friends help: lsass.exe Very High Problem… - Help.com

lsass.exe Very High Problem…

Windows XP SP2
Desktop
Custom Built
No Error Messages…
No Odd Smells, Noises etc…
Nothing New Installed…

To my Problem Now

lsass.exe, when i look at the task manager it states & shows that it has a high IO Read/Write…
Am wondering if this is normal…

While playing a game i would normally just DC & totally drop connection from a game, when i looked at my DUMeter it shows that i was “uploading” at 200-500 KB/s (My ISP upload is only maxed at 512KB [50KB/s])…

Do you reckon it’s a virus/hijacker? Because when i was looking at my Net Limiter Pro 2, it states the program path is from c:\wind*\conf*\lsass.exe & Also shows ALOT of connections from one IP…

Anyone know?

P.S. If you need a print screen of any of these add me as a friend i will release my email.

Hopefully Locke could help again?

This open post was written 2 years ago | V/U/S: 2,313, 38, 7 | Edit Post | Leave a reply | Report Post


Reciprocity (0) Reciprocation Failure -- The poster has NOT helped anyone else yet!

Since writing this post iVaz_ may have helped people, but has not within the last 4 days. iVaz_ is a verified member, has been around for 2 years, 1 month and has 25 posts and 277 replies to their name.

Post Tags (10)

Replies (38)

Where were you?

Click and drag to move the map around. FAQ: How we place people on this map »
You can also watch events on Help.com as they happen
Mouse over the map for 2 seconds to see an expanded, interactive view

tricky offline Verified User (3 years) Long Term User Shouts: 39 #
An Unknown Location | 2 years ago (3 minutes after post)

well my isass is 1158 kb so i dont know if it varies and stuff :)…. but i think it is a virus cause once i had that problem too but am not sure …

Quote this reply Report this reply to moderators
Help me with: What If?
Barbyman offline Verified User (2 years, 5 months) Long Term User Shouts: 5 #
An Unknown Location | 2 years ago (44 minutes after post)

maybe someone milking your isp. signal check it out

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (49 minutes after post)

C:\Windows\Config\lsass.exe

Thats the file path being used! how can they milk my ISP? this is upload NOT Download! AND IT”S Beyond my ISP Allowance!

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (1 hour after post)

lsass is a system process located in C:\Windows\System32, but there are a number of trojans, worms, etc that create a file with that name. If you’re seeing it anywhere other than in system32, especially with the kind of activity you’re talking about, it’s probably malware. Run antivirus, antispy, etc; get rid of it.

Quote this reply Report this reply to moderators
This reply has been removed.
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 39 minutes after post)

hold on, but my computer turns off if i cut out the lsass.exe in the c:\windows\config\lsass.exe if i cut the lsass out, it sends me the system is somethin seotmhing, small window pops up in middle of screen with a count down!

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
This reply has been removed.
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 46 minutes after post)

where can i find a original lsass?

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (1 hour, 46 minutes after post)

To abort the shutdown go to start>run and type “shutdown -a” (no quotes).

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 50 minutes after post)

oh yeah… i forgot about that locke, but where can i find a orignal lsass?

please remember its in the “c:\windows\config\lsass.exe”

The the file thats sending out high uploads at very very un common times!

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
This reply has been removed.
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (1 hour, 52 minutes after post)

open windows>system32>drivers>etc>hosts using Notepad. If you have a number of entries you didn’t enter, particularly Microsoft/antivirus sites, you likely have the Sasser worm or a variant which exploits the system similarly. Just update and run antivirus/antispy; that will likely at least verify the problem if not completely fix it.

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 53 minutes after post)

Could you help me here to “http://help.com/post/111433-how-to-list-everything”

127.0.0.1 localhost

thats all i found in the hosts file.

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (1 hour, 54 minutes after post)

That’s good; that’s what is supposed to be there.

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 55 minutes after post)

wait a sec am i meant to have two lsass.exe then?

one in config folder and one in system32?

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (1 hour, 57 minutes after post)

The config folder lsass, I believe, is anomalous. The system32 lsass is the normal one.

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 57 minutes after post)

Config folder = 220KB
System32 Folder = 13.0KB

the config folder the lsass.exe looks like a folder…
in the system32 folder it looks like a windows.

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 58 minutes after post)

the internal name of the lsass.exe in Config Folder is “Leet.exe” version 1.0?

has no description… nothing…

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 hour, 58 minutes after post)

Also if i right click on the program it say “Unregister Application”

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (2 hours, 5 minutes after post)

C:\WINDOWS\Config\lsass.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
C:\WINDOWS\Config\lsass.exe:SummaryInformation

Thats the files i get when i scan lsass.exe in the config folder…

thats with NOD32 (Yes it may suck! but it’s the best one i can get right now)

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (2 hours, 23 minutes after post)

As I said, the config folder lsass is likely malware-associated. It is an “alternate data stream” version of the system32 lsass. If there’s an icon of a handicapped sign in your system tray, by the way, that’s likely Smitfraud malware.

Quote this reply Report this reply to moderators
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (2 hours, 34 minutes after post)

To clarify, you should probably get rid of the oversized lsass.

Quote this reply Report this reply to moderators
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (2 hours, 39 minutes after post)

Seriously; “leet.exe”? I’d somehow overlooked that. That’s actually pretty funny, but you should still ditch it.

Quote this reply Report this reply to moderators
This reply has been removed.
Roulston offline Verified User (2 years, 3 months) Long Term User Shouts: 5 #
Centralia, ON, CA | 2 years ago (9 hours, 23 minutes after post)

I’m with Oldfart on this one.

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (13 hours, 47 minutes after post)

oh… so how do i delete it?

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (14 hours, 45 minutes after post)

You could try simply deleting it, aborting the shutdown, then running a full system antivirus/antispy scan to get rid of any remnants (download spybot and run that along with your nod32 - one solution often discovers problems another misses, and Spybot is both high-quality and free).

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (14 hours, 51 minutes after post)

NOD32, when scanned doesn’t find it as a virus…

If i try to normally delete it “select it and press delete” it says “Cannot Delete Access Denied” may be in use ……..

Ill try Spybot. Thanks Locke.

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (14 hours, 57 minutes after post)

End the process via task manager if possible; then it won’t be in use. If you can’t end it, perhaps it doesn’t run in Safe Mode.

Quote this reply Report this reply to moderators
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (14 hours, 58 minutes after post)

If Spybot detects it in any case, it will remove it when you restart your system before lsass has a chance to run, anyway.

Quote this reply Report this reply to moderators
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (15 hours, 21 minutes after post)

Can not end task in task manager, i tried that 100 times! i got two lsass.exe in task manager, one from User & one for System.

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (15 hours, 50 minutes after post)

Spybot didn’t delete the lsass.exe OMG!

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (17 hours, 26 minutes after post)

If it detected it but didn’t delete it, it will likely do so when you restart your system. Anyway, you can, one way or another, delete the rogue lsass file, even if you have to do so through recovery console - but I am not conversant with alternate data streams, and I’m not sure if the system will be able to locate the correct file once the rogue lsass is gone. Ad-aware does recognize and search alternate data streams, but I have no idea whether it will fix your problem.

One thing you can do is go to start>run>regedit. Hit ctrl+f, type lsass, hit enter (and keep on doing this until regedit doesn’t find any more entries). Each time regedit finds an entry, look under the “data” column at the right of the screen and see if it lists a path. If it does, it should be “%SystemRoot%\system32\lsass.exe”. If the path is different (it should not point to the config folder), right-click and modify it so that it reads “%SystemRoot%\system32\lsass.exe” (no quotes). If you had to change anything, registry was pointing your system to the rogue lsass file instead of the correct one - and unless the malware modifies your registry on system start, after restarting you should be able to safely eliminate the bad file. I’ll take a fresh look if it isn’t fixed by tomorrow.

Quote this reply Report this reply to moderators
Locke offline Verified User (2 years) Long Term User Shouts: 1 #
Niceville, FL, US | 2 years ago (17 hours, 28 minutes after post)

There should actually be a backslash after the second % and after system32 in the path I listed, FYI. This site doesn’t like backslashes, it seems, and removes them automatically in the post.

Quote this reply Report this reply to moderators
This reply has been removed.
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (23 hours, 18 minutes after post)

Hey Locke, thanks mate! everything turned out fine, i did the registry fix my self, as spybot didn’t even find the lsass entry at all.

Quote this reply Report this reply to moderators
Help me with: How to rhyme?
This reply has been removed.
iVaz_ offline Verified User (2 years, 1 month) Long Term User Shouts: 1 #
Melbourne, 07, AU | 2 years ago (1 day, 14 hours after post)

Oldfart, i may be stupid but not slow…

And i already fixed this problem.

Quote this reply Report this reply to moderators
Help me with: How to rhyme?

Invite Others to Help

A logged in and verified Help.com member has the ability to setup a Friends List and invite others to help with posts.