Forum Settings
       
Reply To Thread

C:\WINDOWS\Sytem32\lsass.exe and LSA Shell (Export Ver.)Follow

#1 May 02 2004 at 1:02 AM Rating: Decent
WTF is this? I think there is some kind of virus or program on my server (Quetzalcoatl) which is causing computers to restart during FF XI. My roomate has NEVER downloaded a program asides from the FF XI patches and has experienced this as well. This is a serious problem, which is spreading, but I am uncertain of how many people are dealing with this. Somehow, it's downloaded onto your computer when you log onto FF XI. I know someone else on my server who mentioned it. I dont know much about viruses, but I never would have imagined that we could get one on the PlayOnline server. This is no hoax, slowly, you will notice more and more people talking about this. I am currenlt awaiting a response to a GM call... anyone else having trouble with this virus / bug?

Lovewind
Quetzalcoatl

P.S. - I read the prior post about someone else having restarting issues, I am not sure if this is the same problem. I have attempted to uncheck the automatic restart, but this seems like a temporary solution.
#2 May 02 2004 at 1:06 AM Rating: Decent
***
1,121 posts
yes please someone help us i have to go thru many hours reinstalling ffxi and swg now because of this stupid problem i even have the comp techs from my work helping me out a little working in a casino can come in handy but they arent sure what the problem is
#3 May 02 2004 at 1:25 AM Rating: Decent
http://ffxi.allakhazam.com/forum.html?forum=28&mid=108346771867782838&num=0


I dont know why this guy's post is in off topics, but check it out.
#4 May 02 2004 at 2:01 AM Rating: Decent
W32.Sasser.Worm and W32.Sasser.B.Worm are brand new worms, which means you need to update your virus definitions ASAP and nuke the damn thing! Norton Antivirus = BLM!!! Research is so good. I hope this link sheds some light on the issue:

http://securityresponse.symantec.com/avcenter/vinfodb.html?prodid=nav2003
#5 May 03 2004 at 2:20 AM Rating: Good
Sasser is a rather nasty Blaster varient.

If you can still get online on the infected computer:
[li] Press Start
[li] Go to Run
[li] Type in services.msc
[li] On the Local Services list, double-click on Internet Connection Firewall ICF
[li] Set the Startup Type to Automatic
[li] In the Service Status area, press Start to enable your Windows XP firewall. (It's better than nothing when it comes to keeping worms out)

If you can't get this to work, try booting to Safe Mode and enabling it there.

Now go online to http://securityresponse.symantec.com/avcenter/FxSasser.exe and download and run the removal tool. Follow the instructions carefully.
There are currently 3 known variations of the Sasser worm, (according to Norton).

Make sure to go online to http://v4.windowsupdate.microsoft.com/en/default.asp when the removal is complete, so that you can download the most current Critical Updates.


If the 60 second timer turns on at any point:
[li] Press Start
[li] Go to Run
[li] Type in shutdown -a

This will turn off the timer, and allow you to continue with the removal process.

Resetting or disabling the RPC timer in Safe Mode only gets results in a few cases with this version of Blaster.
It's better just to do the Shutdown -a.

Edited, Mon May 3 03:46:53 2004 by LadyOfHolyDarkness

Edited, Mon May 3 20:25:03 2004 by LadyOfHolyDarkness
#6 May 03 2004 at 2:50 AM Rating: Good
{OBSOLETE POST}

Edited, Mon May 3 19:53:17 2004 by LadyOfHolyDarkness
Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 96 All times are in CST
Anonymous Guests (96)