Question about security event (lsass.exe)

Question about security event (lsass.exe)

I have multiple computers and print workstations networked together and recently I've been seeing multple counts under the failure heading:

The Windows Firewall has detected an application listening for incoming traffic. Name: - Path: C:\WINDOWSsystem32lsass.exe Process Identifier: 808 User account: SYSTEM User domain: NT AUTHORITY Service: Yes RPC server: No IP version: IPv4 IP protocol: UDP Port Number: 2320 Allowed: No User notified: No

I get lots of those events happening every 10 minutes or so on multiple systems. Also the port number changes with each event. Is this something I should be worried about? None of the computers have been rebooting, so I don't think it's the sasser worm. Any suggestions?



                New to ADSelfService Plus?