Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Help! Cannot Load Windows Desktop!, lsass.exe - System Error
FirefoxRocks
post Nov 27 2007, 11:05 PM
Post #1


Super Member
Group Icon

Group: [HOSTED]
Posts: 658
Joined: 12-July 06
From: Ontario, Canada
Member No.: 14,464



I found out about this error as I got home and discovered that no one used the computer because they couldn't get into Windows!
When I boot into Windows, the Welcome screen does not show up and instead shows an error that says:

lsass.exe - System Error

Click OK to terminate.
Click Cancel to debug.

No matter what you click, it will go away and leave a blank screen. Pressing CTRL+ALT+DEL or CTRL+SHIFT+ESC will not do anything and at that point you must restart.

Initially I went into Safe Mode and Windows loaded there (I'm still in Safe Mode). I tried a System Restore to yesterday's restore point and it didn't help. Since it started in Safe Mode, I assume it is a startup problem so I tried disabling various startup applications but all of them are disabled and it still doesn't work.

I tried using the Windows XP CD to "repair" the operating system, but I don't know what I can do at the command prompt other than
1. Change directory
2. Restore the MBR (wipe out Ubuntu Linux)

I tried booting into Ubuntu but it fails to mount the Windows partition because I have to do a hard shutdown to turn off/restart the PC. I did some research on this file on the Microsoft site but nothing seemed to match what I am looking for. I am in safe mode right now running ClamWin on my flash drive to see if it is a virus.

Anyone know how to fix this issue without reinstalling Windows?
Go to the top of the page
 
+Quote Post
Jimmy89
post Nov 27 2007, 11:50 PM
Post #2


Living at the Datacenter
Group Icon

Group: [HOSTED]
Posts: 696
Joined: 30-June 06
From: Australia
Member No.: 14,219



According to some websites that I found - it looks like you have a virus.

The reason you cannot login at all is because
QUOTE
This is the local security authentication server, and it generates the process responsible for authenticating users for the Winlogon service. This process is performed by using authentication packages such as the default Msgina.dll. If authentication is successful, Lsass generates the user's access token, which is used to launch the initial shell. Other processes that the user initiates inherit this token.
Source: www.microsoft.com

According to Trend Micro
QUOTE
This worm exploits the Windows LSASS vulnerability, which is a buffer overrun that allows remote code execution and enables an attacker to gain full control of the affected system. To propagate, it scans the network for vulnerable systems. When it finds a vulnerable system, this malware sends a specially crafted packet to produce a buffer overflow on LSASS.EXE. This worm can cause LSASS to crash and force Windows to restart.
Source: www.trendmicro.com

Firstly, go to http://www.microsoft.com/technet/security/...n/ms04-011.mspx and download the patch for your system and install it.
Secondly, Scan your computer for any other virus's.

Also, try and not use the Internet, bit hard now that you have posted this - but the virus allows hackers to remotely access your computer while it is connected to the internet. See If this helps. Also, have a look at www.askdavetaylor.com, you should be able to follow those steps to fix your problem also.

Good Luck,
-jimmy

EDIT: ALWAYS keep your Anti-Virus, Firewalls and Anti-Spyware up-to-date!

This post has been edited by Jimmy89: Nov 27 2007, 11:51 PM
Go to the top of the page
 
+Quote Post
xboxrulz
post Nov 28 2007, 02:11 AM
Post #3


Colonel Panic
Group Icon

Group: [MODERATOR]
Posts: 2,734
Joined: 25-March 05
From: Toronto, Ontario, Canada
Member No.: 3,233



Try system reinstall via your disc. It shouldn't kill your files but only your system files. I recommend you to have Knoppix or another Live CD ready to back up before you try my suggestion. Having your lsass.exe is a pain in the neck. Bumped into that problem before because the system went corrupted.

xboxrulz
Go to the top of the page
 
+Quote Post
Sten
post Nov 28 2007, 09:19 AM
Post #4


Oh come on Mrs. B!
Group Icon

Group: Members
Posts: 648
Joined: 6-June 07
From: Tasmania, Australia
Member No.: 22,422



not the worst virus you could ever get, though its pretty bad by the sound of it.

i once got a "spider virus" last year. at least you could get on the computer! i couldnt even load the computer. after the acer screen all i got was a black screen with a smily face. it was a boot sector problem aparantly.

anyway, would a partial reformat get rid of it? or u could just go on a live cd and delete lsass.exe from wherever it is.


Go to the top of the page
 
+Quote Post
Jimmy89
post Nov 28 2007, 10:53 AM
Post #5


Living at the Datacenter
Group Icon

Group: [HOSTED]
Posts: 696
Joined: 30-June 06
From: Australia
Member No.: 14,219



you cannot delete lsass.exe because Windows requires it, along with msgina.dll to allow users to login. Without either of them, you would not be able to login to your computer.
Go to the top of the page
 
+Quote Post
Ronel
post Nov 28 2007, 11:01 AM
Post #6


Member - Active Contributor
Group Icon

Group: Members
Posts: 76
Joined: 6-August 07
From: Philippines
Member No.: 23,872



A got a solution!

If the error appears as:
CONSOLE
System error: Lsass.exe
When trying to update a password the return status indicates that the value provided as the current password is not correct.


Try my 1st tutorial: Registry Configuration Files And The Corruption Problem

Why?
Maybe it is because the SAM or SAM Registry has been corrupted.
Go to the top of the page
 
+Quote Post
FirefoxRocks
post Nov 28 2007, 01:17 PM
Post #7


Super Member
Group Icon

Group: [HOSTED]
Posts: 658
Joined: 12-July 06
From: Ontario, Canada
Member No.: 14,464



I tried extracting a new copy of lsass.exe from the Windows 98 installation disc but the problem persists. I got really scared when I booted into Ubuntu and couldn't boot into safe mode! But now I am in safe mode again, trying to transfer the data as fast as possible.

For some reason, Ubuntu won't mount the NTFS partition, saying that it is "in use". Therefore I can't recover my files, but I hope that files on the shared partition won't be wiped.

Is there any way to reinstall windows without wiping my documents? I don't have enough external devices to backup 16GB of data, and that includes my iPod nano.
Go to the top of the page
 
+Quote Post
Jimmy89
post Nov 29 2007, 02:53 AM
Post #8


Living at the Datacenter
Group Icon

Group: [HOSTED]
Posts: 696
Joined: 30-June 06
From: Australia
Member No.: 14,219



I am assuming you have attempted to 'repair' windows using the Windows XP Install CD? Try this tutorial which tells you how to reinstall windows without loosing your documents at http://pcworld.about.com.

If you need help on how to use the recovery console, have a look at this KB article from MS > http://support.microsoft.com/kb/307654
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Do You Prefer Laptop Or Desktop Computers?(161)
  2. Windows Not Recognizing Ipod(20)
  3. System Sounds Not Working(9)
  4. Sharing Files In Windows Xp Home(15)
  5. Anyone Know Of Any Good Image Editing Software?(23)
  6. A Note To All Illegal Windows Xp Owners(47)
  7. Ncaa Football Bcs System Not Broken!(2)
  8. Www.modthesims2.com - Sims 2 Mods Site(8)
  9. How To Play Mac Games On Windows And Vice-versa(28)
  10. Using Same Serial # On Multiple Copies Of Windows(15)
  11. The Best Version Of Windows(42)
  12. Can You Create A Folder Name "con"(17)
  13. Windows Live Search(14)
  14. Deleting A Corrupt File(25)
  15. Windows Internet Explorer 7 Vs. Mozilla Firefox 2(28)
  1. New Windows Live Messenger 8.5 Beta!(13)
  2. Cracking Wireless Access Point Password?(22)
  3. Windows Live Messenger(11)
  4. Credit System V2.0 Online(17)
  5. Windows Or Mac?(29)
  6. Bid For Power Opengl Error [solved](6)
  7. How To Make A Private Message System.(9)
  8. Strange Error When Trying To Install Fedora Core 9(5)
  9. Image Problems With Windows 2000(8)
  10. Remove Windows Update Uninstall Information(4)
  11. Error Connecting To Domain(2)
  12. Cant Find The Error(2)
  13. Upgrade Windows Service Pack Issues(5)


 



- Lo-Fi Version Time is now: 7th September 2008 - 12:25 AM