My PC was compulsorily restarted while connecting to Internet

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

When my PC (running Windows 2000 Professional) was connecting to Internet (by either dial-up or broadband access), there was occasionally a message box popping up to announce a compulsory restart of PC within one minute and subsequently it actually occurred. The summary of the error message is

The system process c:\winnt\system32\lsass.exe was terminated with error code 128.

Who can tell me what lsass.exe is for? Do I have to download a service pack? If so, which version? Where to download?
 
From another post;
Winupdate accessed via yr Start menu or from IE, also if using Office check
Officeupdate


Sounds like you've been infected by the Sasser worm. This means you didn't
apply Windows Updates (at least not very recently - patch for this came out
April 13) and don't have a firewall enabled....

For WinXP: If you can't stop your computer from restarting:

As soon as your computer reboots and Windows loads, click Start, then Run.
In the box, type the following:

shutdown -a (then click OK)

[for Win2k, shutdown.exe is part of the resource kit and the correct syntax
is
shutdown /a]

Then see http://www.microsoft.com/security/incident/sasser.asp and
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

McAfee's Stinger tool to remove Sasser: http://vil.nai.com/vil/stinger/

MS removal tool for Windows 2000 SP2 and up, or Windows XP:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720

Enable your XP firewall (or get a third party one if not on XP or even if
so - www.zonealarm.com has a free one) and run Windows Update regularly to
keep your OS patched to the gills. You also need good antivirus software and
need to keep it updated regularly. As mentioned, the patch for this exploit
was released April 13th...but there are plenty you do need. Perhaps want to
enable the autoupdate feature of Windows Update and subscribe to the
security bulletin announcements at www.microsoft.com/security.



moonriver said:
When my PC (running Windows 2000 Professional) was connecting to Internet
(by either dial-up or broadband access), there was occasionally a message
box popping up to announce a compulsory restart of PC within one minute and
subsequently it actually occurred. The summary of the error message is:
The system process c:\winnt\system32\lsass.exe was terminated with error code 128.

Who can tell me what lsass.exe is for? Do I have to download a service
pack? If so, which version? Where to download?
 
moonriver said:
When my PC (running Windows 2000 Professional) was connecting to Internet (by either dial-up or broadband access), there was occasionally a message box popping up to announce a compulsory restart of PC within one minute and subsequently it actually occurred. The summary of the error message is:

The system process c:\winnt\system32\lsass.exe was terminated with error code 128.

http://ask-leo.com/archives/000114.html
 
Hi - this sounds like the the Sasser worm or variant. This means you didn't
apply Windows Updates (at least not very recently - patch for Sasser came
out April 13) and don't have a firewall enabled....

See http://www.microsoft.com/security/incident/sasser.asp and
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

McAfee's Stinger tool to remove Sasser: http://vil.nai.com/vil/stinger/

MS removal tool for Windows 2000 SP2 and up, or Windows XP:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720

You need to get a firewall installed/configured ASAP. See www.zonealarm.com
and www.sygate.com for some free ones. You also need to run Windows Update
regularly to keep your OS patched to the gills. You also need good antivirus
software and need to keep it updated regularly. As mentioned, the patch for
this exploit was released April 13th...but there are plenty of others you
need. Perhaps want to enable the autoupdate feature of Windows Update and
subscribe to the security bulletin announcements at
www.microsoft.com/security.
 
Back
Top