NT AUTHORITY SYSTEM

G

Guest

Hi, my friends computer has got major porblems. The computer gets to the log
in screen, but after selecting a user, the computer gives my friend a message
that the computer has been shut down my NT AUTHORITY SYSTEM and will be
restarted (countdown in seconds). My friend also noticed the following peices
of information on the same page:

NT AUTHORITY SYSTEM
1073741819
C;/WINDOWS/SYSTEM32/SERVICES.EXE

No porgrams have been installed recently. Has the computer got a virus?
(running NORTON).

What can i do to resolve this problem.

regards and thanks in advance.
 
C

Carey Frisch [MVP]

How to remove the "Blaster Worm" from your computer:
http://www3.telus.net/dandemar/blaster.htm

[Courtesy of MS-MVP Jupiter Jones]

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User

Be Smart! Protect Your PC!
http://www.microsoft.com/athome/security/protect/default.aspx

-----------------------------------------------------------------------------

:

| Hi, my friends computer has got major porblems. The computer gets to the log
| in screen, but after selecting a user, the computer gives my friend a message
| that the computer has been shut down my NT AUTHORITY SYSTEM and will be
| restarted (countdown in seconds). My friend also noticed the following peices
| of information on the same page:
|
| NT AUTHORITY SYSTEM
| 1073741819
| C;/WINDOWS/SYSTEM32/SERVICES.EXE
|
| No porgrams have been installed recently. Has the computer got a virus?
| (running NORTON).
|
| What can i do to resolve this problem.
|
| regards and thanks in advance.
 
D

David H. Lipman

D

David H. Lipman

This sounds like the Sasser (no Blaster/Lovsan) Internet worm. McAfee's Stinger is an
excellent tool for cleaning both the Sasser and Blaster/Lovsan and I am sufggesting an
addition broad-spectrum virus, worm and Trojan remval tool.

Cleaning the system is NOT enough. A FireWall (such as the built-in XP FireWall) must be
enabled and *all* Critical Updates *must* be installed or the person will just be
infected/shutdown again.

WinXP SP2 corrects the vulnerabilities that the above Internet worms exploit.

When the user gets the shutdiown message, the following command can be used to stop the
shhutdown process

shutdown -a

Once entered, you can then clean and update the affected platform. If the PC is on
Broadband, I highly suggest a Cable/DSL Router as they act as simplistic or full hardware
FireWalls and will help protect against this an other events.

1) Download the following three items...

McAfee Stinger
http://vil.nai.com/vil/stinger/

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the signature files (pattern files) by obtaining the ZIP file.
For example; lpt337.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

2) If you are using WinME or WinXP, disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
3) Reboot your PC into Safe Mode and shutdown as many applications as possible
4) Using both the Trend Sysclean utility and Stinger, perform a Full Scan of your
platform and clean/delete any infectors found
5) Restart your PC and perform a "final" Full Scan of your platform using both.
6) If you are using WinME or WinXP, Re-enable System Restore and re-apply any
System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
7) Reboot your PC.
8) If you are using WinME or WinXP, create a new Restore point


* * * Please report back your results * * *

--
Dave
http://www.claymania.com/removal-trojan-adware.html




| Hi, my friends computer has got major porblems. The computer gets to the log
| in screen, but after selecting a user, the computer gives my friend a message
| that the computer has been shut down my NT AUTHORITY SYSTEM and will be
| restarted (countdown in seconds). My friend also noticed the following peices
| of information on the same page:
|
| NT AUTHORITY SYSTEM
| 1073741819
| C;/WINDOWS/SYSTEM32/SERVICES.EXE
|
| No porgrams have been installed recently. Has the computer got a virus?
| (running NORTON).
|
| What can i do to resolve this problem.
|
| regards and thanks in advance.
 
R

Ron Martell

Pinto1uk said:
Hi, my friends computer has got major porblems. The computer gets to the log
in screen, but after selecting a user, the computer gives my friend a message
that the computer has been shut down my NT AUTHORITY SYSTEM and will be
restarted (countdown in seconds). My friend also noticed the following peices
of information on the same page:

NT AUTHORITY SYSTEM
1073741819
C;/WINDOWS/SYSTEM32/SERVICES.EXE

No porgrams have been installed recently. Has the computer got a virus?
(running NORTON).

What can i do to resolve this problem.

regards and thanks in advance.

Is the Norton antivirus a current version (2004 or 2005)?
And are the virus definition files fully up to date (not more than a
week old)?
And does the system have the Windows XP Service Pack 2 updates
installed?

If the answers to the above questions are no then the problem is most
likely Blaster or Sasser as described in the other replies.

If the answers to all of the above questions is yes then there is some
other problem involved and we need more details about the actual error
message, preferably the complete *verbatim* text inclduing all of the
parameters.

Good luck


Ron Martell Duncan B.C. Canada
--
Microsoft MVP
On-Line Help Computer Service
http://onlinehelp.bc.ca

"The reason computer chips are so small is computers don't eat much."
 
B

Bruce Chambers

Pinto1uk said:
Hi, my friends computer has got major porblems. The computer gets to the log
in screen, but after selecting a user, the computer gives my friend a message
that the computer has been shut down my NT AUTHORITY SYSTEM and will be
restarted (countdown in seconds). My friend also noticed the following peices
of information on the same page:

NT AUTHORITY SYSTEM
1073741819
C;/WINDOWS/SYSTEM32/SERVICES.EXE

No porgrams have been installed recently. Has the computer got a virus?
(running NORTON).

What can i do to resolve this problem.

regards and thanks in advance.


Your friend has apparently contracted the latest worm,
W32.Sasser.Worm, specifically designed to attack people who do not
update their computers promptly and who do not practice "safe hex." In
other words, like Blaster, this worm was developed and distributed
_after_ a patch for the vulnerability was announced and made publicly
available. Further, and also like Blaster, this worm could not affect
any computer whose user had taken the basic precaution of using a
properly configured firewall.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next Shutdown countdown begins. This will abort the shut down. Also,
make sure you've enabled a firewall before starting, to preclude any
more intrusions while getting the updates/patches/tools.

What You should Know about the Sasser Worm and its Variants
http://www.microsoft.com/security/incident/sasser.asp

Microsoft Security Bulletin MS04-011
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

W32.Sasser.Worm
http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html

A tool is available to remove the Sasser worm variants
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720

W32.Sasser.Worm Removal Tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/

--

Bruce Chambers

Help us help you:



You can have peace. Or you can have freedom. Don't ever count on having
both at once. - RAH
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top