My computer's spontaneously shutting down.

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18679
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

My computer's spontaneously shutting down.

Post by Rogue 9 »

Error Message wrote:This system is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was authorized by NT AUTHORITY\SYSTEM. Timer countdown.

The system process C:\WINDOWS\system32\lsass.exe terminated unexpectedly with status code -1073741819. The system will now shut down and restart.
Anybody know what the hell this is? I have no clue how long I have until it does this again; it just happened twice within five minutes. Its doing it again right now. What the hell?

Okay, that's all of it. I'm running Windows XP. What gives? Its done it five times now.
Last edited by Rogue 9 on 2004-05-03 04:30pm, edited 3 times in total.
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
Hamel
Sith Marauder
Posts: 3842
Joined: 2003-02-06 10:34am
Contact:

Post by Hamel »

2000/NT/XP?

This happens when ya end one of the svchost processes in task manager. Something might be killing it.
"Right now we can tell you a report was filed by the family of a 12 year old boy yesterday afternoon alleging Mr. Michael Jackson of criminal activity. A search warrant has been filed and that search is currently taking place. Mr. Jackson has not been charged with any crime. We cannot specifically address the content of the police report as it is confidential information at the present time, however, we can confirm that Mr. Jackson forced the boy to listen to the Howard Stern show and watch the movie Private Parts over and over again."
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18679
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

I'm getting as much of it as I can while the timer's running. That's almost all of it.
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
Hamel
Sith Marauder
Posts: 3842
Joined: 2003-02-06 10:34am
Contact:

Post by Hamel »

Rogue 9 wrote:I'm getting as much of it as I can while the timer's running. That's almost all of it.
Try running in safe mode, and if possible, scan for viruses. Something is killing critical system processes.
"Right now we can tell you a report was filed by the family of a 12 year old boy yesterday afternoon alleging Mr. Michael Jackson of criminal activity. A search warrant has been filed and that search is currently taking place. Mr. Jackson has not been charged with any crime. We cannot specifically address the content of the police report as it is confidential information at the present time, however, we can confirm that Mr. Jackson forced the boy to listen to the Howard Stern show and watch the movie Private Parts over and over again."
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18679
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

Won't let me get through a virus scan. Not enough time. It seems to be getting more frequent.
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
Hamel
Sith Marauder
Posts: 3842
Joined: 2003-02-06 10:34am
Contact:

Post by Hamel »

Rogue 9 wrote:Won't let me get through a virus scan. Not enough time. It seems to be getting more frequent.
Boot from your OS' CD and use the recovery console to repair your installation. At the most you would replace the OS, and would not lose your other files.
"Right now we can tell you a report was filed by the family of a 12 year old boy yesterday afternoon alleging Mr. Michael Jackson of criminal activity. A search warrant has been filed and that search is currently taking place. Mr. Jackson has not been charged with any crime. We cannot specifically address the content of the police report as it is confidential information at the present time, however, we can confirm that Mr. Jackson forced the boy to listen to the Howard Stern show and watch the movie Private Parts over and over again."
User avatar
Dahak
Emperor's Hand
Posts: 7292
Joined: 2002-10-29 12:08pm
Location: Admiralty House, Landing, Manticore
Contact:

Post by Dahak »

That, my friend, is the sasser virus.
Useful information
Image
Great Dolphin Conspiracy - Chatter box
"Implications: we have been intercepted deliberately by a means unknown, for a purpose unknown, and transferred to a place unknown by a form of intelligence unknown. Apart from the unknown, everything is obvious." ZORAC
GALE Force Euro Wimp
Human dignity shall be inviolable. To respect and protect it shall be the duty of all state authority.
Image
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18679
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

Damn, its doing it again and the virus scan didn't find it first. :evil:
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
Dahak
Emperor's Hand
Posts: 7292
Joined: 2002-10-29 12:08pm
Location: Admiralty House, Landing, Manticore
Contact:

Post by Dahak »

Rogue 9 wrote:Damn, its doing it again and the virus scan didn't find it first. :evil:
Download the patch here.
Download removal tool here.
Image
Great Dolphin Conspiracy - Chatter box
"Implications: we have been intercepted deliberately by a means unknown, for a purpose unknown, and transferred to a place unknown by a form of intelligence unknown. Apart from the unknown, everything is obvious." ZORAC
GALE Force Euro Wimp
Human dignity shall be inviolable. To respect and protect it shall be the duty of all state authority.
Image
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18679
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

Shuts down before the download completes. I've been trying it.
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
Hamel
Sith Marauder
Posts: 3842
Joined: 2003-02-06 10:34am
Contact:

Post by Hamel »

Rogue 9 wrote:Shuts down before the download completes. I've been trying it.
Have you tried safe mode or the recovery console yet?
"Right now we can tell you a report was filed by the family of a 12 year old boy yesterday afternoon alleging Mr. Michael Jackson of criminal activity. A search warrant has been filed and that search is currently taking place. Mr. Jackson has not been charged with any crime. We cannot specifically address the content of the police report as it is confidential information at the present time, however, we can confirm that Mr. Jackson forced the boy to listen to the Howard Stern show and watch the movie Private Parts over and over again."
User avatar
Dahak
Emperor's Hand
Posts: 7292
Joined: 2002-10-29 12:08pm
Location: Admiralty House, Landing, Manticore
Contact:

Post by Dahak »

Rogue 9 wrote:Shuts down before the download completes. I've been trying it.
When it shuts down, go to start menu -> run, and type "shutdown -a" in it.
Image
Great Dolphin Conspiracy - Chatter box
"Implications: we have been intercepted deliberately by a means unknown, for a purpose unknown, and transferred to a place unknown by a form of intelligence unknown. Apart from the unknown, everything is obvious." ZORAC
GALE Force Euro Wimp
Human dignity shall be inviolable. To respect and protect it shall be the duty of all state authority.
Image
User avatar
Rogue 9
Scrapping TIEs since 1997
Posts: 18679
Joined: 2003-11-12 01:10pm
Location: Classified
Contact:

Post by Rogue 9 »

WOOHOO! VICTORY IS MINE! :D It was Sasser B. I just hope there's not another copy on here...

Edit: The file name was C:\WINDOWS\avserve2.exe
It's Rogue, not Rouge!

HAB | KotL | VRWC/ELC/CDA | TRotR | The Anti-Confederate | Sluggite | Gamer | Blogger | Staff Reporter | Student | Musician
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

This is why you routinely go to Windows Update or have it automatically update for you. The patch has been out for more than two weeks.
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

Do your self and the world a favour.

Put a router/hardware/software firewall between your computer and the internet and block the TCP/IP ports: 139-445.

Those ports have known security issues, do not allow them to be exposed to the internet. Exposing this ports to the internet is a stupid(And in Australia aurgably criminal) thing todo.
Last edited by Xon on 2004-05-05 01:17am, edited 1 time in total.
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Why not everything below, say, 1500-2000 (exempting P2P software)? Anyway, I just nmapped the win2k computer upstairs (not mine, my sister's).

Nmap of Win2k computer upstairs:

Code: Select all

135/tcp  open  msrpc
139/tcp  open  netbios-ssn
389/tcp  open  ldap
445/tcp  open  microsoft-ds
1002/tcp open  windows-icfw
1025/tcp open  NFS-or-IIS
1720/tcp open  H.323/Q.931
Can anyone explain what is happening above? I'm not a windows expert.

Also note that this computer is deliberately connected to the internet w/o any software firewall, since it interferes with internet connection sharing (so how do I rectify this and still allow ICS to work.. yes, I will claim writing IPTables scripts is 1000x easier to understand)(my sister insists on having it dial out directly when she is home, despite the fact that things are noticibly faster when things are routed through a caching proxy server :roll: . She also insists on using IE... it's been amazing how no malware is on it yet (then again, lots of malware probably is on it, just undetected due to lack of spyware removal programs)).

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

You are playing with fire not having anything on it. If she gets hit, browbeat her into letting you put something on ... and software firewalls should cooperate with ICS since you have the option of only blocking the dial-up networking adapter.

Port 135 is the Remote Procedure Call service. You can't shut that down.
Port 139 is for NetBIOS-based SMB/CIFS networking
Port 389 is for LDAP authentication (i.e. ActiveDirectory)
Port 1002 looks like its related to the built-in Windows firewall but it can also be used for NetMeeting
Port 1025 is related to IIS ... does she have Personal Web Sharing enabled?
Port 1720 is for various interactive media stuff.
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

I don't think she is using PWS or videoconferencing.... oh, and the udp scan:

Code: Select all

PORT    STATE SERVICE
53/udp  open  domain
135/udp open  msrpc
137/udp open  netbios-ns
138/udp open  netbios-dgm
445/udp open  microsoft-ds
500/udp open  isakmp
I've never gotten IPSEC to work w/ ICS blocking all ports listed by nmap or using KPF w/o having timeout errors, even with sharing explicitly enabled for KPF... need to look at it if/when computer upstairs gets nuked, since currently not allowed to use computer.

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
Stark
Emperor's Hand
Posts: 36169
Joined: 2002-07-03 09:56pm
Location: Brisbane, Australia

Post by Stark »

I occassionally get the same error and shutdown after a few hours of downloading with emule; I've got no virus activity tho. Bloody emule :)
Post Reply