Problem with lsass.exe windows xp firewall disabled

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Base, Oct 25, 2005.

  1. Base

    Base Private E-2

    Hello,

    I would like to ask for help on this forum. I have a big problem with my acer laptop at the moment. I have looked on this forum for simular problem but i can't get the problem fixed. Pease help.

    This is my problem:
    At first i got a cmd.exe window poping up followed by a explorer window with info on sidebar. When i closed both, my internet connection went down. After running a lot of spyware scans as suggested on this forum i found out that the windows firewall and automatic update where disabled. No possibility to enable the firewall. I can enable automatic updates but after a while this gets disabled again. Also i found some files on c:\ (don't know the exact names anymore) 1 had an icon like a tool. I deleted the files and after al kinds of scans i restarted the system. After restarting the same thing happened again. I tried to disabable lsass.exe as suggested on one of the other threads here but that couldn't be done. Microsoft anti spyware suggested to quarantine lsass.exe but that did not solve the problem. I found out that i have a lsass.exe file in c:\windows and in c:\windows\system32 but i cannot see the one in the windows directory altough hiddenfile view is enabled.

    For now i neutralized the problems by installing zonealarm and not letting anything happen unless i say so. This works for now but the problem is still on my computer.

    I would be great if i could get some help here. If you need more info from me please contact me.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .

    If you really do have lsass.exe running from c:\windows, that is bad. You may have a similar problem as covered in a couple threads here recently. One of them was

    http://forums.majorgeeks.com/showthread.php?t=75387

    You will see bad service named: Local Security Authority Subsystem Service in that thread.
     
  3. Base

    Base Private E-2

    I have done all the scans as advised.

    All scans could be done.

    Only spybot found threats:
    - Windows security center.antivirusnotify
    - Windows security center.antivirusoverride
    - Windows security center.firewallnotify
    - Windows security center.firewalldisable
    - Windows security center.sp2udate
    - Windows security center.updatedisablenotify

    Microsoft ani spyware disables c:\windows\lsass.exe and gives a notify of this every few seconds

    I have attached the hijackthis log.

    I have looked in the other thread. My problem looks about the same but it is not exactly the same so i hope i can get a personalized advise.

    Thanks in advance
     

    Attached Files:

  4. Base

    Base Private E-2

    Update: Mcafee virusscan just informed me that c:\windows\lsass.exe was infected and it has cleaned the file. I don't know if it has been deleted because i couldn't find it on my machine earlier.

    THe windows firewall is still disabled. I have no idea how to turn it back on again
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you enable viewing of hidden & system files per the READ & RUN ME?

    If so, check again for c:\windows\lsass.exe and delete if found. Do not attempt to delete c:\windows\system32\lsass.exe because it is valid and required.

    Do you know what the below is for:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    Other than that your log is basically free of malware.
     
  6. Base

    Base Private E-2

    I looked again for the file and it is not there. Microsoft anti spyware doesn't say anything about the file so i think it is gone now.

    I know the thing you mentioned. it's ok.

    Great my system performs better than yesterday :)

    The only problem i have now is the windows firewall that i cannot enable agian. Could you help me with that?

    When everything is ok do i need to turn windows restore on again?

    Thnaks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It really does not matter that it is disabled because, you do not want to use the Windows firewall because it does not provide adequate bidirectional protection. You need to use a firewall like one of the one mentioned in How to Protect yourself from malware!. After installing one of these you do not want the WinXP SP2 firewall enabled anyway. The "How to protect" link also gives you a link to info on the Windows Firewall. You should be working thru the steps in that link (see the hot link at the end of step 3).

    If you do not install one of these real firewalls (this is not a recommended choice), then yes you must re-enable the Windows Firewall because using it is still better than no fireall at all.

    Yes as per step 1 on the READ & RUN ME,
     
  8. Base

    Base Private E-2

    Thanks a lot for your help.

    My system works correct now i think.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds