[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

PC shuts down when connected to internet...

Posted on 2004-05-01
6
Medium Priority
?
1,234 Views
Last Modified: 2013-12-04
Dear Experts

since today, 5/1/04, my PC (Win 2K SP4 1st partition/ WinXP SP1 on 2nd partition) restarts automatically after a random period of time when connected to internet.
I always connect to internet with my Win2K system only! I DON'T HAVE Blaster Worm, the symantec Blaster scanner returns no infections, The Microsoft KB Patch is installed, my NaV is running with latest virus definition from 04/30/04.

The message coming up informs me that there are 60 seconds left until shutdown and that  system32\LSASS.EXE was exited unexpected with statss code 128. What is this???

thanx
0
Comment
Question by:MPKR
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
6 Comments
 
LVL 11

Accepted Solution

by:
ghana earned 400 total points
ID: 10968173
Your computer was hit by a new self executing worm:
http://www3.ca.com/threatinfo/virusinfo/virus.aspx?ID=39012
http://vil.nai.com/vil/content/v_125007.htm
http://www.sophos.com/virusinfo/analyses/w32sassera.html
http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SASSER.A

You need another patch to be protected against this worm. Go immediately to http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx and download and install the corresponding patch on your computer.

Then you should check your computer and delete the files mentioned in the virus descriptions. Finally run a port scanner against your own machine to make sure that it isn't listening on TCP port 9996.
0
 
LVL 11

Expert Comment

by:ghana
ID: 10968206
I saw that McAfee has added Sasser.A into its removal tool Stinger. You can also use Trend Micro's Damage Cleanup Service (DSC) to remove the worm.

Stinger: http://vil.nai.com/vil/stinger
DSC: http://www.trendmicro.com/download/dcs.asp
0
 
LVL 11

Expert Comment

by:ghana
ID: 10968614
Glad I could help you. Thanks for your rating!
0
Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

 
LVL 4

Author Comment

by:MPKR
ID: 10968642
I wonder why my Notton Av definitions downloadad a few minutes ago seems not to support this virus...

Thanks a lot !!!!
0
 
LVL 11

Expert Comment

by:ghana
ID: 10968684
According to
- http://securityresponse.symantec.com/avcenter/defs.added.html 
- http://www.symantec.com/avcenter/venc/data/w32.sasser.worm.html
the current IntelligentUpdater and LiveUpdate definitions should be able to detect Sasser.A. But sometimes the guys who are responsible for the website are faster than the developers... It's also possible that the current definitions will support a new virus but not reliable. We should watch Symantec's definition releases in the next hours and update the definitions frequently.

It's also possible that your computer wasn't infected. To check this search for the file c:\Windows\avserve.exe. If this file is not present then your computer wasn't infected but only affected. The exploit didn't work but LSASS.EXE did crash.

To prevent similar problems in the future I would recommend to protect internet connected computers with all available MS-patches. MBSA 1.2 (Microsoft Baseline Security Analyzer) is a free application that is able to check your computer whether all necessary patches are installed or not. If not it will list all these patches. In addition there will be a link to the corresponding security bulletin where you can download the patch. Running MBSA once a week will make sure that your computer is up to date.

Link to MBSA: http://support.microsoft.com/?kbid=320454
0
 
LVL 11

Expert Comment

by:ghana
ID: 10970395
Hello again!

There's another explanation why NAV didn't detect the virus. There is a second variant (Sasser.B) in the wild that won't be detected with the previous definitions.

Sources:
http://www3.ca.com/threatinfo/virusinfo/virus.aspx?id=39021
http://vil.nai.com/vil/content/v_125008.htm
http://www.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SASSER.B

As you can see on http://securityresponse.symantec.com/avcenter/defs.added.html Sasser.B needs new definitions.
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question