XP Process Question

Discussion in 'Software' started by zimbo, Aug 8, 2005.

  1. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    hi guys


    just wondering if someone could tell me what the the lsass.exe does... im running xp pro and it attempted to get and outbound port and nortons blocked it anyone know what this process does? or if it even is a process :twisted: :ohmy

    thanks
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  2. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Here you go. PS. Google is your friend.

    http://www.liutilities.com/products/wintaskspro/processlibrary/lsass/

    EDIT: I thought a little more info might be helpful:

    http://www.iamnotageek.com/a/lsass.exe.php
     
    Certifications: A+ and Network+
  3. hkymre

    hkymre Nibble Poster

    76
    1
    34
    According to google newsgroups

    lsass.exe = LSA Shell (Export Version) or Local Security Authority Service


    lsass - lsass.exe - Process Information
    Process File: lsass or lsass.exe
    Process Name: Local Security Authority Service


    Description:
    lsass.exe is a system process of the Microsoft Windows security mechanisms.
    It specifically deals with local security and login policies, and is NOT to be confused with the lsas.exe virus.


    Author: Microsoft Corp.
    Part Of: Microsoft Windows Operating System
    --------------


    Local Security Authentication Server


    What does it do?
    It generates the process responsible for authenticating users for the Winlogon service. This process is performed by using authentication packages such as the default Msgina.dll. If authentication is successful, Lsass generates the user's access token, which is used to launch the initial
    shell. Other processes that the user initiates inherit this token.


    You will not be able to end this through task manager!
    ---


    Note: The lsass.exe file is located in the c:\windows\System32 folder. In other cases, lsass.exe is a virus, spyware, trojan or worm!
     
    Certifications: ECDL, ITIL Green Badge
    WIP: A+, Advanced ECDL
  4. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181

    in other words guys it should not be there and it should not ask for access to outbound ports therefore I NEED TO REMOVE IT?
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  5. Phoenix
    Honorary Member

    Phoenix 53656e696f7220 4d6f64

    5,749
    200
    246
    its always there, cant say i know if it needs outbound access or not, im sure your norton would of detected it as a virus if it wasnt the true version, although, being norton, it might of missed it! lol
     
    Certifications: MCSE, MCITP, VCP
    WIP: > 0
  6. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    well i just updated nortons... clean up my registry... and ill scan with nortons.. otherwise everything looks okay to me! :rolleyes:
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  7. ffreeloader

    ffreeloader Terabyte Poster

    3,661
    106
    167
    Have you just run windows update, or installed anything related to logon or security policies? If you have the file may have been changed and that's why Norton is now asking permission for it. Also, make sure what you're reading as lssass.exe is actually a small cap L and not a Capital I (i). They are almost impossible to tell apart on the computer screen.

    Do a search for issass.exe and see if anything shows up. It's a virus.
     
    Certifications: MCSE, MCDBA, CCNA, A+
    WIP: LPIC 1
  8. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    tell me what you think from the screen shot... yeah i did some updates i think cause i reinstalled windows XP...

    and i did a search for that using hidden files included and nothing came up... scan with nortons 2005 after just updating and im clean (HOPEFULLY!!)
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  9. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Where is that? :blink
     
    Certifications: A+ and Network+
  10. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    sorry the image was big and it didnt upload... :) there now..
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  11. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Sure looks like lsass.exe to me.
     
    Certifications: A+ and Network+
  12. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    trip is that an L or I ???? :cry:
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics
  13. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Lower case "L".
     
    Certifications: A+ and Network+
  14. zimbo
    Honorary Member

    zimbo Petabyte Poster

    5,215
    99
    181
    phew :thumbleft so its normal... :biggrin
     
    Certifications: B.Sc, MCDST & MCSA
    WIP: M.Sc - Computer Forensics

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.