1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

60 seconds until shutdown (sasser?)

Discussion in 'Security and Privacy' started by Gasolene, 2004/05/12.

Thread Status:
Not open for further replies.
  1. 2004/05/12
    Gasolene

    Gasolene Inactive Thread Starter

    Joined:
    2002/01/17
    Messages:
    210
    Likes Received:
    0
    system keeps shutting down in 60 seconds (even in safe mode)

    “This system is shutting down. Please save all... This shutdown was initiated by NT AUTHORITY\SYSTEM.

    Message: The system process 'c:\windows\system32\lsass.exe' terminated unexpectedly with the status code -1073741676. The system will now shut down and restart.â€

    lsass.exe is exploited by the sasser virus but I could not find any of the values associated with the sasser.A - sasser.F in the regestry.

    nor was there any suspicious processes running, nor are there any unknown startup regestry keys in Hkey_current_users, or hkey_local_machine.

    suggestions???

    where else could a virus start from, and if i don't see it in the process list, then can it be a virus??

    The os is win2000 so I have no "startup -a" nor do i have "msconfig ".

    thnx,
     
    Last edited: 2004/05/12
  2. 2004/05/12
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Have you seen this ?
    http://www.microsoft.com/security/incident/sasser_print2000.asp

    The command to stop the shutdown is

    On the taskbar at the bottom of your screen, click Start, and then click Run.
    Type: cmd and then click OK.
    At the command prompt, type: shutdown.exe -a and then press ENTER.

    But thats not mentioned on the Win2000 page
     

  3. to hide this advert.

  4. 2004/05/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Do you have a firewall running? If not, just an incoming attack can shut down the service, no need to be infected.
     
  5. 2004/05/12
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Lonnie - shutdown.exe isn't a part of the normal 2K install. You gotta get it from the resource kit. It does come standard with XP.
     
    Newt,
    #4
  6. 2004/05/12
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Thanks Newt I was unsure of that.

    noahdfear is correct a PC doesn't necessarily need to be infected to get the shutdown message merely being unpatched and without a firewall is enough.
    But I would get and use several removal tool's nonetheless
     
  7. 2004/05/13
    Gasolene

    Gasolene Inactive Thread Starter

    Joined:
    2002/01/17
    Messages:
    210
    Likes Received:
    0
    thnx,

    the problem is is that I don't hav enough time to run any removal tools.

    the system shutsdown almost immediatly after login, and this install has no resource kit installed.

    I'm not sure if firewall is enabled (not my PC).

    note, this happens even when internet is disconnected.

    is there another way to abort the shutdown?
     
  8. 2004/05/13
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    You will need to get shutdown.exe. If you get the res kit onto another PC and copy off shutdown.exe (no install, just a file that will run), you can boot the affected PC to the recovery console via Install CD boot, copy the file to the PC, and be able to block shutdown that way.

    Alternative (but still requiring the same method to get it on your PC) would be PSShutdown from www.sysinternals.com .
     
    Newt,
    #7
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.