005, 07:18:39 PM »

Well, at least I have never found lsass.exe in my startups anywhere. I'm composing a letter to MS right now and I copied and pasted that goofy looking dll dlll...... thing in there to give them something to think about Exclamation
Logged
69 RAT
TMN Friend
*
Offline Offline

Gender: Male
Posts: 324


View Profile
« Reply #29 on: June 16, 2005, 07:32:06 PM »

 Exclamation Well-update, maybe. I told Microsoft yesterday that I had run an HT scan and that it had a suspicious multiple dll listing in the log. Well, they wrote me back and said to go ahead and download HT and run a scan/log and send it to them Exclamation Exclamation Exclamation Exclamation Exclamation  Ah, HELLO, Microsoft, how did I run the scan if I didn't have HT in the first place>??? :haha: :haha: After I got done laughing I went ahead and sent them the same thing that I posted here in this forum. Sometimes I think that I am a day ahead of them Exclamation Exclamation Exclamation Exclamation ;) ;) ;)
Logged
Print  Pages 1 2 3 4 5 6 7 8 9 ... 42 Go Up
testmy.net Broadband  |  Main Forum  |  HELP!  |  HELP! With Other Stuff  |  Topic: Lsass.exe « previous next »
Jump to:  

    
testmy.net's forum is proudly Powered by SMF | SMF © 2006-2007, Simple Machines LLC
Bookmark: Del.icio.us    StumbleUpon
 
 

 

© 1999-2008 testmy.net - Contact - Legal - Facts & FAQs
Page Loading Stats: This forum Page created in 0.121 seconds with 54 queries.