Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
10/15/2008 10:11:00 PM EDT
I have a pop up from my zonealarm firewall for:

LSA Shell (exporter version)

Source IP:  151.13.145.246:port500

this is the programs first attempt to access the internet.


Located in :  C:\\WINDOWS\systems32\lsass.exe

Size of file:  13 KB

Is this program the correct version and not a spware version?
10/15/2008 10:13:17 PM EDT
[#1]
On my copy of Vista Home Premium 64 bit, C:\Windows\System32\lsass.exe is 11kb, but it IS a Microsoft file...
10/15/2008 10:14:10 PM EDT
[#2]
Do you have anti-virus software, and is it current (most important part)?

This could be a virus, so sayeth google.

ETA:  That IP is in Italy.  Chances are quite high you have a virus.
10/15/2008 10:17:57 PM EDT
[#3]
running avast, occasional scans with SD, housecall and ewido.

thats why I was asking because I did get the warning that malware was designed to look like this.  Any way to tell them apart?

file was last modified 4/13/2008 at 20:12:24
10/15/2008 10:24:09 PM EDT
[#4]

Quoted:
Do you have anti-virus software, and is it current (most important part)?

This could be a virus, so sayeth google.

ETA:  That IP is in Italy.  Chances are quite high you have a virus.


All right any info on what it could be?
10/15/2008 10:25:24 PM EDT
[#5]
It is (or is supposed to be) the Local Security Authority Subsystem Service.

I can't tell from what you posted if ZoneAlarm blocked an incoming request from that address, or an outgoing request. In other words, I can't tell which machine originated the request - yours, or that address in Italy.

I suspect it blocked an incoming request. If not, and this was originated from your machine, I'd be...concerned.
10/15/2008 10:27:15 PM EDT
[#7]
might be a worm
10/15/2008 10:27:37 PM EDT
[#8]
What OS is this, out of curiosity?

EDIT: Nevermind. You have XP.
10/15/2008 10:30:18 PM EDT
[#9]
Apparently MS has a tool to remove the worm...
support.microsoft.com/kb/841720

You should be able to run that with no ill effects, though we don't know what OS you're running... that's not a vista tool.
10/15/2008 10:32:18 PM EDT
[#10]

Quoted:
file was last modified 4/13/2008 at 20:12:24


You have the right version. Don't worry about it.

ZoneAlarm blocked an incoming request to port 500 (which lsass.exe listens on). The Windows firewall (or even a simple router doing NAT) would have blocked this just as well as ZoneAlarm, and without bugging you with useless annoying messages in a misguided attempt to justify it's miserable existence.

Some dude in Italy is port scanning, looking for vulnerabilities. Don't worry about it.
10/15/2008 10:38:30 PM EDT
[#11]

Quoted:
It is (or is supposed to be) the Local Security Authority Subsystem Service.

I can't tell from what you posted if ZoneAlarm blocked an incoming request from that address, or an outgoing request. In other words, I can't tell which machine originated the request - yours, or that address in Italy.

I suspect it blocked an incoming request. If not, and this was originated from your machine, I'd be...concerned.


zonealarm is asking me if this program is ok to be a server, so I believe its on my computer.  

I went to the web site another poster linked to and I have a shit ton of IPs listed there.  I opened run and typed Notepad \windows\system32\drivers\etc\hosts  I am going through them but I have not found any anti virus sites listed that would indicate a sasser hit me.  My computer has been running fairly normal, with the exception of ar15.com going down on me occasionally.

edit read that page wrong, it is coming from outside my computer.
10/15/2008 10:49:41 PM EDT
[#12]

Quoted:

Quoted:
It is (or is supposed to be) the Local Security Authority Subsystem Service.

I can't tell from what you posted if ZoneAlarm blocked an incoming request from that address, or an outgoing request. In other words, I can't tell which machine originated the request - yours, or that address in Italy.

I suspect it blocked an incoming request. If not, and this was originated from your machine, I'd be...concerned.


zonealarm is asking me if this program is ok to be a server, so I believe its on my computer.  

I went to the web site another poster linked to and I have a shit ton of IPs listed there.  I opened run and typed Notepad \windows\system32\drivers\etc\hosts  I am going through them but I have not found any anti virus sites listed that would indicate a sasser hit me.  My computer has been running fairly normal, with the exception of ar15.com going down on me occasionally.

edit read that page wrong, it is coming from outside my computer.


Again, the version you have is fine. It's correct. It's the actual Microsoft version.

And no, there is no reason (for you) to have it act as a server. And again, there's no reason to have ZoneAlarm bugging you needlessly with bullshit like this. I swear they do this to trick people into thinking it's "doing something".

I do it for a living, I don't run Zone Alarm, never have, and neither does any other IT professional I personally know (help desk monkeys don't count).
10/15/2008 10:52:11 PM EDT
[#13]
Hope you don't mind help from a computer girl..........  


"lsass.exe" is the Local Security Authentication Server. It verifies the validity of user logons to your PC/Server. It generates the process responsible for authenticating users for the Winlogon service. This process is performed by using authentication packages such as the default Msgina.dll. If authentication is successful, Lsass generates the user's access token, which is used to launch the initial shell. Other processes that the user initiates inherit this token.

Note: The lsass.exe file is located in the folder C:\Windows\System32. In other cases, lsass.exe is a virus, spyware, trojan or worm!


There are three at least three viruses that use either this exact file name or a darn similar one:

   * W32.Nimos.Worm
   * W32.Sasser.E.Worm (Lsasss.exe)
   * W32.HLLW.Lovgate.C@mm


If you need to, the backup copy of lsass.exe can be found on your original Windows install disk in the folder F:\i386\lsass.ex_ (I'm guessing that "F:" is the identification of your CD/DVD drive. If not, use "E:" or similar as required).

Because the backup copy is compressed, you need to copy the .ex_ file into your System32 folder, then rename it from ".ex_" to ".exe".



My lsass.exe file size is 12.0 KB (12,288 bytes),  Vista Home Premium 32 bit with SP1.  File version -- 6.0.6001.18000 and is in the proper folder.
10/15/2008 10:54:13 PM EDT
[#14]
where did you learn the version number Subnet?
10/15/2008 10:56:46 PM EDT
[#15]

Quoted:
where did you learn the version number Subnet?


Updated/patched copy of XP Pro I've got running in a virtual machine.

EDIT: He didn't post the version number, but the size is right, and so is the modified time (down to the second).
10/15/2008 11:00:30 PM EDT
[#16]
the internetz IS serious business

way out of my paygrade with some of this stuff, thanks guys for the help!
10/15/2008 11:11:04 PM EDT
[#17]

Quoted:

Quoted:

Quoted:
It is (or is supposed to be) the Local Security Authority Subsystem Service.

I can't tell from what you posted if ZoneAlarm blocked an incoming request from that address, or an outgoing request. In other words, I can't tell which machine originated the request - yours, or that address in Italy.

I suspect it blocked an incoming request. If not, and this was originated from your machine, I'd be...concerned.


zonealarm is asking me if this program is ok to be a server, so I believe its on my computer.  

I went to the web site another poster linked to and I have a shit ton of IPs listed there.  I opened run and typed Notepad \windows\system32\drivers\etc\hosts  I am going through them but I have not found any anti virus sites listed that would indicate a sasser hit me.  My computer has been running fairly normal, with the exception of ar15.com going down on me occasionally.

edit read that page wrong, it is coming from outside my computer.


Again, the version you have is fine. It's correct. It's the actual Microsoft version.

And no, there is no reason (for you) to have it act as a server. And again, there's no reason to have ZoneAlarm bugging you needlessly with bullshit like this. I swear they do this to trick people into thinking it's "doing something".

I do it for a living, I don't run Zone Alarm, never have, and neither does any other IT professional I personally know (help desk monkeys don't count).


Gee Mr Sub.,
You're feeling very generous and altruistic this morning!
Carry on, My good Man.
10/15/2008 11:13:35 PM EDT
[#18]
Delete it.


Just kidding...