lsass.exe takes cpu times for a few minutes

From: tomoseki (tomoseki_at_discussions.microsoft.com)
Date: 07/14/04


Date: Wed, 14 Jul 2004 02:04:01 -0700

Hi,

I posted this to security and administration group, but I had only one response so far.

Any advice are welcome.

Thanks,
Tomoki

-----------

When I logon to my XP Pro box, the logon process runs very slowly.
Taskmgr shows that lsass.exe takes up a lot of cpu cycle like 70-80% for a few minuites. During this, everything goes very slowly. After that, everything works fine.

Windows XP Pro SP1, all updates are applied.
The box is not in a domain.

NAV2003 is installed on the box, and scans the PC everyday. So, I don't think that it is affected by any viruses.

I looked into eventlog, but there is nothing special in application log and system log.

And when I logon to the box with other local accounts, it doesn't happen. Everything looks normal. Only my account seems affected.

I suspect that it's kind of a spyware or something like that, but I can't find any thing saying that how to fix this.

I was advised to install and scan spyware, so I did it.

I installed spybot and the latest rule, and scaned the box.
It found some tracing cookies, and registry settings (DSO Exploit and Alexa related).
I removed those things, but it doesn't change the situation.

I looked into task list again, and I found that one svchost.exe also take some cpu time. It looks like the svchost and lsass working together for something.

below is the output from tasklist.exe /svc :

svchost.exe 952 AudioSrv, Browser, CryptSvc, Dhcp, dmserver,
                                 ERSvc, EventSystem,
                                 FastUserSwitchingCompatibility, helpsvc,
                                 HidServ, lanmanserver, lanmanworkstation,
                                 Messenger, Netman, Nla, RasMan, Schedule,
                                 seclogon, SENS, ShellHWDetection, srservice,
                                 TapiSrv, TermService, Themes, TrkWks,
                                 uploadmgr, W32Time, winmgmt, wuauserv, WZCSVC

Again, it only affects my local account.

Some more information.
I recently write some codes that use com+, com+ catalog, com+ events, com+ instruments, msmq, event tracing for windows.
Also, I applied group policy setting to disable windows messenger.

I don't remember anything else that likely affects the system behavior..

Any comments are welcome.

-------

Thanks,
tomoki



Relevant Pages

  • Re: New employee, same computer -- what to do?
    ... Doesn't that name become a local logon? ... The only local accounts you have to have are administrator and guest ... there's no real need to rename user accounts to ensure ... Let's see, I want to print to the $100 label printer, which *is* hung ...
    (microsoft.public.windows.server.active_directory)
  • Re: New employee, same computer -- what to do?
    ... The only local accounts you have to have are administrator and guest (the ... "Marketing department") permission to a resource, ... good domain logon password, but everyone has access to all the shared ... there's no real need to rename user accounts to ensure people ...
    (microsoft.public.windows.server.active_directory)
  • RE: SMS Deployment of Office 2007: Silent w/o user interaction con
    ... night (much less a week or so to spread out the deployment). ... I get more and more discouraged everyday I use SMS. ... The only solution is to wake the computers or just have them on and install ... logs in,the packages is interrupted by the logon, or it forces a restart but ...
    (microsoft.public.sms.swdist)
  • Re: Security event id 537
    ... Logon Failure. ... From the detail in the event log, the error code 0x80090308 can translated ... You can get the network monitor from the following link and install ...
    (microsoft.public.windows.server.sbs)
  • Re: sunfire v210 reinstall -help please.
    ... I hit enter it goes to next line and thats it, ... its the same deal as the hyper terminal connection result. ... Boots to logon but password is unknown ... Can someone please let me know or suggest where to find a install o/s ...
    (comp.sys.sun.admin)