Lsass.exe

G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.general (More info?)

How do I get rid of this. Norton Antivirus won't detect it version 2004 (up
to date).
Microsoft's fix tool doesn't work. Symantec's fix tool doesn't work.
Bitdefender didn't touch it. It resides in my XP Home system file and hogs
the Cpu 98% when I use IE>Tools>Internet options>Content>Auto Complete>Clear
forms> OK. I have to close IE to kill it. Any suggetions. Spy Sweeper was
suggested to me. Any thoughts on that?
--
Computers give me a headache!
 
Archived from groups: microsoft.public.windowsxp.general (More info?)

Further to my first message, when doing a search for lsass (small L) I find
LSASS.EX_ in Windows/I386 and lsass.exe in Windows\system32, and
LSASS.EXE-20DB6D1B.pf in Windows\Prefetch. What's all this? Are any the
worm affecting my CPU?
--
Computers give me a headache!


"Raymond T." wrote:

> How do I get rid of this. Norton Antivirus won't detect it version 2004 (up
> to date).
> Microsoft's fix tool doesn't work. Symantec's fix tool doesn't work.
> Bitdefender didn't touch it. It resides in my XP Home system file and hogs
> the Cpu 98% when I use IE>Tools>Internet options>Content>Auto Complete>Clear
> forms> OK. I have to close IE to kill it. Any suggetions. Spy Sweeper was
> suggested to me. Any thoughts on that?
> --
> Computers give me a headache!
 
Archived from groups: microsoft.public.windowsxp.general (More info?)

"Raymond T." <RaymondT@discussions.microsoft.com> wrote in message
news:97346C57-B625-4E33-B89B-642C0C238912@microsoft.com...
> How do I get rid of this. Norton Antivirus won't detect it version 2004
> (up
> to date).
> Microsoft's fix tool doesn't work. Symantec's fix tool doesn't work.
> Bitdefender didn't touch it. It resides in my XP Home system file and
> hogs
> the Cpu 98% when I use IE>Tools>Internet options>Content>Auto
> Complete>Clear
> forms> OK. I have to close IE to kill it. Any suggetions. Spy Sweeper
> was
> suggested to me. Any thoughts on that?
> --
> Computers give me a headache!

It's a system file isn't it? You won't be able to get rid of it. It's
needed.

From Google:


lsass - lsass.exe - Process Information
Process File: lsass or lsass.exe
Process Name: Local Security Authority Service

Description:
lsass.exe is a system process of the Microsoft Windows security mechanisms.
It specifically deals with local security and login policies.

Note: lsass.exe also relates to the Windang.worm, irc.ratsou.b, Webus.B,
MyDoom.L, Randex.AR, Nimos.worm which spread via floppy disk drives,
mass-mailing and peer-to-peer sharing. Please review file path for
clarification of this.


begin 666 count.php?key=load
M1TE&.#=A`0`!`/<``````/______________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
M____________________________________________________________
A_____________________RP``````0`!```(`P`#```[
`
end
 
Archived from groups: microsoft.public.windowsxp.general (More info?)

I don't know. I am puzzled because it acts like a virus and uses 98% cpu.
It didn't do this when I first got this new computer in 11/04 but has caused
this problem for the last month or two as best I can recall. I find info
saying its a worm and other info saying it's not as you found. Can't seem to
get a clear answer.
--
Computers give me a headache!


"Rich" wrote:

>
> "Raymond T." <RaymondT@discussions.microsoft.com> wrote in message
> news:97346C57-B625-4E33-B89B-642C0C238912@microsoft.com...
> > How do I get rid of this. Norton Antivirus won't detect it version 2004
> > (up
> > to date).
> > Microsoft's fix tool doesn't work. Symantec's fix tool doesn't work.
> > Bitdefender didn't touch it. It resides in my XP Home system file and
> > hogs
> > the Cpu 98% when I use IE>Tools>Internet options>Content>Auto
> > Complete>Clear
> > forms> OK. I have to close IE to kill it. Any suggetions. Spy Sweeper
> > was
> > suggested to me. Any thoughts on that?
> > --
> > Computers give me a headache!
>
> It's a system file isn't it? You won't be able to get rid of it. It's
> needed.
>
> From Google:
>
>
> lsass - lsass.exe - Process Information
> Process File: lsass or lsass.exe
> Process Name: Local Security Authority Service
>
> Description:
> lsass.exe is a system process of the Microsoft Windows security mechanisms.
> It specifically deals with local security and login policies.
>
> Note: lsass.exe also relates to the Windang.worm, irc.ratsou.b, Webus.B,
> MyDoom.L, Randex.AR, Nimos.worm which spread via floppy disk drives,
> mass-mailing and peer-to-peer sharing. Please review file path for
> clarification of this
 
Archived from groups: microsoft.public.windowsxp.general (More info?)

From: "Raymond T." <RaymondT@discussions.microsoft.com>

| How do I get rid of this. Norton Antivirus won't detect it version 2004 (up
| to date).
| Microsoft's fix tool doesn't work. Symantec's fix tool doesn't work.
| Bitdefender didn't touch it. It resides in my XP Home system file and hogs
| the Cpu 98% when I use IE>Tools>Internet options>Content>Auto Complete>Clear
forms>> OK. I have to close IE to kill it. Any suggetions. Spy Sweeper was
| suggested to me. Any thoughts on that?
| --
| Computers give me a headache!

Your post makes NO sense !

You don't get rid of legititimate files unless you can show that they are indeed
illegitimate files.

You are saying that it runs at 98% ? Well it is a system file and it must be determined if
what is causing LSASS.EXE to have such a high utilization.

The following can be used to scan your system in case it is a an Internet worm that has
exploited a vulnerability in LSASS that hasn't been patched yet.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, this PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove
viruses and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE and/or FTP.EXE to go
through your FireWall to allow them to download the needed AV vendor related files.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm