Yeah, definately sasser.
Main Topics
Browse All Topicslsass.exe is ending itself how can i stop this
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
i have a AV software "Microsoft Forefront Security" found no sasser or blaster worm, run rootkit "revealer rootkit" delete some but don't really know what else to delete. run sasser and blaster fix tool no worms were found. Run Hijackthis don't know what check in order to fix.
My OS Server 2003.
When type shutdown -a users can't access the network, I can open active directory etc..
Try malwarebytes from www.malwarebytes.org
nop just add some updates.
The server has Server 2003 SP2 Standard Edition, Forefront is up to date.
The error code:
"This system is shutting down. please save all work in progress and logg off. any unsaved changes will be lost. This shutdown was initiated by NT Authority/system.
the system process 'C:\windows/system32\lsass
Any change you can install SP3?
http://www.microsoft.com/d
See if you have this hotfix installed: http://support.microsoft.c
I think since I have installed forefront i start to have LSA Shell error that restarts the computer once a day until I get this error describes above where the server restarts itself every five mns. and when I type "shutdownn -a" it didn't restart but i can't access to active directory and some other important components.
Let's try to desinstall forefront.
Can you post your hijackthis log here please?
Also, try combofix http://www.bleepingcompute
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:18:16 AM, on 6/16/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\system32\Dfssvc
C:\WINDOWS\System32\dns.ex
C:\WINDOWS\system32\inetsr
C:\WINDOWS\System32\ismser
C:\Program Files\Common Files\System\MSSearch\Bin\
C:\WINDOWS\system32\ntfrs.
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon
C:\WINDOWS\system32\oobech
C:\WINDOWS\system32\mshta.
C:\Program Files\Trend Micro\HijackThis\HijackThi
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\Run: [ShutdownEventCheck] %systemroot%\system32\dump
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
O4 - HKUS\S-1-5-21-1314936129-2
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
O15 - ESC Trusted Zone: http://view.atdmt.com
O15 - ESC Trusted Zone: http://www.bleepingcompute
O15 - ESC Trusted Zone: http://googleads.g.doublec
O15 - ESC Trusted Zone: http://www.eggheadcafe.com
O15 - ESC Trusted Zone: http://www.eventid.net
O15 - ESC Trusted Zone: http://images.experts-exch
O15 - ESC Trusted Zone: http://www.experts-exchang
O15 - ESC Trusted Zone: http://www.freedomlist.com
O15 - ESC Trusted Zone: http://pagead2.googlesyndi
O15 - ESC Trusted Zone: http://bleepingcomputer.us
O15 - ESC Trusted Zone: http://images.intellitxt.c
O15 - ESC Trusted Zone: http://edge.quantserve.com
O15 - ESC Trusted Zone: http://forums.techarena.in
O15 - ESC Trusted Zone: http://m.webtrends.com
O15 - ESC Trusted IP range: http://66.129.67.103
O16 - DPF: {6414512B-B978-451D-A0D8-F
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CS1\Services\T
O23 - Service: WTNGEW - Sysinternals - www.sysinternals.com - C:\DOCUME~1\BARRYR~1.ADM\L
O23 - Service: ZSIM - Sysinternals - www.sysinternals.com - C:\DOCUME~1\BARRYR~1.ADM\L
--
End of file - 4147 bytes
Business Accounts
Answer for Membership
by: ssmith764Posted on 2009-06-15 at 13:25:38ID: 24632687
Sounds like the Sasser worm. Do you have AV software?
When you see the shutdown initiated countdown go to start>run and type 'shutdown -a' This will stop the shutdown.