Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
window xp shutdown problem
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > window xp shutdown problem  
Forum Quick Jump
 
New Topic Post reply to : window xp shutdown problem Printable version of : window xp shutdown problem
[ << Previous Thread | Next Thread >> ]

sid
New Member


Date Joined Jun 2004
Total Posts : 1
 
   Posted 7-14-2004 8:36 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
 hi guys if any body know the solution of window xp shutdown problem plz tell us the path of the file is c:/windows/system32/lsass.exe

Post Edited (sid) : 7/14/2004 7:40:25 AM GMT

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 7-18-2004 9:54 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Give more info-plz. Is it countdown problem, or?
Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 7-18-2004 4:12 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Sounds a bit like msblast (and lord I hope not) but if it is I think bullguard still has a removal tool for it, but to make sure you can go to your regedit, edit , find, type in msblaster click ok if it's there it will rear it's mighty ugly head. same with sasser
the file path you show looks like MS's patch download to safeguard this. check www.bullguard.com and see if tool is there, and while there download the 60 day trial it works. good luck and keep me posted.

Eagle smilewinkgrin
Back to Top
 

amar
New Member


Date Joined Jun 2004
Total Posts : 3
 
   Posted 7-19-2004 9:28 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
sid said...
hi guys if any body know the solution of window xp shutdown problem plz tell us the path of the file is c:/windows/system32/lsass.exe
Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 7-19-2004 4:13 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Keep me posted.
Eaglesmilewinkgrin
Back to Top
 

SClyde
New Member


Date Joined Jun 2004
Total Posts : 20
 
   Posted 7-28-2004 11:58 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
PASS ME THAT JOINT!  WHAT ARE YOU SMOKING?
 
c:/windows/system32/lsass.exe
 
all that is the Windows Local Security Authority Server Process son! it handles Windows security mechanisms and verifies the validity of user logons to your computer. WHICH means all it does is  generates the process that is responsible for authenticating users for the Winlogon service.
It's not a virus, not spyware, adware, its PART OF THE SYSTEM!
 
OK , WHAT  HAPPENED WAS YOU HAVE ONE OF THE MOST VIRULENT/Violent VIRUSES ON THE INTERNET! THE NEW SASSER WORM HAS INFECTED YOUR lsass.exe file!  MAN THATS NOT COOL AT ALL..  THIS VIRUS IS LIKE THE LANCE ARMSTRONG OF 2004 VIRUSES! CUZ LIKE YOUR PC LIKES TO REBOOT EVERY 260 SECONDS WHEN IT HAS BEEN EFFECTED WITH THE SASSER WORM!
IF YOU HAVE THE SASSER WORM YOU WILL NEED TO GET ON ANOTHER COMPUTER TO READ THIS BUT ONCE YOUR COMPUTER HAS BEEN TURNED ON YOU HAVE A LITTLE OVER 260 SECONDS TO
Press the Start button, and then the Run menu item.
Type shutdown -a. That's the "shutdown" command, with the "-a" option, which stands for "abort the pending shutdown".
Press OK.
 
SO WHAT DOES THAT DO? IT STOPS YOUR PC FROM SHUTTIN DOWN EVERY ALMOST EVER 260 SECONDS... BUT DUDE THE VIRUS IS STILL THERE.. AND MAN.. ITS NOT A VIRUS TO BE RECKONED WITH.
 
THIS VIRUS IS SO SERIOUS YOU WOULDN'T KNOW! A F'KIN GENUIS VIRUS! This worm scans RANDOM, JUST RANDOM IP addresses for exploitable systems. When one is found, the worm exploits the vulnerable system, by overflowing a buffer in LSASS.EXE. It creates a REMOTE SHELL on TCP port 9996. Next it creates an FTP script named cmd.ftp on the remote host and executes it. This FTP script instructs the target victim to download and execute the worm (with the filename #_up.exe as aforementioned) from the infected host. The infected host accepts this FTP traffic on TCP port 5554. THEN THE worm TAKES ENDLESS VACATIONS on multiple threads, some of which scan the local class A subnet, others the class B subnet, and others completely random subnets (SOOOO GENUIS). The destination port is TCP 445
ITS DELETING/ADDING SPACE/....(basically its like you have a gurlfriend AND YOU LOVE HER ALOT and THIS VIRUS IS A GUY thats having sex with her and you cant do shit about it CUZ HES LOADED WITH 12 GUAGES, AK 47's, GRENADES AND HE AINT AFRAID TO USE IT)
 
IF YOU WANT 2 DELETE IT TAKE THESE FOLLOWIN STEPS
 
0.DOWNLOAD http://vil.nai.com/vil/stinger , RUN IT, and
Then Remove AS MUCH OF IT AS YOU CAN
1.TURN OFF SYSTEM RESTORE
2.RESTART IN SAFE MODE
3.Delete the file AVSERVE2.EXE from your WINDOWS directory FROM EITHER c:\windows or c:\winnt
4.THEN, HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Windows>CurrentVersion>Run
5.Delete the "avserve2" value
6. DELETE \windows\system32\*_up.exe .
Reboot the system into Default Mode
 
EDIT :
stay up man, this virus is fatal. Stay Up.

 
 
 

Post Edited (SClyde) : 7/28/2004 11:04:30 PM GMT

Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 7-29-2004 2:26 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Sclyde,

sasser ain't sub seven dude What you been smokin. all you have to do is go into regedit , edit key, find type in "sasser" hit enter and wahlah! there it is in it's glory ll you have to do is delete from the regedit. But do turn off the system restore and do a disk clean remove all restore points first then do a cold boot . real hard huh?

Eagle smilewinkgrin
Back to Top
 

SClyde
New Member


Date Joined Jun 2004
Total Posts : 20
 
   Posted 7-29-2004 10:54 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
eagle, I have the virus, If you want to experiment your way of deletion on it, I will send it you by email.
 
Its great to understand that way worked for you, but that way is far beyond my comprehension, cause when I JUST TRIED that now, there is over 50 keys linked to the sasser, and one being the system itself. So deleting that key would automatically cause my computer to not function.  Welp, i'm glad its so easy for you.  Just give me a email address to send it to, and It'll be there with the subject "Sasser -  Experimental Use"

Post Edited (SClyde) : 7/29/2004 10:35:38 PM GMT

Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 7-30-2004 1:34 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
No need to get rude dude, but seriously, if you turn off system restore first then do what I said the you could turn the restore back on for the reboot and the bad file will be gone and your system will fix itself. If you remove all restore points it will automatically go back to it's original configuration. Oh threaten me like that again and I'LL send you something you aint gonna want to play with.

Eagle smilewinkgrin


Oh BTW I believe bullguard.com still has a removal tool for that particular virus .
Back to Top
 

SClyde
New Member


Date Joined Jun 2004
Total Posts : 20
 
   Posted 7-31-2004 12:53 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
honestly, I would appreciate it if you sent the virus to
I like to experiment on how viruses and how they function(I have a preety good selection),
so please send it and it would be more than appreciated.
 
Regards,
SClyde
Back to Top
 

Ricardo
New Member


Date Joined Aug 2004
Total Posts : 5
 
   Posted 8-14-2004 1:41 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
good thing that that german guy who made it is gone but the virus is still on the net :(
Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 8-14-2004 5:37 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Ain't that the truth,

thing is sclyde does have some good methods for removal but I wish he would leave the tude at home.

Eagle smilewinkgrin
Back to Top
 

acornbutter
New Member


Date Joined Aug 2004
Total Posts : 6
 
   Posted 8-25-2004 9:37 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
I think I've had the same virus and you've probably had days or weeks of stress trying to remove it,but the only way I found to remove it was to back up the files and wipe the computer.And I wish I'd done that in the first place.
Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 8-26-2004 1:44 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Only problem with that acorn, is that if it's like blaster then it will leave a piece of itself on the drive so when you reinstall it says hello.

Eagle smilewinkgrin
Back to Top
 

acornbutter
New Member


Date Joined Aug 2004
Total Posts : 6
 
   Posted 8-26-2004 10:17 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Actually its ran perfectly for months until I put kazaa on .But its got a trojan virus now,and I can't access loads of websites.
Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 8-27-2004 4:47 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Acorn disable or uninstall all anti-viruses and download Bullguard(bullguard.com) and scan. Don't use the one off of kazaa that is part of the problem (kazaa). It would not hurt to uninstall kazaa. If your running XP turn off system restore. If you don't know how to do that just post me and I'll help out. After you do your scan send your vscan logs to support@bullguard.com they can help with things better than I can. Good luck and keep me posted.

Eagle smilewinkgrin
Back to Top
 

acornbutter
New Member


Date Joined Aug 2004
Total Posts : 6
 
   Posted 8-28-2004 11:56 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
    
       :-)  I've got this problem sorted now,by emptying temp and temporary files,thus getting rid of the trojan,and then downloading 2 webfixes from www.webfixes.co.uk. Rather than getting rid of kazaa,I'm probably just going to exit when I'm not using it,when I log or switch on.Also I've set the bullguard slightly to 1.clean and 2.delete the infected files,on their advice,as the trojans can't be disinfected only deleted,so cross fingers it should be ok.

Post Edited (acornbutter) : 8/28/2004 11:17:48 AM GMT

Back to Top
 

eagle
Senior Member


Date Joined May 2004
Total Posts : 805
 
   Posted 8-28-2004 2:21 (GMT +1)    Quote: window xp shutdown problemAlert an admin about: window xp shutdown problem
Sounds Good to me.
All except the leaving the kazaa in.

Eagle smilewinkgrin

Keep me posted though.
Back to Top
 
New Topic Post reply to : window xp shutdown problem Printable version of : window xp shutdown problem
 
Forum Information
Currently it is Saturday, November 22, 2008 2:20 PM (GMT +1)
There are a total of 64.050 posts in 15.836 threads.
In the last 3 days there were 26 new threads and 157 reply posts. View Active Threads
Who's Online
This forum has 27196 registered members. Please welcome our newest member, Catlady UK.
53 Guest(s), 1 Registered Member(s) are currently online.  Details
r1ch1e
5 Latest Threads
Antivirus trigger is now the threat or what? (6)22-11-2008 13:01:06 (thegascomp)
Generic.PWS.WoW.B7078E0 (16)22-11-2008 11:55:15 (Behram)
Redirecting virus? (5)22-11-2008 10:29:08 (r1ch1e)
Help please!!! (15)22-11-2008 10:05:45 (Touch)
HELP I AM GOING MAD (5)22-11-2008 06:51:49 (Touch)