Unsolved

This post is more than 5 years old

81 Posts

1868

May 21st, 2007 15:00

Isass.exe

Hello.
 
Recently, I have been receiving warnings from the software firewall I run (Zone Alarm) that program "Isass.exe" is being contacted by an external source via port 500. 
 
I have been denying the connection and I've since googled "Isass.exe" 
 
It appears that "Isass.exe" with a capital "I" is quite different then "isass.exe" with a lowercase "i".  The former being a valid Window's system process, the other a virus masquerading as a valid windows process.
 
Since in the Zone Alarm warning message, it cleary shows that "Isass.exe" with the capital "I" is the program in question, which would be the valid windows process, why is it I've never seen this message in the year and a half I've been running ZoneAlarm?  Now all of a sudden, a few times a day something is attempting to contact "Isass.exe" via port 500.
 
Anti-virus scans have turned up nothing.
 
Suggestions?

81 Posts

May 22nd, 2007 18:00

It did it again today.
 
I'm like super paranoid now. :smileysad:

4 Apprentice

 • 

8.8K Posts

May 22nd, 2007 21:00

Please post a log on the HJT Forum where someone can review it and help you.


Click HERE OR HERE to download HJTsetup.exe
* Save HJTsetup.exe to your desktop.
* Open Notepad > Click on Format > Uncheck Word Wrap, if checked.
* Double-click on the desktop icon for HJTsetup.exe.
* By default it will install to C:\Program Files\HijackThis.
* In the screens that follow, continue to click Next to accept the default settings in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
* Put a check by Create a desktop icon then click Next again.
* Continue to follow the rest of the prompts from there.
* At the final dialogue box click Finish and HijackThis (HJT) will launch.
* Click on the "Do a system scan and save a logfile" button; HJT will then scan and a log showing the results should open in Notepad.
* Click on Edit > Select All (or CTRL+A) then click on Edit > Copy (or CTRL+C) to copy the contents of the log.

Posting Your Log:

* Next, just click the New Message button in the HijackThis forum to start your own thread requesting assistance.
* In the Message Body window that opens, simply Right-Click and select Paste.
*Please add text to describe your symptoms.
*Include in the message subject line a description of your problem. For example, "Popups warning of infection".
* Make certain you post the entire log by clicking the Preview Post link at the bottom of the window and comparing it to the log from your scan before you click Submit Post

NOTE:
* DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

zb1

81 Posts

May 29th, 2007 13:00

Been doing some research myself on the issue.
 
apparently the process "lsass.exe" is a valid windows process, where "Isass.exe" is a malicious process.
 
Look the same to you?  Me too.  But the valid process is "lsass.exe" beginning with a lower case "L" and the bad process is "Isass.exe" with an upper case "i".
 
Very sneaky, because in the task manager, there is hardly a distinction between I and l, same with this board's font.
 
So now I just need to wait for the error message again and see which one I'm dealing with.
 
Updates soon, hopefully.

2 Intern

 • 

2K Posts

May 30th, 2007 14:00

Yup. There is also an lsasss.exe out there (Sasser worm). Look-a-likes are common in the malware world. You need to look close and also take note of what folder it is in before deciding if a file is legit or a baddie.

81 Posts

May 30th, 2007 15:00

Yes, pretty sneaky of them. 

81 Posts

June 3rd, 2007 14:00

Well, I have been waiting for the warning from my firewall about this process for the last week now.  Nothing.  Ah well. Guess I can't complain about that!
No Events found!

Top