RPC message

  • Thread starter Thread starter R.Harris
  • Start date Start date
R

R.Harris

I have just signed up for Broadband -during the first
minute the RPC error message came up and now comes up
every time I try to start -I have been told I probably
have contracted a blaster worm virus-but I am not able to
counter it because I cannot get past this RPC message.
What can I do?
Thanks
Ray Harris
 
Hi, You have Blaster/Nachi worm.

To stop your PC from shutting down Goto Start>>Run>>Type "shutdown -a" (Hit
Enter) Then see the following sites to help you remove and patch your
system so it doesn't happen again.

A tool is available to remove Blaster worm and Nachi worm infections from
computers that are running Windows 2000 or Windows XP
http://support.microsoft.com/?kbid=833330

What You Should Know About the Blaster Worm and Its Variants
http://www.microsoft.com/security/incident/blast.asp
 
R.Harris said:
I have just signed up for Broadband -during the first
minute the RPC error message came up and now comes up
every time I try to start -I have been told I probably
have contracted a blaster worm virus-but I am not able to
counter it because I cannot get past this RPC message.
What can I do?
Thanks
Ray Harris

(Courtesy of Ken Blake - Microsoft MVP Windows: Shell/User)

You have the MSBlaster worm. To remove it, do the following:

The following instructions are in three parts

1. Stop it from running

2. Remove it from your system

3. Make sure it doesn't come back



Before beginning, if you have an always-on internet connection,
it's a good idea to disconnect it.



1. Stop it from running

Press Ctrl-Alt-Delete to bring up the Task Manager, then on the
Processes tab, click msblast.exe and then "End process." Reply
"Yes" to the warning message that comes up.

This stops the worm from running, so your system will not shut
down. However, it doesn't remove it, and if that's all you do, it
will start up again the next time you boot.


***

2. Remove it from your system

a. Start the registry editor program, regedit, by going to Start
| Run, and typing REGEDIT
Navigate to HKEY_Local_Machine\Software\Microsoft\Windows\Current
Version\Run by clicking the plus signs next to each of the
folders in the left hand pane. When you get to the last of them,
Run, click the word Run itself.

Find an entry called "Windows Auto Update" on the right side.
Right-click it and delete it.

b. Do a Windows search for msblast, and delete all files found.

The worm is now gone, and won't start again the next time you
boot. But if that's all you do, you can get reinfected just as
you did the first time.

***


3. Make sure it doesn't come back

a. Make sure you're running a firewall that prevents worms like
this from getting in. You can enable the built-in Windows XP
firewall, or download and install another one such as the free
version of ZoneAlarm. To enable the built-in firewall, go to
Control Panel, double-click Networking and Internet Connections,
then click Network Connections. Right-click your connection, then
click Properties, and on the Advanced tab, click the option
"Protect my computer and network..."


b. If you've disconnected your internet connection, reconnect it.
Download and install the Microsoft patch at
http://download.microsoft.com/downl...e-b7a52a983f01/WindowsXP-KB823980-x86-ENU.exe

That will remove the vulnerability that the worm exploits.


c. Be sure you are running an anti-virus program, and that you
regularly download the latest updated virus definitions.
 
Use CTRL-ALT-DELETE to bring up the Task Manager. Look for msblast.exe and
select
it and End Process. This will stop the computer from shutting down.

For more information and how to fix this please see these links:

http://www.microsoft.com/downloads/...8b-fe98-493f-ad76-bf673a38b4cf&displaylang=en

http://support.microsoft.com/?kbid=826955

http://www.microsoft.com/security/incident/blast.asp

http://www.microsoft.com/security/protect/main.asp



--

Thanks,
Marc Reynolds
Microsoft Technical Support

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Back
Top