+ Post New Thread
Results 1 to 6 of 6
Network and Classroom Management Thread, Lsass.exe and Lssas.exe in Technical; Found both of these in our WINNT/System32 folder. The Alerter service on our DC appears to be pointed to Lssas.exe. ...
  1. #1

    Join Date
    May 2007
    Location
    Hale Barns
    Posts
    211
    Thank Post
    39
    Thanked 8 Times in 2 Posts
    Rep Power
    16

    Lsass.exe and Lssas.exe

    Found both of these in our WINNT/System32 folder. The Alerter service on our DC appears to be pointed to Lssas.exe. The Alerter service on our replica points to SCVHost.

    A bit of research looks like the Lssas.exe is a nasty piece of work and shouldn't be there. A trojan variant of GrayBird.

    Should Alerter be using SCVHost as opposed to the proper Lsass.exe?

    We're also completely unable to ping our DC. It tells us it's connected to the switch fine, the switch says its fine yet we can't reach it?! Any suggestions. It has a fixed IP and being the DC has all the DNS and DHCP stuff on it.

    Ta

    Nick "head scratching" Davies

  2. #2

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,807
    Thank Post
    110
    Thanked 583 Times in 504 Posts
    Blog Entries
    1
    Rep Power
    224

    Re: Lsass.exe and Lssas.exe

    On W2k3 SP2:
    Code:
    C:\WINDOWS\system32\svchost.exe -k LocalService

  3. #3

    Join Date
    May 2007
    Location
    Hale Barns
    Posts
    211
    Thank Post
    39
    Thanked 8 Times in 2 Posts
    Rep Power
    16

    Re: Lsass.exe and Lssas.exe

    turns out someone has loaded several services onto our dc to do with the counterstrike game. we've actually this morning just caught a remote user on it, trying to install more services and transferring stuff via an open ftp connectoin......first thing..pull the plug!

    dear oh dear.

  4. #4

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,807
    Thank Post
    110
    Thanked 583 Times in 504 Posts
    Blog Entries
    1
    Rep Power
    224

    Re: Lsass.exe and Lssas.exe

    So your network has been compromised?

  5. #5

    Join Date
    May 2007
    Location
    Hale Barns
    Posts
    211
    Thank Post
    39
    Thanked 8 Times in 2 Posts
    Rep Power
    16

    Re: Lsass.exe and Lssas.exe

    Looks like it. We're working through cleaning it up offline. But how can we ever be sure...there's so many processes running!

  6. #6

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,807
    Thank Post
    110
    Thanked 583 Times in 504 Posts
    Blog Entries
    1
    Rep Power
    224

    Re: Lsass.exe and Lssas.exe

    You can't. You must rebuild your systems from known good backups and/or scratch. Also, contact your LEAs audit department. They have people for helping you with this.

SHARE:
+ Post New Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •