Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 01-03-2006, 06:01 AM   #1
Member (10 bit)
 
regans cortina's Avatar
 
Join Date: Aug 2002
Location: LIVERPOOL U.K.
Posts: 930
Send a message via MSN to regans cortina
lsass.exe

Guys , one of my work collegues has as hp laptop , win xp home on it . and its just started rebooting on the logon screen . i get an error message saying lsass.exe, and then it reboots . Is this a virus ??? and can i save it ??????
__________________
Asus a8r 32mvp Deluxe motherboard, Athlon 64 4800+ Dual Core Socket 939 Water Cooled, 2048 Corsair ddr400 twin x xms pro + led lights, 2x Ati Radeon X1950XTX pci express graphics in crossfire mode, Creative soundblaster X-FI Fatal1ty series, Wd 80gb + Wd 40gb 7500 rpm se,WD Sata 2 500gb hd, Maxtor Diamondmax Plus 9 Sata 160 gb, External Maxtor OneTouch 250gb Firewired HDD, Thermaltake Tai Chi WaterCooled case, Enermax Noisetaker 600 watt Powersupply , Win Vista Ultimate Retail, 2 x Pioneer 111 16x16 Dual Layer dvdrw, Harmon kardon speakers, Samsung 226bw 22' widescreen
regans cortina is offline   Reply With Quote
Old 01-03-2006, 06:04 AM   #2
Member (8 bit)
 
(51)'s Avatar
 
Join Date: Feb 2003
Location: Sarasota, FL
Posts: 191
lsass - lsass.exe - Process Information

Process File: lsass or lsass.exe
Process Name: Local Security Authority Service

Description:
lsass.exe is a system process of the Microsoft Windows security mechanisms. It specifically deals with local security and login policies. This program is important for the stable and secure running of your computer and should not be terminated.

Note: lsass.exe also relates to the Windang.worm, W32.Spybot.ABDO, irc.ratsou.b, Webus.B, MyDoom.L, Randex.AR, Nimos.worm which spread via floppy disk drives, mass-mailing and peer-to-peer sharing. Please review file path for clarification of this.

Determining whether this process is a virus or a Windows process depends on the directory location it executes or runs from in WinTasks.


Read on:

http://ask-leo.com/what_are_lsass_ls...o_if_i_am.html

Last edited by (51); 01-03-2006 at 06:09 AM.
(51) is offline   Reply With Quote
Old 01-03-2006, 06:29 AM   #3
Member (10 bit)
 
regans cortina's Avatar
 
Join Date: Aug 2002
Location: LIVERPOOL U.K.
Posts: 930
Send a message via MSN to regans cortina
This is definately a virus ,. Ive been on symantecs website , and it says i should have 20 secs or so , to delay the shutting down . I cant do this because it only boots to the desktop picture , not with all the icons on !! So i cant go into the the command prompt and type whats needed. It shuts down instantly when that message appears.

Is there a fix ??
regans cortina is offline   Reply With Quote
Old 01-03-2006, 06:51 AM   #4
Member (10 bit)
 
Join Date: Mar 2003
Location: Nottingham UK or Kuala Lumpur Malaysia
Posts: 600
Send a message via ICQ to rave Send a message via AIM to rave Send a message via MSN to rave Send a message via Yahoo to rave
you could try to use the keyboard shortcuts...if your fast enough(works for me sometimes)

WindowsKey+R --> type "cmd" --> type this (note the space) "shutdown -a"

if you are able to stop the shutdown and get to a browser...better go get one of Symantecs Virus Removal Tools
rave is offline   Reply With Quote
Old 01-03-2006, 06:54 AM   #5
Member (10 bit)
 
regans cortina's Avatar
 
Join Date: Aug 2002
Location: LIVERPOOL U.K.
Posts: 930
Send a message via MSN to regans cortina
Ill try , If i cant do this , are we talking reformat ????
regans cortina is offline   Reply With Quote
Old 01-03-2006, 07:32 AM   #6
Member (10 bit)
 
regans cortina's Avatar
 
Join Date: Aug 2002
Location: LIVERPOOL U.K.
Posts: 930
Send a message via MSN to regans cortina
Nope , aint havin none of it. just found out she hasnt any antivirus on it.
regans cortina is offline   Reply With Quote
Old 01-03-2006, 08:02 AM   #7
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,538
Send a message via AIM to Panama Red
You have a Sasser worm or a variant of it. Here's a removal tool:

http://securityresponse.symantec.com...oval.tool.html

Sounds like your collegue doesn't have all the updates from MS installed. The monthly tool from MS, Malicious Software Removal Tool, would have taken care of Sasser too.
__________________
Computers have enabled people to make more mistakes faster than almost any invention in history,
with the possible exception of tequila and hand guns.

Last edited by Panama Red; 01-03-2006 at 08:17 AM.
Panama Red is offline   Reply With Quote
Old 01-03-2006, 09:01 AM   #8
Come in Ray...
 
faulkner132's Avatar
 
Join Date: Sep 2004
Posts: 1,668
I had a friend with this problem... never could get it to work. You can't get into safe mode either. I backed up all her files using a USB pen drive and Knoppix Linux then reformatted.
faulkner132 is offline   Reply With Quote
Old 01-03-2006, 09:14 AM   #9
Member (10 bit)
 
Join Date: Mar 2003
Location: Nottingham UK or Kuala Lumpur Malaysia
Posts: 600
Send a message via ICQ to rave Send a message via AIM to rave Send a message via MSN to rave Send a message via Yahoo to rave
Quote:
Originally Posted by faulkner132
I had a friend with this problem... never could get it to work. You can't get into safe mode either. I backed up all her files using a USB pen drive and Knoppix Linux then reformatted.
very smart move.never tought of that...hehehe
rave is offline   Reply With Quote
Old 01-03-2006, 09:20 AM   #10
Member (10 bit)
 
regans cortina's Avatar
 
Join Date: Aug 2002
Location: LIVERPOOL U.K.
Posts: 930
Send a message via MSN to regans cortina
Guys , i cant get into windows to do anything. It looks like she has never updated it or had any kind of antivirus on there. It instantly reboots as soon as the desktop picture comes on, then i get the error message then reboot. Is there a way of saving anything of it , or can a repair be done in dos ?????

The notebook is a hp nx9010
regans cortina is offline   Reply With Quote
Old 01-03-2006, 09:36 AM   #11
Shiro Usagi
Premium Member
 
Cricket's Avatar
 
Join Date: Sep 1999
Location: Kaneohe, Hawaii
Posts: 34,002
One way to work this is to remove the hard drive from the laptop and then install it in a desktop with a 2.5" HDD to 3.5" HDD adapter and then run a virus scan that way. Once the 2.5" HDD is clean you install it back in the laptop and see how it runs.

Also, could you please change the color of the font in your sig...the red lettering is really bothersome.

Cricket
Cricket is offline   Reply With Quote
Old 01-03-2006, 10:11 AM   #12
Come in Ray...
 
faulkner132's Avatar
 
Join Date: Sep 2004
Posts: 1,668
Quote:
Originally Posted by regans cortina
Guys , i cant get into windows to do anything. It looks like she has never updated it or had any kind of antivirus on there. It instantly reboots as soon as the desktop picture comes on, then i get the error message then reboot. Is there a way of saving anything of it , or can a repair be done in dos ?????

The notebook is a hp nx9010
As stated in my post above... use a Knoppix Linux Live CD and a USB pen drive to backup the data.

http://www.knoppix.org
faulkner132 is offline   Reply With Quote
Old 01-03-2006, 10:34 AM   #13
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 36,460
An alternative to Knoppix is a BartPE CD. If available, you can try someone's antivirus program that comes on a bootable CD, but the definitions are going to be quite stale. XP has no DOS so that's not really an option - you can boot with an XP CD and use the console, but there's not much you can do in there that would help this issue.
glc is offline   Reply With Quote
Old 01-03-2006, 11:18 AM   #14
Member (10 bit)
 
regans cortina's Avatar
 
Join Date: Aug 2002
Location: LIVERPOOL U.K.
Posts: 930
Send a message via MSN to regans cortina
Ok thanks for all the replies guys. Ill have a go at the knoppix . If i cant do it , she knows the worst case scenario.

Cheers
regans cortina is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 09:32 PM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0