shutdowns on brand new computer

G

Guest

just got this computer yesterday, and i've done no surfing, except for the preset homepage, and yahoo games, but when i try to run some applications, it shuts down on me. Similar to blaster situation, but it doesn't do it all the time the way it does with blaster
it is running with a trial version of Norton antivirus, but i haven't downloaded any email until i get the latest version of Norton installed

i can't get the whole message but the gist is
NT Authority syste
save all work and log of
system process C:window\sys32\lsass.ex
terminated unexpectedly status code107374181

i would much appreciate any help you can give me
 
C

Carey Frisch [MVP]

Sasser Worm - A New Threat To Users!
http://www.updatexp.com/sasser-worm.html

What You Should Know About the Sasser Worm and Its Variants
http://www.microsoft.com/security/incident/sasser.asp

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User

Be Smart! Protect your PC!
http://www.microsoft.com/security/protect/

-------------------------------------------------------------------------------------------------


| just got this computer yesterday, and i've done no surfing, except for the preset homepage, and yahoo games,
but when i try to run some applications, it shuts down on me. Similar to blaster situation, but it doesn't
do it all the time the way it does with blaster.
| it is running with a trial version of Norton antivirus, but i haven't downloaded any email until i get the
latest version of Norton installed.
|
| i can't get the whole message but the gist is
| NT Authority system
| save all work and log off
| system process C:window\sys32\lsass.exe
| terminated unexpectedly status code1073741819
|
| i would much appreciate any help you can give me
 
S

Shenan Stanley

marigold said:
just got this computer yesterday, and i've done no surfing, except
for the preset homepage, and yahoo games, but when i try to run some
applications, it shuts down on me. Similar to blaster situation,
but it doesn't do it all the time the way it does with blaster. it is
running with a trial version of Norton antivirus, but i haven't
downloaded any email until i get the latest version of Norton
installed.

i can't get the whole message but the gist is
NT Authority system
save all work and log off
system process C:window\sys32\lsass.exe
terminated unexpectedly status code1073741819

i would much appreciate any help you can give me

Congratulations! You have a virus!
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html

There are removal instructions there for both versions
(including tools to help you.)
Know that even if you have the normal updates for Norton, the definitions
for "B" were added on May 1. You can go to Symantec's site and get the
manual update if you like.

If it starts to shutdown on you, click Start > Run, and enter "shutdown -a".
(no quotes.) That will stop the shutdown and let you continue fixing.

Note that Microsoft is not sending you patches in emails nor should you EVER
open attachments you did not expect in emails. You simply posted your
un-munged email address to the thousands of newsgroups that this is spread
to around the world and it has been "harvested".


My other suggestions to you include:

Please Notice that if you use AOL, you should at least upgrade to 9.0 or
greater before doing any of the fixes. I know you can get AOL 9.0 at almost
any convenience store, gas station, super market or other retail outlet in
the world, so this should not be a problem.


Turn on that firewall...
http://www.microsoft.com/WindowsXP/home/using/howto/homenet/icf.asp
(It has been reported that it now works with AOL 9.0+)


Make sure you have all the updates (critical) installed from:
http://windowsupdate.microsoft.com/
(Scan for updates, Review and Install)


Get rid of the spy/ad/mal-ware..
(Yes - using MORE than one of these..
I recommend at least the first three. Also..
UPDATE the definitions for them before using.)

Spybot Search and Destroy
http://www.safer-networking.net/

Lavasoft AdAware
http://www.lavasoft.de

CWSShredder
http://www.spywareinfo.com/~merijn/downloads.html

Hijack This!
http://mjc1.com/mirror/hjt/

I also like "The Cleaner" and "SpywareBlaster" and "SpywareGuard".
- http://www.moosoft.com/
- http://www.javacoolsoftware.com/

The first is a PAY product, but useable for 30 days - it has found and
eliminated problems in the past the others did not. The latter two are
prevention mechanisms. I like SpywareGuard for those with enough processor
to have something running like antivirus software - and it prevents browser
hijacking quite well. SpywareBlaster is a FANTASTIC free product, I suggest
getting this after you cleanup and keeping it updated as well....

And Assortment of Others:
http://spywareinfo.com/

ALSO - Be sure to IMMUNIZE after you clean up. SpywareBlaster and Spybot
Search and destroy both have these features - use both!


After you cleanup your PC somewhat of spy/ad/mal-ware, verify your antivirus
software is updated and run a full scan of your computer. If you have no
antivirus software - get one NOW! Grisoft AntiVirus:
http://www.grisoft.com/us/us_dwnl_free.php


Empty your Temporary Internet Files and shrink the size it stores to about
80 to 120MB (seems to be an optimal size for the normal user)

- Open ONE copy of Internet Explorer.
- Select TOOLS -> Internet Options.
- Under the General tab in the "Temporary Internet Files" section,
do the following:
- Click on "Delete Cookies" (click OK)
- Click on "Settings" and change the
"Amount of disk space to use:" to something between 80MB
and 120MB. (Betting it is MUCH larger right now.)
- Click OK.
- Click on "Delete Files" and select to
"Delete all offline contents" (the checkbox) and click
OK. (If you had a LOT, this could take 2-10 minutes or
more.)
- Once it is done, click OK, close Internet Explorer
- Re-open Internet Explorer.


Uninstall any software you do not use often/ever. (If you have something
installed but never use it, uninstall it.) If you go through Control
Panel -> Add/Remove Programs and see things you seldom if ever use, it is to
your advantage to remove it.


Also, if you are tired of Web Page Pop-Ups/Unders.. You could try the
Google Toolbar.
http://toolbar.google.com/


Stop loading applications at logon.. run MSCONFIG and look under the startup
tab for things you DON'T want to startup! Search the Internet with Google
to discover what things are safe to remove and what things may even be
malware infecting your computer.


Better control your email and lessen the amount of time you spend dealing
with SPAM:
SpamBayes
http://sourceforge.net/projects/spambayes/
or
Spamihilator.
http://www.spamihilator.com
 
G

Guest

THANK YOU THANK YOU THANK YOU ALL. I can't believe it. I couldn't have been online more than 60 to 90 minutes altogether since I got this computer and the first shutdown must have happened in something like the first ten minutes online. Was I really unlucky or is this thing so smart that it can attack any unprotected computer more or less in seconds? Is it possible that the virus was already on the computer when I got it????

If it hadn't been brand new, my first thought would have been a virus, but I didn't expect I could be hit so fast. A lesson for us all

Thank you for your help, and so quickly too. Stinger has wiped it, and 72 files were corrupted already.
 
S

Shenan Stanley

marigold said:
THANK YOU THANK YOU THANK YOU ALL. I can't believe it. I couldn't
have been online more than 60 to 90 minutes altogether since I got
this computer and the first shutdown must have happened in something
like the first ten minutes online. Was I really unlucky or is this
thing so smart that it can attack any unprotected computer more or
less in seconds? Is it possible that the virus was already on the
computer when I got it?????

If it hadn't been brand new, my first thought would have been a
virus, but I didn't expect I could be hit so fast. A lesson for us
all!

Thank you for your help, and so quickly too. Stinger has wiped it,
and 72 files were corrupted already.

It can get on an unprotected machine in seconds.
 
B

Bruce Chambers

Greetings --

You've apparently contracted the latest worm, W32.Sasser.Worm,
specifically designed to attack people who do not update their
computers promptly and who do not practice "safe hex." In other
words, like Blaster, this worm was developed and distributed _after_ a
patch for the vulnerability was announced and made publicly available.
Further, and also like Blaster, this worm could not affect any
computer whose user had taken the basic precaution of using a properly
configured firewall.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next RPC countdown begins. This will abort the shut down. Also, make
sure you've enabled a firewall before starting, to preclude any more
intrusions while getting the updates/patches/tools.

What You should Know about the Sasser Worm and its Variants
http://www.microsoft.com/security/incident/sasser.asp

Microsoft Security Bulletin MS04-011
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

W32.Sasser.Worm
http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html

A tool is available to remove the Sasser worm variants
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720

W32.Sasser.Worm Removal Tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html

McAfee AVert Stinger Virus Removal Tool
http://vil.nai.com/vil/stinger/


Bruce Chambers

--
Help us help you:




You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
G

Guest

Thank you again for all your very helpful responses. Normally I do practice "safe hex", don't open any attachments from anyone I don't know, and alway check with the (apparent) sender before I open attachments even from anyone I know. I also do microsoft updates ASAP

I just got caught because my computer was brand new, and I literally got the virus within minutes of being online for the first time. I didn't even have time to do the microsoft downloads before it happened. I do admit to forgetting to enable the firewall, but I certainly won't make THAT mistake again lol. I suppose it must have been scanning IPs in my area for me to get hit so fast

VERY grateful for this newsgroup. You've got me out of trouble in the past, and I'm sure you will again in the future!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top