Jump to content

Mysterious alert (lsass.exe)


Go to solution Solved by Porthos,

Recommended Posts

I got this alert. While using firefox but not on any dodgy websites atm. Although I have used football streaming webistes in the past but allways with adblock and script block and never gotten anything.

 

Any Ideas what this is? I uploaded the file in question to virustotal also and will post results below.

malwarebyte pic.png

Screenshot 2023-03-13 at 23-19-04 VirusTotal - File - 0777fd312394ae1afeed0ad48ae2d7b5ed6e577117a4f40305eaeb4129233650.png

Link to post
Share on other sites

2 minutes ago, Pedro1212 said:

I have one outbound from using qbittorrent. I only download tv episodes from trusted vendors and scan them before viewing

Malwarebytes does not scan video files.

3 minutes ago, Pedro1212 said:

but maybe I should stop that.

That is a good idea. Depending on the laws in your country, that could be a legal issue as well.

If you wish to not stop and take the risk, as it is your computer and all that,

Quote

As for why Malwarebytes blocked QBitTorrent , this is because QBitTorrent , and all Bittorrent software, are what are known as Peer-to-Peer (P2P) applications meaning it connects to many different servers/IP addresses (this is how files are downloaded through QBitTorrent ) and because of this, sometimes QBitTorrent will connect to a server that is also known for hosting malicious content.  This is because servers/IP addresses are often shared by multiple sites, so while what you are downloading through QBitTorrent may be perfectly safe, some of the sites hosted on some of the IP addresses that QBitTorrent connects to may be malicious.  Such connections are not a threat however, and you may exclude QBitTorrent from the Web Protection component in Malwarebytes to stop the blocks from happening without compromising your protection (your web browser and other critical web facing programs will still be fully protected from malicious websites and other malicious content).  To do so, add QBitTorrent to your exclusions using the method described under the Exclude an Application that Connects to the Internet section of this support article.

 

File sharing involves using technology that allows internet users to share files that are housed on their individual computers. Peer-to-peer (P2P) applications, such as those used to share music files, are some of the most common forms of file-sharing technology. However, P2P applications introduce security risks that may put your information or your computer in jeopardy.  Risks of File-Sharing Technology

 

  • Thanks 1
Link to post
Share on other sites

3 minutes ago, Porthos said:

Malwarebytes does not scan video files.

That is a good idea. Depending on the laws in your country, that could be a legal issue as well.

If you wish to not stop and take the risk, as it is your computer and all that,

 

Yeah. Thank you again. I was just wondering: Do you think I have a trojan or is this a case of one of  the sources I was downloading from and later seeding also has been known host a trojan? Should I just leave it a all my scans are clean do you think?

Link to post
Share on other sites

Torrent uses many IP's to seed the files. Many games use the same protocol as well.

If you are not convinced if you are infected or not, please do the following and @AdvancedSetup can take a look at the logs.

NOTE: The tools and the information obtained is safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system.

 

  • Download the Malwarebytes Support Tool
  • In your Downloads folder, open the mb-support-x.x.x.xxx.exe file
  • In the User Account Control pop-up window, click Yes to continue the installation
  • Run the MBST Support Tool
  • In the left navigation pane of the Malwarebytes Support Tool, click Advanced
  • In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine
  • A zip file named mbst-grab-results.zip will be saved to your desktop, please upload that file on your next reply

Thanks

  • Like 1
Link to post
Share on other sites

  • 4 weeks later...
  • Root Admin

Due to the lack of feedback, this topic is closed to prevent others from posting here.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this topic. Other members who need assistance please start your own topic in a new thread.

Tips to help protect from infection

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.