Solved

Windows XP Shutdown -- Status Code 1073741819

Posted on 2006-11-30
9
3,610 Views
Last Modified: 2012-05-05
I have a user who has an XP machine w/ SP2 and has the most current updates installed on his computer. He has recently been having shut down issues.  

He will receive a message box referencing "lsass.exe: 0x012e0178 referenced at 0x00000000 can't be written".  He clicks on the OK button then will receive :

"System Shutdown: This system is shutting down.  Please save all work in progress and log off.  Any unsaved changes will be lost.  This shutdown was initiated by NT AUTHORITY\SYSTEM, and gives a 60 second timer before it shuts down.  The message in the System Shutdown box lists status code 1073741819.  

When the computer restarts, and the user logs in, he will receive a Data Execution Prevention message citing LSA Shell (Export Version).

Thinking it was a virus issue, I did a full scan with Sophos, Microsoft Malicious Software Removal Tool, no virus was detected.  In addition used Symantec's removal tool for Sasser and Blaster, and neither found anything.

Any thoughts on what I can do or what the issue might be.

Thanks!
0
Comment
Question by:CBHelpDesk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
9 Comments
 
LVL 14

Expert Comment

by:FriarTuk
ID: 18058876
search for lsass on you pc to find if more than one exists (should be c:\windows\system32)
try slaving the drive to another computer or put it in a usb enclosure, then do a full drive scan on all files.
http://www.microsoft.com/security/incident/sasser.mspx
0
 

Author Comment

by:CBHelpDesk
ID: 18114727
Thanks for the suggestion.  There is only lsass on the computer.  I slaved the drive and did a couple different scans on the drive with no result.
0
 
LVL 14

Expert Comment

by:FriarTuk
ID: 18120644
Problem: LSA Shell (Export Version) has encountered a problem and needs to close.
Then: C:\Windows\System32\ Isass.exe terminated unexpectedly with status code 1073741819.

http://www.microsoft.com/downloads/details.aspx?FamilyID=ad724ae0-e72d-4f54-9ab3-75b8eb148356&DisplayLang=en

http://www.symantec.com/security_response/writeup.jsp?docid=2004-050114-1706-99
http://vil.nai.com/vil/stinger/

Manual Removal Instructions
To remove this virus "by hand", follow these steps:

Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
Delete the file AVSERVE.EXE  from your WINDOWS directory (typically c:\windows or c:\winnt)
Edit the registry
Delete the "avserve" value from
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run Reboot the system into Default Mode
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:CBHelpDesk
ID: 18123475
Unfortunately, I have already run Microsoft's Malicious Software Removal Tool, Stinger, Symantec's Removal Tool with no result.  Also, avserve.exe cannot be found anywhere on the computer nor the registry.  I am at the point where I am going to rebuild the computer unless you have any other thoughts.  Thanks for your suggestions and help.
0
 
LVL 14

Expert Comment

by:FriarTuk
ID: 18145815
yeah, that sounds like what you'll have to do, as i can't find anything else that points to a decisive answer.
0
 
LVL 14

Expert Comment

by:FriarTuk
ID: 18394426
could you refund but paq this as it was hard trying to find anything on this direct error & it may help others in the future, thx.
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 18414248
PAQed with points refunded (500)

Computer101
EE Admin
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Can I legally transfer my OEM version of Windows to another PC?  (AKA - Can I put a new systemboard in my OEM PC?) Few of us are both IT and legal experts but we all have our own views of Microsoft's licensing rules and how they apply.  There are…
cPanel is a Unix based web hosting control panel that provides a graphical interface and automation tools designed to simplify the process of hosting a web site. cPanel utilizes a 3 tier structure that provides functionality for administrators, rese…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question