Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Trojan Defence Suite
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 11th, 2004, 02:40 PM
the mul's Avatar
the mul the mul is offline
Very Frequent Poster
 
Join Date: Jul 2003
Location: scotland
Posts: 1,709
Default tds3 update

When tds starts to download the update, up pops a warning box from norton firewall saying, programme- c:/windows/system32/lsass.exe
protocol-udp [inbound] what do u want to do, [permit] or [block] and norton says that this is also a low risk warning.
I have not seen this before when updating tds, and the update works fine with no problems, even if i block lsass.exe [ inbound] all works well.
Can u tell me what lsass.exe does, or is, and is it ok to permit.


thanks the mul
__________________
OUTPOST BETA TESTER

WINDOWS 7 PRO 64 BIT, SP1, DUO CORE 2 OVERCLOCKED 3.4 GHZ 4 Gb PC6400 RAM 800MHZ
AVIRA ANTIVIRUS PREMIUM 2013 - Outpost PRO 8.0(4164.652.1856) - MBAM PRO V 1.70 - WINPATROL PLUS V 26.0 - HITMAN PRO 3.7.0
  #2  
Old March 11th, 2004, 02:46 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re:tds3 update

Hi Mul, I'd guess that the connection is internal to your pc "LocalHost" So probably your system talking to itself:
If you use Port Explorer you could see it easily, If you have not tried PE then get the free trial

Process File: lsass or lsass.exe
Process Name: Local Security Authority Service
Description: Windows Local Security Authority Server Process handles Windows security mechanisms. It verifies the validity of user logons to your computer or server. Technically, the software generates the process that is responsible for authenticating users for the Winlogon service.
Company: Microsoft Corp.
System Process: Yes
Security Risk ( Virus/Trojan/Worm/Adware/Spyware ): No
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #3  
Old March 11th, 2004, 02:54 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,648
Default Re:tds3 update

the mul,

There are several possibilities for lsass.exe. since yours is located at c:/windows/system32/lsass.exe, I would say it is the legitimate Windows file. You can find more info here.

Also, lsass.exe can come from a virus. See here.

I am not sure whether you want to permit or block the connection attempt tho. I have never seen it trying to connect on my system. You could try blocking it and see what happens or wait for someone else to give advice.

Regards,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #4  
Old March 11th, 2004, 02:56 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,648
Default Re:tds3 update

You might also want to take a look at this thread.

Regards,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #5  
Old March 11th, 2004, 03:09 PM
the mul's Avatar
the mul the mul is offline
Very Frequent Poster
 
Join Date: Jul 2003
Location: scotland
Posts: 1,709
Default Re:tds3 update

Thanks for all your help, i do have port explorer v1.800and the next time i will use pe and see what is going on .
I did check windows c:/windows/system32/lsass.exe,and i also confirmed it as Local Security Authority Service as well, and as i say everything is ok, and working fine.
In norton firewall, i have automatic programme control box unchecked, so that if anything requires permmision to install, it asks the user first, rather than the programme doing it for u, so maybe this is the reason i am getting this warning box.

Thanks Again

The Mul
__________________
OUTPOST BETA TESTER

WINDOWS 7 PRO 64 BIT, SP1, DUO CORE 2 OVERCLOCKED 3.4 GHZ 4 Gb PC6400 RAM 800MHZ
AVIRA ANTIVIRUS PREMIUM 2013 - Outpost PRO 8.0(4164.652.1856) - MBAM PRO V 1.70 - WINPATROL PLUS V 26.0 - HITMAN PRO 3.7.0
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Trojan Defence Suite « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:35 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums