Re: 100% cpu usage for LSASS.EXE on DC intermittently, consistent



There is an LSASS worm I think. I think I also saw this with McAfee AV.

"Bill-MT" wrote:

> > "Bill-MT" <BillMT@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> > > I've look on the Internet and see references to WORMS doing this, but
>
> "Phillip Windell" wrote:
> > Phillip Windell [MCP, MVP, CCNA]
> > That is the wrong thing to expect. It is probably infected. Everytime I
> > have heard of this happening, without exception,...it was infected.
>
> Thanks for your response Phillip, but...
>
> I doubt any of the DC's are infected themselves. They are not logged into
> interactively accept to do DC work (no email, no web). They always have the
> latest security patches applied. If it is a WORM on a client machine, very
> possible, (like MS-Blaster, etc) it must be a worm specific to hitting a
> single DC. Again note, I don't see this behavior on any other machine (other
> DC's, member server, or clients) which I would expect to see in the case of a
> worm randomly walking the internal address spaces.
>
> Anyone have any more insight on what to look for here.
> Anyone tell me what to look for in my sniffer captures.
> tks. - bill.
.



Relevant Pages

  • Re: Bring me the head of the sasser Creator!!!
    ... > currently circulating on the Internet. ... The worm exploits the Local ... > visit the following Web site: ... > Please contact your Antivirus Vendor for additional details about this ...
    (microsoft.public.security.virus)
  • Re: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
    ... Even more disturbing then the fact that they use the internet and not there ... MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434! ... > this while at a Bank of America ATM today. ...
    (Bugtraq)
  • Re: PLEASE HELP
    ... It doesn't remove the worm. ... Left Click 'Advanced' Under "Internet Connection Firewall" tick the box ... You can then connect to the Internet and download the Microsoft relevant patch. ... It has been reported that, for users of Windows XP, ...
    (microsoft.public.windowsxp.newusers)
  • RE: MS tool to disinfect Code Red II
    ... There was a bug in the previous version because of the following IIS ... If your system got the worm and was internet-exposed, ... > WORM ON INTERNAL SERVERS THAT ARE PROTECTED FROM THE ... > INTERNET BY A ROUTER ...
    (Incidents)
  • Re: Remote Procedure Call
    ... You have the MSBlaster worm. ... Find an entry called "Windows Auto Update" on the right side. ... Control Panel, double-click Networking and Internet Connections, ...
    (microsoft.public.windowsxp.general)

Loading