IPB

Welcome Guest ( Log In | Register )

> lsass.exe, system restart
Yume
post Jan 11 2005, 19:12
Post #1


challenger
**********

Group: Jounin
Posts: 3875
Joined: 4-March 04




Es tūlīt sākšu grauzt galda malu. Man katras 3-4 minūtes ir restarts , jo redzieties lsass ir izdomājis ka grib pieļaut čupu ar ķļūdām un izslēgties.
Kas tas ir? Un ko ar to dara?
Tāda lieta kā system shutdown man ir atslēgta, Nortons vīrusus neredz, a man šis mūžīgais restarts jau nierēs sēž.
varbūt kāds būs tik gudrs un pateiks kas un ko ar to jādara?


--------------------
IPB Image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
 
Reply to this topicStart new topic
Replies
MareX
post Jan 11 2005, 23:52
Post #2


Heimin
*

Group: Chuunin
Posts: 17
Joined: 27-December 04




Kaa jau agraaak "edg" mineeja tas visticamaak ir Sasser viirusa paveids -> links (liidziigs gadiijums)...

Vari pameegjinaat izdariit sekojosho...

1) Atrodi kaadu Sasser removal tool (ieteicams jaunaako)... piem Symantec, Microsoft, McAfee AVERT Stinger.

2) Lejuplaadee manis jau iteikto SafeXP.

3) Ieteicams jau laiciigi pamekleet kaadu ugunsmuuri... piem Microsoft (Win XP iebuuveetais), citi...

4) Atvieno datoru no interneta un jebkaada datoru tiikla...

5) Palaid Sasser removal tool (ieteicams to dariit nostarteejot datoru Safe Mode)... seko instrukcijaam...

6) Palaid SafeXP un saliec vismaz shaadas opcijas (iteicams)...
* Disable Remote Desktop support
Prevents your machine from having the ability to be remotely controlled by a system administrator or via the internet.
* Disable Remote Registry service
Disallows remote computers to access and modify the registry on the local computer.
* Disable RPC Locator service
Prevents your machine from using a specially malformed argument to be executed with system privileges by an attacker. The Locator service is not enabled by default except on Windows 2000 domain controllers and Windows NT 4.0 domain controllers
* Disable Windows Update service
Changes Windows automatic updates to manual mode(jo dazhi viirusi prot Windows Auto Update izmantot sev par labu).
* Disable UPNP/SSDP service
UPnP is a set of communications protocol standards that allow networked TCP/IP devices to announce their presence to all other devices on the network and to then inter-operate in a flexible and pre-defined fashion. There are currently limited UnPnP devices available and due to a recent security flaw it's advisable to disable this service. This also allows you to disable Universal Plug and Play Network Address Translation discovery which uses the Simple Service Discovery Protocol (SSDP) to reduce bandwidth and increase security.
* Disable support for DCOM
Distributed Component Object Model, or DCOM, provides a method for distributed network applications to communicate with one another. This setting allow you to disable support for DCOM.
* Disable the POSIX Subsystem
Windows 2000 and XP still come with the POSIX subsystem which allows the use of Unix commands against your system.
* Enable Windows File Protection
Windows File Protection (WFP) protects certain files that are key to the Windows 2000/XP operating system. These files are protected to prevent deletion of key files, unauthorized updating, and file damage that may be caused by viruses.
* Protect Against SYN Flood Attacks
Windows includes protection that allows it to detect and adjust when the system is being targeted with a SYN flood attack (a type of denial of service attack). When enabled the connection responses time out more quickly in the event of an attack.
* Prevent Denial of Service Attacks
Denial of service attacks are network attacks that are aimed at making a computer or a particular service unavailable to network users. These settings can be used to increase the ability for Windows to defend against these attacks when connected directly to the Internet. It also eliminates DHCP vulnerability.
* Disable listening on TCP port 445
Disables the raw SMB transport to cause malicious NetBIOS attacks and protect users from inadvertently exposing files on their computers, and also to block worms which spread via open file shares.

7) Pirms pievienot datoru atpakalj internetam (datoru tiiklam)... ieteicams uzinstaleet un aktivizeet kaadu no 3. punktaa mineetajiem ugunsmuuriem.

Good Luck!!!


--------------------
image
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Posts in this topic
Yume   lsass.exe   Jan 11 2005, 19:12
Kikumi   Dabon sev Spybot un paskaties, kas notiekās... :ph...   Jan 11 2005, 19:15
Yume   vēl 2 minūtes palika.. Kikumi, kur viņu var ķert? ...   Jan 11 2005, 19:25
Sigfa   ar spybot tur neko neizdariisi. Taa ir sisteemas k...   Jan 11 2005, 19:29
Kikumi   Nu, nez, man to kaut kāds kompjūteru frīks ieinsta...   Jan 11 2005, 19:29
Dzonis   tas ir lsass.exe vai isass.exe..?isass.exe - tad a...   Jan 11 2005, 19:34
Kikumi   Kaspersky Anti-Virus Personal... :ph34r:   Jan 11 2005, 19:36
Yume   Man Norton Profesional un neatrod. Nezinu, nav jau...   Jan 11 2005, 19:51
Kikumi   Beidzot atjēdzos, kas tas ir par gļuku. Man arī di...   Jan 11 2005, 19:53
Yume   Man tā kādu pus gadu atpakaļ bija, un nekas, pēc p...   Jan 11 2005, 19:55
edg   Yume, tavaa datoraa ir Sasser viiruss (worm) vai t...   Jan 11 2005, 20:20
Seven_of_zero   Man liekas ka zinu. kas par lietu. labais klik uz ...   Jan 11 2005, 20:36
dark ruin   Vari pameginat izdarit System Restore. Man personi...   Jan 11 2005, 21:04
Yume   Op, nezinu kā būs pēc piecam minūtēm, bet pagaidām...   Jan 11 2005, 22:02
Hideki   Nav atkal parādijies tas vīruss sistēmā? Vinš vis...   Jan 11 2005, 22:26
Yume   Ek, es vairs nezinu kā ir jabūt, bet šķiet ka tā, ...   Jan 11 2005, 22:47
MareX   Kaa jau agraaak "edg" mineeja tas vistic...   Jan 11 2005, 23:52
edg   Par probleemas atkalparaadiishanos: * peec viirusa...   Jan 12 2005, 00:03
zenofex   Aizmirsu veel atgaadinaat - Windows apdeitus jaasa...   Jan 12 2005, 00:44
Laugh|nGMan   Zelta vārdi :D Vajadzīgs tikai ielāps. Bet viņu...   Mar 9 2005, 11:00
MareX   Tiko tikai pamaniiju... shito postu... Informaac...   Jan 12 2005, 04:07
MareX   Veidi kaa izsargaaties no shaada tipa viirusem (ne...   Jan 12 2005, 04:29
deBUGa   Ņja... tas ir sāpīgs pasākums... Vienreiz iemanījo...   Jan 12 2005, 09:44
Inc   Antivīruss rokas neiztaisnos.   Jan 12 2005, 09:59
Yume   Oi, tagad zināšu ko darīt, un ceru ka man pietiks ...   Jan 12 2005, 13:42
ETM   shutdown -a   Mar 9 2005, 11:06
Laugh|nGMan   Nu Yume! Tagad viss ir tavās rokās. :rolleyes:   Mar 9 2005, 11:40
ETM   emmm... tas topiks ir 2 meeneshus vecs. shaubos, v...   Mar 9 2005, 12:04
Yume   Tu vari smieties, bet ir.. Es tiku galā ar system ...   Mar 9 2005, 23:21
JurCHiX   Yume.. neilgi pēc šī topica izveidošanas, man bija...   Mar 9 2005, 23:29
Yume   Man ir tāds prikols, ka jau tā ir paša lsass vaina...   Mar 10 2005, 01:02
ETM   OK, tas vairs pat nav smiekliigi. 2 meeneshus ar s...   Mar 10 2005, 15:17
Yume   Man pašlaik ir problēma, nav xp prof, ar offisu ne...   Mar 13 2005, 13:59
gix   nekadu problemu, 1mais solis nonjemam automatisko ...   Mar 13 2005, 20:00
Taka   Firewalls nav vajadzīgs. Un Client for Microsoft N...   Mar 13 2005, 21:06


Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 16 June 2025 - 13:02