Network and Classroom Management Thread, Lsass.exe and Lssas.exe in Technical; Found both of these in our WINNT/System32 folder. The Alerter service on our DC appears to be pointed to Lssas.exe. ...
-
29th October 2007, 01:26 PM #1
- Rep Power
- 12
Lsass.exe and Lssas.exe
Found both of these in our WINNT/System32 folder. The Alerter service on our DC appears to be pointed to Lssas.exe. The Alerter service on our replica points to SCVHost.
A bit of research looks like the Lssas.exe is a nasty piece of work and shouldn't be there. A trojan variant of GrayBird.
Should Alerter be using SCVHost as opposed to the proper Lsass.exe?
We're also completely unable to ping our DC. It tells us it's connected to the switch fine, the switch says its fine yet we can't reach it?! Any suggestions. It has a fixed IP and being the DC has all the DNS and DHCP stuff on it.
Ta
Nick "head scratching" Davies
-
-
IDG Tech News
-
29th October 2007, 02:00 PM #2 Re: Lsass.exe and Lssas.exe
On W2k3 SP2:
Code:
C:\WINDOWS\system32\svchost.exe -k LocalService
-
-
30th October 2007, 01:43 PM #3
- Rep Power
- 12
Re: Lsass.exe and Lssas.exe
turns out someone has loaded several services onto our dc to do with the counterstrike game. we've actually this morning just caught a remote user on it, trying to install more services and transferring stuff via an open ftp connectoin......first thing..pull the plug!
dear oh dear.
-
-
30th October 2007, 02:31 PM #4 Re: Lsass.exe and Lssas.exe
So your network has been compromised?
-
-
30th October 2007, 03:53 PM #5
- Rep Power
- 12
Re: Lsass.exe and Lssas.exe
Looks like it. We're working through cleaning it up offline. But how can we ever be sure...there's so many processes running!
-
-
30th October 2007, 04:19 PM #6 Re: Lsass.exe and Lssas.exe
You can't. You must rebuild your systems from known good backups and/or scratch. Also, contact your LEAs audit department. They have people for helping you with this.
-
SHARE:
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules