NT AUTHORITY\SYSTEM Remote Procedure Call

  • Thread starter Thread starter Agent Orange
  • Start date Start date
A

Agent Orange

I have Windows XP Home Edition Upgrade. I upgrade from
Windows ME. I've had no problems for over a year.

I formatted my hard drive a couple of days ago. After
installing Win Me, and then the Win XP upgrade, all was
fine for about a half hour. Then I get a pop-up window
that says "NT AUTHORITY\SYSTEM". It goes on to say that I
have 60 seconds untill it re-boots my computer. Now that's
all it does...Can anybody help me?
Thanks in advance.
 
Hi

Your system has been infected by the Blaster Worm. Have a look at the
following links:

www.kellys-korner-xp.com/xp_qr.htm#rpc

Courtesy of MVP Kelly Theriot.

"Virus Alert About the Blaster Worm and Its Variants"
http://support.microsoft.com/?id=826955

"What You Should Know About the Blaster Worm and Its Variants"
http://www.microsoft.com/security/incident/blast.asp

--

Will Denny
MS-MVP Windows - Shell/User


| I have Windows XP Home Edition Upgrade. I upgrade from
| Windows ME. I've had no problems for over a year.
|
| I formatted my hard drive a couple of days ago. After
| installing Win Me, and then the Win XP upgrade, all was
| fine for about a half hour. Then I get a pop-up window
| that says "NT AUTHORITY\SYSTEM". It goes on to say that I
| have 60 seconds untill it re-boots my computer. Now that's
| all it does...Can anybody help me?
| Thanks in advance.
 
Im having this problem aswell. I restored windows XP but
now i get these shutdown messages exactly like yours.

please someone reply
 
Chris said:
Im having this problem aswell. I restored windows XP but
now i get these shutdown messages exactly like yours.

please someone reply


(Courtesy of Ken Blake - Microsoft MVP Windows: Shell/User)

You have the MSBlaster worm. To remove it, do the following:

The following instructions are in three parts

1. Stop it from running

2. Remove it from your system

3. Make sure it doesn't come back



Before beginning, if you have an always-on internet connection,
it's a good idea to disconnect it.



1. Stop it from running

Press Ctrl-Alt-Delete to bring up the Task Manager, then on the
Processes tab, click msblast.exe and then "End process." Reply
"Yes" to the warning message that comes up.

This stops the worm from running, so your system will not shut
down. However, it doesn't remove it, and if that's all you do, it
will start up again the next time you boot.


***

2. Remove it from your system

a. Start the registry editor program, regedit, by going to Start
| Run, and typing REGEDIT
Navigate to HKEY_Local_Machine\Software\Microsoft\Windows\Current
Version\Run by clicking the plus signs next to each of the
folders in the left hand pane. When you get to the last of them,
Run, click the word Run itself.

Find an entry called "Windows Auto Update" on the right side.
Right-click it and delete it.

b. Do a Windows search for msblast, and delete all files found.

The worm is now gone, and won't start again the next time you
boot. But if that's all you do, you can get reinfected just as
you did the first time.

***


3. Make sure it doesn't come back

a. Make sure you're running a firewall that prevents worms like
this from getting in. You can enable the built-in Windows XP
firewall, or download and install another one such as the free
version of ZoneAlarm. To enable the built-in firewall, go to
Control Panel, double-click Networking and Internet Connections,
then click Network Connections. Right-click your connection, then
click Properties, and on the Advanced tab, click the option
"Protect my computer and network..."


b. If you've disconnected your internet connection, reconnect it.
Download and install the Microsoft patch at
http://download.microsoft.com/download/9/8/b/98bcfad8-afbc-458f-aaee-b7a52a9
83f01/WindowsXP-KB823980-x86-ENU.exe

That will remove the vulnerability that the worm exploits.


c. Be sure you are running an anti-virus program, and that you
regularly download the latest updated virus definitions.
 
You can get this error due to virus named blaster or it may possible that rpc service has gone bad
To rectify this problem use the following steps to prevent the forced shut down

From the Start menu, click Run.

In the Run dialog box, type: shutdown -a. Click OK.

Download the FixBlast.exe file from the Symantec Web site and run on the computer

Note:Disable the system restore and if computer is connected to cable modem or dsl disconnect it from the computer

End task on msblast.exe.

On your keyboard, press the CTRL+ALT+DELETE keys.
In the Windows Security window, click Task Manager.
In the Windows Task Manager window, click the Processes tab.
On the Processes tab, click msblast.exe, and then click End Proces

After accomplishing above steps run FixBlast.exe in safe mode

After running the fixblast.exe download and install the "Blaster Worm: Critical Security Patch for Windows XP" patch from the Microsoft Web site to prevent this type of attack.

Enable the system restore

If problem presist it may possible service has gone bad
 
Greetings --

If you connected the PC to the Internet without having first
installed the KB824146 Hotfix, without having first installed an
antivirus application with current virus definition files, and before
enabling a firewall, you're very likely to get infected from any of
the thousands of PCs on the Internet that are constantly broadcasting
the Blaster and/or Welchia worms. It only takes a few seconds of
exposure.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next RPC countdown begins. This will abort the shut down. Also, make
sure you've enabled a firewall before starting, to preclude any more
intrusions while getting the updates/patches/tools.

Microsoft Security Bulletin MS03-39
http://support.microsoft.com/?kbid=824146

What You Should Know About the Blaster Worm
http://www.microsoft.com/security/incident/blast.asp

W32.Blaster.Worm a.k.a. W32/Lovesan.Worm
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

W32.Blaster.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

W32.Welchia.Worm a.k.a. W32/Nachi.Worm
http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html

W32.Welchia.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.welchia.worm.removal.tool.html

McAfee AVERT Stinger
http://us.mcafee.com/virusInfo/default.asp?id=stinger


Bruce Chambers
--
Help us help you:



You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
Back
Top