Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Shutdown from NT-AUTHORITY\... = virus/attack? |
|---|---|
| Date: | Fri, 3 Sep 2004 07:59:09 -0400 |
-----Original Message----- From: Peter Nabbefeld [mailto:Peter.Nabbefeld@gmx.de] Sent: September 2, 2004 15:24 To: focus-virus@securityfocus.com Subject: Shutdown from NT-AUTHORITY\... = virus/attack? Hello, could anybody here tell me, if a "Shutdown from NT-AUTHORITY\..." (can't remember the full name) is caused by a virus or an attack? How can I stop W2k from shutting down? I've tried to close the shutdown task and to open notebook and fill in some text, but both didn't work. I fear, that some virus might have been installed into my startup files (probably a backdoor).
Could this not be the result of your Event Log settings being configured to "Shut down the computer when the security audit log is full"? I'll bet that this is your culprit, since this practice is highly recommended by many different sources. INFO (beware of line wraps): http://www.windowsnetworking.com/kbase/WindowsTips/WindowsNT/ RegistryTips/Shutdown/CrashOnAuditFail.html http://support.microsoft.com/default.aspx?scid=http://support. microsoft.com:80/support/kb/articles/q232/5/64.asp&NoWebContent=1
I've installed a firewall (maybe outdated) and a virus scanner (last update about one week ago, maybe also some days more), so if it's been caused by a virus, it should be a relatively recent one.
If you're firewall and AV have remained quiet (especially the firewall not asking if app such 'n' such is allowed to listen on port whatever), it is likely that it isn't malware at all. It is probably an Event log setting. One other possibility is that your system is having problems writing to the Event Log (System shutdown because of this is not a default setting though). You didn't mention seeing a blue screen error, so I don't think that this is it... INFO (beware of line wrap): http://support.microsoft.com/default.aspx?scid=http://support. microsoft.com:80/support/kb/articles/q178/2/08.asp&NoWebContent=1 Alex Arndt
| Previous by Date: | RE: Shutdown from NT-AUTHORITY\... = virus/attack?, Benjamin Cerny |
|---|---|
| Next by Date: | RE: Shutdown from NT-AUTHORITY\... = virus/attack?, McDonald, Gray |
| Previous by Thread: | RE: Shutdown from NT-AUTHORITY\... = virus/attack?, Philip Wagenaar |
| Next by Thread: | RE: Shutdown from NT-AUTHORITY\... = virus/attack?, McDonald, Gray |
| Indexes: | [Date] [Thread] [Top] [All Lists] |