LSA Shell (Export Version) - System Shutdown

N

Nick

When i go on the interent after any where from 5 to 20
minutes my computer says its encountered a problem with
LSA Shell (Export Version) and needs to close, after i
send the error report a system shutdown screen comes up
saying the NT Authroity/System has a problem and gives me
a minute to save and log off then it restarts so i can
not go on the internet with out having to restart every 5
minutes, if any one knows how to fix this please email me
and i will be very greatfull. Thank you.
Sincerly, Nick
 
C

Carey Frisch [MVP]

Apparently, your PC has suffered a major security breech and is now
infected with Malware (i.e. "a viral worm") because:

1. The latest Windows XP Critical Updates have apparently not been installed......
2. The PC's firewall apparently has not been properly enabled.....
3. Out-of-date or no AntiVirus program has been installed......

If you have Sasser, follow these directions to remove it from your computer:
http://www3.telus.net/dandemar/sasser.htm

[Courtesy of MS-MVP Jupiter Jones]


What You Should Know About the Sasser Worm and Its Variants
http://www.microsoft.com/security/incident/sasser.asp

PSS Security Response Team Alert - Sasser Worm and Variants
http://www.microsoft.com/technet/Security/alerts/sasser.mspx

W32.Sasser.B.Worm Critical Information
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html

W32.Sasser Removal Tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

3 Steps to Help Ensure your PC is Protected
http://www.microsoft.com/security/protect/

Frequently Asked Questions About Antivirus Software
http://www.microsoft.com/security/protect/antivirus.asp

Special note if you use AOL:

America Online installs its own connection settings that override
the ones that come with Windows XP. America Online's
connection settings don't include a way to turn on Windows XP's
built-in firewall.

Visit the following web site for instructions on downloading
a FREE firewall program for your computer.

Ref: http://www.updatexp.com/free.html

Consider purchasing a top-notch Internet Security program
that will help protect your PC from future viruses, hackers, and
privacy threats:
http://www.symantec.com/sabu/nis/nis_pe/

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User

Be Smart! Protect your PC!
http://www.microsoft.com/security/protect/

------------------------------------------------------------------------


| When i go on the interent after any where from 5 to 20
| minutes my computer says its encountered a problem with
| LSA Shell (Export Version) and needs to close, after i
| send the error report a system shutdown screen comes up
| saying the NT Authroity/System has a problem and gives me
| a minute to save and log off then it restarts so i can
| not go on the internet with out having to restart every 5
| minutes, if any one knows how to fix this please email me
| and i will be very greatfull. Thank you.
| Sincerly, Nick
 
R

roger

Hi Nick.

You have the sasser worm

What You Should Know About the Sasser Worm and Its Variants
http://www.microsoft.com/security/incident/sasser.asp

PSS Security Response Team Alert - New Worm Sasser
http://www.microsoft.com/technet/Security/alerts/sasser.mspx


Mitigation Steps for Affected Computers
If your computer is infected with the W32.Sasser.worm,
please do the following:

Enable the Windows XP Internet Connection Firewall or a
third-party firewall on the affected computer.
Disconnect the computer from the Internet.
Restart the computer. If you have problems rebooting,
reboot in safe mode.
Press CTRL+ALT+DEL.
Click the Task Manager.
Click the Processes tab.
Press and hold the CTRL key and then click
C:\WINDOWS\avserve.exe and c:\WINDOWS\system32\*_up.exe.
Click the End Task button.
Click Start.
Click Search and then search for and delete the following
files:
C:\WINDOWS\avserve.exe
C:\WINDOWS\system32\*_up.exe
Click Start again, click Run, and then type: regedit32
Click OK.
In Registry Editor, locate and delete the following
registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Run "avserve.exe" = C:\WINDOWS\avserve.exe
Connect the computer to the Internet.
Go to the Windows Update site, and click the Scan for
Updates button.
Download and install the critical updates recommended
after the scan.



http://www.microsoft.com/security/incident/sasser.asp
The stinger tool may also be helpful in detecting and
cleaning the Sasser worm.
http://vil.nai.com/vil/stinger/

Download this update
Microsoft Security Bulletin MS04-011
Security Update for Microsoft Windows (835732)
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

Enable your firewall.

MORE ON SECURITY:

Three steps you can take to improve your computer's security:
http://www.microsoft.com/security/protect/

321050 Description of a Personal Firewall
http://support.microsoft.com/?id=321050

More info:

http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html
http://www.bullguard.com/antivirus/vit_randon_i.aspx
http://www.vsantivirus.com/sasser-a.htm

Good luck
 
G

Guest

Also

http://www.sasser-worm.co

----- roger wrote: ----

Hi Nick

You have the sasser wor

What You Should Know About the Sasser Worm and Its Variant
http://www.microsoft.com/security/incident/sasser.as

PSS Security Response Team Alert - New Worm Sasse
http://www.microsoft.com/technet/Security/alerts/sasser.msp


Mitigation Steps for Affected Computer
If your computer is infected with the W32.Sasser.worm,
please do the following

Enable the Windows XP Internet Connection Firewall or a
third-party firewall on the affected computer.
Disconnect the computer from the Internet.
Restart the computer. If you have problems rebooting,
reboot in safe mode.
Press CTRL+ALT+DEL.
Click the Task Manager.
Click the Processes tab.
Press and hold the CTRL key and then click
C:\WINDOWS\avserve.exe and c:\WINDOWS\system32\*_up.exe.
Click the End Task button.
Click Start.
Click Search and then search for and delete the following
files:
C:\WINDOWS\avserve.exe
C:\WINDOWS\system32\*_up.exe
Click Start again, click Run, and then type: regedit32
Click OK.
In Registry Editor, locate and delete the following
registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVers
on\Run "avserve.exe" = C:\WINDOWS\avserve.exe
Connect the computer to the Internet.
Go to the Windows Update site, and click the Scan for
Updates button.
Download and install the critical updates recommended
after the scan.



http://www.microsoft.com/security/incident/sasser.as
The stinger tool may also be helpful in detecting and
cleaning the Sasser worm
http://vil.nai.com/vil/stinger

Download this updat
Microsoft Security Bulletin MS04-01
Security Update for Microsoft Windows (835732
http://www.microsoft.com/technet/security/bulletin/MS04-011.msp

Enable your firewall

MORE ON SECURITY:

Three steps you can take to improve your computer's security
http://www.microsoft.com/security/protect

321050 Description of a Personal Firewal
http://support.microsoft.com/?id=32105

More info

http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.htm
http://www.bullguard.com/antivirus/vit_randon_i.asp
http://www.vsantivirus.com/sasser-a.htm

Good luc

On Mon, 3 May 2004 16:12:56 -0700, "Nick" <[email protected]
wrote
 
C

Carey Frisch [MVP]

Amazingly, a worm or virus can enter your PC the very moment
you establish an internet connection and have not enabled a firewall.
You don't have to visit any website to become infected. Chances are
your PC running Windows XP has indeed contracted the Sasser worm.

If you have Sasser, follow these directions to remove it from your computer:
http://www3.telus.net/dandemar/sasser.htm

[Courtesy of MS-MVP Jupiter Jones]


What You Should Know About the Sasser Worm and Its Variants
http://www.microsoft.com/security/incident/sasser.asp

PSS Security Response Team Alert - Sasser Worm and Variants
http://www.microsoft.com/technet/Security/alerts/sasser.mspx

W32.Sasser.B.Worm Critical Information
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html

W32.Sasser Removal Tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

3 Steps to Help Ensure your PC is Protected
http://www.microsoft.com/security/protect/

Frequently Asked Questions About Antivirus Software
http://www.microsoft.com/security/protect/antivirus.asp

Special note if you use AOL:

America Online installs its own connection settings that override
the ones that come with Windows XP. America Online's
connection settings don't include a way to turn on Windows XP's
built-in firewall.

Visit the following web site for instructions on downloading
a FREE firewall program for your computer.

Ref: http://www.updatexp.com/free.html

Consider purchasing a top-notch Internet Security program
that will help protect your PC from future viruses, hackers, and
privacy threats:
http://www.symantec.com/sabu/nis/nis_pe/

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User

Be Smart! Protect your PC!
http://www.microsoft.com/security/protect/

-----------------------------------------------------------------------------------------------------


| Amazingly enough I came to this newsgroup to ask this very question. Supposedly the sasser worm is connected
with lsa shell. But it may not be the problem. See artcle:
|
| http://support.microsoft.com/default.aspx?scid=kb;en-us;300038
|
| I received an old computer that was running windows 2000 on a network. I removed the hard drive and
installed XP clean on a new hard drive. Once connected to the internet the first time I received the above
error message within 5 minutes of being online. I did not go anywhere online except the MSN homepage.
Basically, unless I received this sasser virus from MSN I could not be infected. But my symptoms are exactly
the same as Nick.
|
| My question is: when windows 2000 is being run on a network, can there be any residual code left in the BIOS
or in the DOS start-up? Having removed the hard drive no part of the 2000 OS can remain on the computer, or
can it? The above article is for windows 2000, but the exact symptoms are ocurring in XP. Is the cause exactly
the same? Can the same Hotfix be used?
|
| I also read that LSA shell can cause problems when memory is low. I intend to increase my pagefile space on
my disk. Does anyone know anything about this?
|
 
B

Bruce Chambers

Greetings --

You've apparently contracted the latest worm, W32.Sasser.Worm,
specifically designed to attack people who do not update their
computers promptly and who do not practice "safe hex." In other
words, like Blaster, this worm was developed and distributed _after_ a
patch for the vulnerability was announced and made publicly available.
Further, and also like Blaster, this worm could not affect any
computer whose user had taken the basic precaution of using a properly
configured firewall.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next RPC countdown begins. This will abort the shut down. Also, make
sure you've enabled a firewall before starting, to preclude any more
intrusions while getting the updates/patches/tools.

What You should Know about the Sasser Worm and its Variants
http://www.microsoft.com/security/incident/sasser.asp

Microsoft Security Bulletin MS04-011
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

W32.Sasser.Worm
http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html

A tool is available to remove the Sasser worm variants
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720

W32.Sasser.Worm Removal Tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/


Bruce Chambers

--
Help us help you:




You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top