Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 4.72%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.06%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.22%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.01%
6.2.9200.16384 (win8_rtm.120725-1247) 0.86%
6.1.7601.17725 (win7sp1_gdr.111116-1503) 40.58%
6.1.7601.17725 (win7sp1_gdr.111116-1503) 18.70%
6.1.7600.16915 (win7_gdr.111116-1506) 3.54%
6.1.7600.16385 (win7_rtm.090713-1255) 8.16%
6.1.7600.16385 (win7_rtm.090713-1255) 3.92%
5.1.2600.5512 (xpsp.080413-2113) 12.71%
5.1.2600.5512 (xpsp.080413-2113) 0.91%
5.1.2600.5512 (xpsp.080413-2113) 0.65%
5.1.2600.5512 (xpsp.080413-2113) 0.06%
5.1.2600.5512 (xpsp.080413-2113) 0.59%
5.1.2600.5512 (xpsp.080413-2113) 0.01%
5.1.2600.5512 (xpsp.080413-2113) 0.01%
5.1.2600.5512 (xpsp.080413-2113) 0.38%
5.1.2600.5512 (xpsp.080413-2113) 0.06%
5.1.2600.5512 (xpsp.080413-2113) 0.01%
5.1.2600.5512 (xpsp.080413-2113) 0.17%
5.1.2600.5512 (xpsp.080413-2113) 0.27%
5.1.2600.5512 (xpsp.080413-2113) 0.06%
5.1.2600.5512 (xpsp.080413-2113) 0.27%
5.1.2600.5512 (xpsp.080413-2113) 0.06%
View more

lsass.exe

Local Security Authority Process by Microsoft Corporation (Signed)

Remove lsass.exe
Version:   5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5:   4bca771a81625259affaa218e0111d76
SHA1:   c451366d8d3299234286cda7c24ad436af25bea7
SHA256:   7339318277521c04de3892b9fc70fd3c4ba1c3d2d8f3347e03e775be70a15448
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is lsass.exe?

Local Security Authority Subsystem Service (LSASS), is a process in Microsoft Windows operating systems that is responsible for enforcing the security policy on the system. It verifies users logging on to a Windows computer or server, handles password changes, and creates access tokens.

Overview

lsass.exe runs as a service under the name Titkosított fájlrendszer (EFS) (KeyIso) with extensive SYSTEM privileges (full administrator access) as a shared service. The file is digitally signed by Microsoft Corporation. This version is installed on Windows XP and is compiled as a 32 bit program.

DetailsDetails

File name:lsass.exe
Publisher:Microsoft Corporation
Product name:Local Security Authority Process
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\lsass.exe
File version:5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version:5.1.2600.2180
Size:13 KB (13,312 bytes)
Build date:8/4/2004 1:59 PM
Certificate
Issued to:Microsoft Corporation
Authority (CA):Microsoft Corporation
Expiration date:Friday, June 13, 2014
Digital DNA
Entropy:5.983062
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' as a shared service by the Service Host (svchost.exe)
Network connections
  • [UDP] listens on port 4500

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00554942%
    0.028634%
    Kernel CPU:0.00471669%
    0.013761%
    User CPU:0.00083273%
    0.014873%
    Kernel CPU time:1,753 ms/min
    100,923,805ms/min
    Context switches:1/sec
    284/sec
    Memory
    Private memory:3.65 MB
    21.59 MB
    Private (maximum):5.71 MB
    Private (minimum):264 KB
    Non-paged memory:3.65 MB
    21.59 MB
    Virtual memory:41.11 MB
    140.96 MB
    Virtual memory (peak):44.61 MB
    169.69 MB
    Working set:1.32 MB
    18.61 MB
    Working set (peak):5.71 MB
    37.95 MB
    Resource allocations
    Threads:19
    12
    Handles:356
    600
    GUI GDI count:4
    103
    GUI USER count:1
    49

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:32-bit
    Command line:C:\Windows\System32\lsass.exe
    Owner:SYSTEM
    Windows Service
    Service name:KeyIso
    Display name:Titkosított fájlrendszer (EFS)
    Description:“Durch den Start dieses Diensts wird anderen Diensten signalisiert, dass die Sicherheitskontenverwaltung (SAM) bereit ist, Anforderungen anzunehmen. Wenn Sie diesen Dienst deaktivieren, wird verhindert, dass andere Dienste im System benachrichtigt werden, wenn die Sicherheitskontenverwaltung bereit ist. Dies kann wiederum dazu führen, dass diese Dienste nicht korrekt gestartet werden. Dieser Dienst”
    Type:Win32ShareProcess
    Parent process:winlogon.exe (Microsoft Windows Operating System by Microsoft)

    ResourcesThreads

    Averages
     
    LSASRV.dll
    Total CPU:0.04532407%
    0.272967%
    Kernel CPU:0.01510802%
    0.107585%
    User CPU:0.03021605%
    0.165382%
    Context switches:1/sec
    79/sec
    Memory:696 KB
    1.16 MB
    RPCRT4.dll
    Total CPU:0.00114408%
    Kernel CPU:0.00057204%
    User CPU:0.00057204%
    Memory:580 KB
    ADVAPI32.dll
    Total CPU:0.00095370%
    Kernel CPU:0.00019074%
    User CPU:0.00076296%
    Memory:668 KB
    ntdll.dll
    Total CPU:0.00054026%
    Kernel CPU:0.00012712%
    User CPU:0.00041314%
    Memory:596 KB
    msvcrt.dll
    Total CPU:0.00031790%
    Kernel CPU:0.00025432%
    User CPU:0.00006358%
    Memory:352 KB

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 8.1 34.50%
    Windows 8.1 Pro 27.00%
    Windows 8.1 Single Language 12.00%
    Windows 7 Ultimate 10.50%
    Windows 7 Home Premium 7.00%
    Windows 8.1 Pro with Media Center 3.00%
    Windows 8.1 N 3.00%
    Windows 8.1 Enterprise Evaluation 3.00%

    Distribution by countryDistribution by country

    United States installs about 39.50% of Local Security Authority Process.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    ASUS 30.23%
    Dell 24.03%
    Acer 17.83%
    Lenovo 13.95%
    Hewlett-Packard 6.98%
    Toshiba 4.65%
    Alienware 2.33%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE