system
2
Hi,
a) try blocking TCP in port 4500 and UDP IN port 500 for lsass, or ALL connections inbound for lsass.exe
maybe with 3rd-party firewall
b) are you SURE you installed all Windowsupdates ? also the ones from April 12.-14. ??
cause those updates replaced LSASS / fixed an lsass-vulnerability in additon to some RPC-security-Rollup-package
b1) there have been lots of reports that the above updates make some XP or 2000 system really unstable, try google
c) why don’t you try installing/scanning with an AV-scanner OFFLINE, like avast, or Kaspersky ?
d) post a hijackthis-Log: www.lurkhere.com
e) try SFC.exe (system filecheck in WIN) to check for bogus windows/system files
