"This system is shutting down"...and there's nothing I can do!!

Sulaco

Diamond Member
Mar 28, 2003
3,825
46
91
k guys, I have a real b!tch of a problem that seems very serious and I just can't crack.

I'll try and provide as much information as I can.

About a week or so ago I got a new motherobard and CPU. So I install it just fine, and reformat Windows. All goes smoothly it seems. I install all my drivers, put on some games, and get online. A few days go by and everythings running without a hitch.

Then it happens.

Upon trying to get online one day, I receive this error message from windows:

":This System is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY\SYSTEM

Time before shutdown: (a timer counting down from 1 minute)

Message: The system process C:\Windows\SYSTEM\lsass.exe terminated unexpectedly with status code -1073741819. The system will now shutdown and restart"



At which point when the timer hits zero, the system restarts.

So I decided to do some research, and ran across some other people in the past who had similar errors. Everyone jumped to the conclusion it was the sasser virus. So since I had just recently installed windows and had nothing to lose, I decided to reformat.

Sure enough, within a day of reinstalling windows from scratch and connecting to the internet, this same message keeps showing up. I have not been anywhere, or downloaded anything. I installed SP1 and all updates on the Security Disk Microsoft sent me, so my system does have SP1. This ONLY happens after connecting to the internet.

I've spent the last day or so studying this and collecting as much info about it as I could for you guys. Here's some other things:

-Only happens right after connecting to the internet.

-Once the machine has restarted and Windows is loaded, I get an error message saying: "LSA Shell (Export Version) has encountered a problem and needs to close". The error signature reads: "szAppName: lsass.exe".

-While the "System shut down" error is being displayed, the System Properties dialog box under Control Panel does not display the System Restore, Automatic Updates, or Remote tabs. Clicking the Computer Name tab brings up this curious error message: "Computer Name Changes: The following error occured while attempting to read domain membership information: THE RPC SERVER IS UNAVAILABLE"


So I'm thinking there's something majorly f'd up with "lsass.exe" and whatever it does.
I checked Microsoft's database, and apparently my problem is acknowledged under Windows 2000, but they say nothing about Windows XP. They also only say the problem is fixed with the latest Service Pack patch for Windows 2000.


If you guys can help, I WILL BE FORVER IN YOUR DEBT! Please let me know if you need to know any other details or anything.

Thanks!
 

boshuter

Diamond Member
Feb 11, 2003
4,145
0
76
It still sounds like the sasser virus..... do you have a firewall? If not enable the built in one in XP, if it is the sasser virus this should allow you to stay online long enough to go to Symantec's web site and downl the removal tool.... Good luck :)
 

Souka

Diamond Member
Sep 25, 2000
4,728
1
76
Also, you need to install the MS-critcal security updates.

The Sasser virus causes a component of windows to fail..which triggers the OS shutdown.


There are ways to delay this shutdown to 999seconds..... once you do that, you can go to MS and get updates.



Good Luck!
 

dclive

Elite Member
Oct 23, 2003
5,626
2
81
Originally posted by: Sulaco
k guys, I have a real b!tch of a problem that seems very serious and I just can't crack.

I'll try and provide as much information as I can.

About a week or so ago I got a new motherobard and CPU. So I install it just fine, and reformat Windows. All goes smoothly it seems. I install all my drivers, put on some games, and get online. A few days go by and everythings running without a hitch.

Then it happens.

Upon trying to get online one day, I receive this error message from windows:

":This System is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY\SYSTEM

Time before shutdown: (a timer counting down from 1 minute)

Message: The system process C:\Windows\SYSTEM\lsass.exe terminated unexpectedly with status code -1073741819. The system will now shutdown and restart"



At which point when the timer hits zero, the system restarts.

So I decided to do some research, and ran across some other people in the past who had similar errors. Everyone jumped to the conclusion it was the sasser virus. So since I had just recently installed windows and had nothing to lose, I decided to reformat.

Sure enough, within a day of reinstalling windows from scratch and connecting to the internet, this same message keeps showing up. I have not been anywhere, or downloaded anything. I installed SP1 and all updates on the Security Disk Microsoft sent me, so my system does have SP1. This ONLY happens after connecting to the internet.

I've spent the last day or so studying this and collecting as much info about it as I could for you guys. Here's some other things:

-Only happens right after connecting to the internet.

-Once the machine has restarted and Windows is loaded, I get an error message saying: "LSA Shell (Export Version) has encountered a problem and needs to close". The error signature reads: "szAppName: lsass.exe".

-While the "System shut down" error is being displayed, the System Properties dialog box under Control Panel does not display the System Restore, Automatic Updates, or Remote tabs. Clicking the Computer Name tab brings up this curious error message: "Computer Name Changes: The following error occured while attempting to read domain membership information: THE RPC SERVER IS UNAVAILABLE"


So I'm thinking there's something majorly f'd up with "lsass.exe" and whatever it does.
I checked Microsoft's database, and apparently my problem is acknowledged under Windows 2000, but they say nothing about Windows XP. They also only say the problem is fixed with the latest Service Pack patch for Windows 2000.


If you guys can help, I WILL BE FORVER IN YOUR DEBT! Please let me know if you need to know any other details or anything.

Thanks!

Sasser or a related worm.

You're on XP, so type shutdown -a at a command shell to abort the shutdown.

Install some antivirus products. Install ALL (ALL!) Windows updates from the Windows Updates site. Get SP2. Turn on the firewall.

Problem solved. :)
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Yeah, the worms will keep coming back until you plug the security vulnerability permanently. I had a home-office employee who took his firewall/router out from between his (then-unpatched) PC and his cable modem, and his VirusScan Enterprise was repelling worms pretty much non-stop.

My suggestions:

1) hardware firewall between your computer(s) and the broadband modem. I got a $45 Netgear RP614 for my sister recently, if you need a nominee.

2) Strong passwords for all your administrator-class accounts on your computer(s)

3) If you have more than one computer on your side of your firewall (like, if you have two or more computers sharing the Internet connection using a router), then activate WinXP SP2's firewall or install ZoneAlarm free version on each computer and set Trusted Zone Security to "High"

4) Patch your system at Windows Update (and Office Update too, if you have Microsoft Office) and enable Automatic Updates so it stays up-to-date.

5) Install, update and properly configure some antivirus software so that it deals with threats autonomously (meaning, it doesn't come to you asking what to do, it gets it dealt with... silently clean, else delete). If it lets you specify how frequently to update the definitions, have it do so daily (at work, we have them update hourly, or 4x per hour on the servers).

6) Run Microsoft Baseline Security Analyzer to check your system for vulnerabilities that Windows Update may not pick up.

You can find a link to MBSA, ZoneAlarm, AVG Free Edition Antivirus and some other stuff if you hit the bottom link in my signature below, and go to the Resources page.
 

TygGer

Senior member
Feb 20, 2003
393
0
76
I have the same problem on my laptop. Why didnt the reformat clean everything?
 

dclive

Elite Member
Oct 23, 2003
5,626
2
81
Originally posted by: TygGer
I have the same problem on my laptop. Why didnt the reformat clean everything?

It did. Then the moment he took an unpatched system onto the internet, he was infected again.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: dclive
Originally posted by: TygGer
I have the same problem on my laptop. Why didnt the reformat clean everything?

It did. Then the moment he took an unpatched system onto the internet, he was infected again.
Yeah ^ If you need a stopgap measure (I'm assuming WinXP here) then here's a Security Rollup Kit that should plug the vulnerability so you can fully patch the system and get your defenses set up. A router like the Netgear RP614, Linksys BEFSR11 or BEFSR41, or a similar unit from D-Link, SMC etc, would still be a great idea since they don't cost much.
 

oldman420

Platinum Member
May 22, 2004
2,179
0
0
i cant beleive that you did not have a firewall up even xp firewall will stop sasser. let this be a lesson be prepared and keep abreast of security online. you dont have to do anything but connect to catch a bug nowadays.
no offense
jerome
 

dclive

Elite Member
Oct 23, 2003
5,626
2
81
Originally posted by: TygGer
Are dial-ups less succeptible to being compromised?

Nope. A few minutes online without a firewall, and you're owned. (Assuming an unpatched system.)
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: dclive
Originally posted by: TygGer
Are dial-ups less succeptible to being compromised?

Nope. A few minutes online without a firewall, and you're owned. (Assuming an unpatched system.)
Yeah, check out my ZoneAlarm screenie here. Plenty of wormy love for us dial-up users :Q
 

Confused

Elite Member
Nov 13, 2000
14,166
0
0
Originally posted by: dclive
Originally posted by: TygGer
Are dial-ups less succeptible to being compromised?

Nope. A few minutes online without a firewall, and you're owned. (Assuming an unpatched system.)

A few minutes?

I was infected within 10 seconds of connecting the the internet on one occasion (server (which has firewall etc) was down, so wasn't sharing net connection, hooked laptop (with fresh copy of XP) directly up to cable modem)


Confused