A relative of mine (not nearby) called to tell me his brand new computer is shutting down when he tries to log onto the net. He's getting an error message something like this...
<i>"This shutdown was initiated by NT/authority/system
in system process
c/windows/system32/sass.exe
status code 1073741879..."</i>
Does this mean he has the "sasser worm"?
Can I download the FxSasser from Symantec onto a disc, and then run it on his computer? (Since I obviously won't be able to do any downloading on his computer until the problem is corrected.)
Thanks in advance.
Is this "Sasser" at work?
Moderator: Wiz Feinberg
-
Donny Hinson
- Posts: 21756
- Joined: 16 Feb 1999 1:01 am
- Location: Glen Burnie, Md. U.S.A.
-
Ray Minich
- Posts: 6431
- Joined: 22 Jul 2003 12:01 am
- Location: Bradford, Pa. Frozen Tundra
Yes, unfortunately, it's caused by Sasser or one of it's variants. I've worked on 3 Sasser victims in the past two weeks.
The LSASS service (process) in the operating system is being hit.
Go to symantec.com for removal instructions. Run the FxSasser & also check for the other symptoms discussed. Also you will have to upload the Windows Critical Updates from Microsoft for the OS to stop it from reoccurring.
One more thing, in the past 2 weeks I have also seen the LSASS subsystem shut a networked computer down, but the computer was not infected. Don't know what's going on there...<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Ray Minich on 13 May 2004 at 09:05 AM.]</p></FONT><FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Ray Minich on 13 May 2004 at 02:40 PM.]</p></FONT>
The LSASS service (process) in the operating system is being hit.
Go to symantec.com for removal instructions. Run the FxSasser & also check for the other symptoms discussed. Also you will have to upload the Windows Critical Updates from Microsoft for the OS to stop it from reoccurring.
One more thing, in the past 2 weeks I have also seen the LSASS subsystem shut a networked computer down, but the computer was not infected. Don't know what's going on there...<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Ray Minich on 13 May 2004 at 09:05 AM.]</p></FONT><FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Ray Minich on 13 May 2004 at 02:40 PM.]</p></FONT>