lsass.exe continuously reading and writing disk

  • Thread starter Thread starter Guest
  • Start date Start date
Thanks, kratkevich. Look below for my answers inside <<>>.

kratkevich said:
Grok,

I have noticed some things using ProccessMonitor that would lead to
troubleshooting taking several different paths. To try to narrow things down
please check the following and answer the questions:

1) Using Windows Explorer, look in C:\Documents and Settings\(User Name)\.
Watch the file size of ntuser.dat.LOG (You may have to adjust your Folder
Options from Control Panel to Show hidden and system files). Does the size of
this file change as you just watch it from Windows Explorer? Do you get an
error when you right-click and try to Open it (it's just a text file)?

<<My ntuser.dat.LOG is only 1 KB and is not increasing. When I try to open
it with Notepad I get an error because it is being used by another process
even though I only have ie windows open.
2) Do you have any Logitech hardware?

<<I have Logitech mouse and KB although my problem predates having any
Logitech.
3) Do you have any HP hardware?

4) Do you have any of the MS Office 2007 suites installed?

5) Have you ever run RegCure, PC Pitstop Optimize or TuneUp RegistryCleaner?

<< I've run RegCure, RegistryEasy, and SpeedUpMyPC although my problem
predates all of them. I have not rum Pitstop or TuneUp.
 
Hi,

I have my startup programs well under control using TuneUp Utilities 2007
StartUp Manager. I built this PC myself.

Thanks for your input.
 
Hi grok, I have a win 2000 machine that has started with this problem this
week. The page-fault delta is always 300 or so and the total page faults for
this process was at 16 million+ overnight. I think what I have is a variant
of 'vundu' virus, but none of the antivirus/antispyware (norton, adware,
counterspy) have detected anything wrong with lsass.exe

Whatever it is on my machine randomly pops up IE windows. That is the only
sympton that I have seen, other than the constant disk io from lsass.exe.

I have even disabled the Windows Security service that is supposed to be
using lsass.exe, but the process is still started at reboot. I have tried
deleting the file from winnt/system32, only to have it reappear almost
immediately.
 
Back
Top