search
Japanese Chinese Nederlands Espanol Italiano Deutsch Francais Twitter Rss Feeds
Windows Vista GroupsView
Windows Vista Administration_Accounts_Passwords
Windows Vista File_Management
Windows Vista Games
Windows Vista General
Windows Vista Hardware_Assessment
Windows Vista Hardware_Devices
Windows Vista Installation_Setup
Windows Vista Mail
Windows Vista Music_Pictures_Video
Windows Vista Networking_Sharing
Windows Vista Performance_Maintenance
Windows Vista Security

Group SummariesView
.NET Framework
Access
BizTalk
Certifications
CRM
DDK
Exchange Server
FoxPro
French
French .NET
Games
German
German .NET
Graphic Design
IIS
Internet
ISA Server
Italian
Italian .NET
Maps
MCIS
Miscellaneous
Mobile Application Development
Money
MSN
Networking
Office
Ops Mgr
Publisher
Security
SharePoint
Small Business
Spanish
Spanish .NET
SQL Server
Systems Management Server
Transaction Server
Virtual PC / Virtual Server
Visual Studio
Win32
Windows 2000
Windows 2003 Server
Windows 7
Windows Live
Windows Media
Windows Update
Windows Vista
Windows XP
 

View All Microsoft Windows Vista Security Posts  Ask A New Question 

lsass.exe - 3 I/O Reads / Writes per second - lsas

Thursday, February 07, 2008 3:47 AM

The lsass process is doing constant I/O.  Process Monitor describes the
action as:

56	1:32:41.6962584
AM	lsass.exe	740	RegOpenKey	HKLM\SECURITY\Policy	SUCCESS	Desired Access:
Read/Write
57	1:32:41.6962737
AM	lsass.exe	740	RegOpenKey	HKLM\SECURITY\Policy\SecDesc	SUCCESS	Desired
Access: Read
58	1:32:41.6962867
AM	lsass.exe	740	RegQueryValue	HKLM\SECURITY\Policy\SecDesc\(Default)	BUFFER
OVERFLOW	Length: 12
59	1:32:41.6962992
AM	lsass.exe	740	RegCloseKey	HKLM\SECURITY\Policy\SecDesc	SUCCESS
60	1:32:41.6963103
AM	lsass.exe	740	RegOpenKey	HKLM\SECURITY\Policy\SecDesc	SUCCESS	Desired
Access: Read
61	1:32:41.6963228
AM	lsass.exe	740	RegQueryValue	HKLM\SECURITY\Policy\SecDesc\(Default)	SUCCESS	Type: REG_NONE, Length: 200, Data:
62	1:32:41.6963351
AM	lsass.exe	740	RegCloseKey	HKLM\SECURITY\Policy\SecDesc	SUCCESS
63	1:32:41.6964635 AM	lsass.exe	740	RegCloseKey	HKLM\SECURITY\Policy	SUCCESS

Any ideas what is going on?  Note, the old XP trick of disabling Terminal
Services does not have an effect.  This is Vista with the latest updates.
reply
 

Looks like these I/O operations are caused by Task Manager itself. - lsas

Thursday, February 07, 2008 4:54 PM

Looks like these I/O operations are caused by Task Manager itself.  Process
Monitor is quiet when they are not running.
reply

Looks like the I/O operations were caused by Task Manager itself. - lsas

Thursday, February 07, 2008 4:56 PM

Looks like the I/O operations were caused by Task Manager itself.  Process
Monitor is quiet when TM is not running.
reply
 
 

Previous Microsoft Windows Vista Security conversation.