System Shutdwon in Windows XP

Posted on 2012-08-24
Last Modified: 2012-09-20
Hello everyone,
            I need to find out why the computer is shutting down.


This system is shutting down.Please save all work in progress adn log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY/SYSTEM

Message: C\windows\system32\lsass.exe with code 1073741819

I am attaching a picture.

Thank you
Question by:iscivanomar
    LVL 12

    Assisted Solution

    Take a look at this:

    Otherwise, I would recommend scanning for malware with the following two scanners:
    LVL 15

    Assisted Solution

    Abort the shutdown by going to Start ->Run, type    shutdown -a    and click OK.

    Then you can start task manager and check for any odd processes running. Make sure that the Show processes from all users checkbox is ticked.
    LVL 9

    Assisted Solution

    You are infected with a Sasser like worm from 2003, which kills lsass.
    LVL 62

    Assisted Solution

    by:☠ MASQ ☠
    Go with the advice to run MBAM
    Looks like your file at HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff has been replaced with a rogue version so expect to find a trojan or three.

    If you open a command window and run "shutdown -a" that will stop the shutdown and allow you to get on with the fix.  Not Sasser type attack though as that was patched by SP2 the NTAuthority window is different.
    LVL 32

    Expert Comment

    Prior to running MBAM, run RogueKiller.
    LVL 30

    Assisted Solution

    Don't forget to patch the system.
    That exploit is many years old

    Run the updater and install!

    Sasser is worm,and without a good firewall and up to date patches,it will just reinfect the system.

    MS security essentials is a free virus scan tool that is easily a top 5 product (paid or not).

    Download it and install it.
    LVL 32

    Assisted Solution

    All lsass shutdowns are not Sasser related. Behavior is not that of old Sasser worm.
    LVL 29

    Accepted Solution


    As suggested above by EE experts please run RogueKiller, followed by MalwareBytes and post the logs from both here for further investigation of the issue.

    Incase you are again prompted by the same message run shutdown -a (also suggested above). This would let the RogueKiller and MBAM to run completely.


    Author Closing Comment

    sorry for getting back to you until now. I was move from this project to other. I gave the information to my coworkers in charge of this project now. They found out that was a virus as you said.

    Thank you

    Featured Post

    How to improve team productivity

    Quip adds documents, spreadsheets, and tasklists to your Slack experience
    - Elevate ideas to Quip docs
    - Share Quip docs in Slack
    - Get notified of changes to your docs
    - Available on iOS/Android/Desktop/Web
    - Online/Offline

    Join & Write a Comment

    Issue: Unstable cursor in Windows XP and Windows runs extremely slow in that any click will bring up the Hour glass (sometimes for several seconds before giving you what you want) . Troubleshooting Process and the FINAL FIX: This issue see…
    For both online and offline retail, the cross-channel business is the most recent pattern in the B2C trade space.
    This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
    Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    15 Experts available now in Live!

    Get 1:1 Help Now