Wim XP shuts down unexpectedly

  • Thread starter Thread starter Jim
  • Start date Start date
J

Jim

A friend of mine has a Win XP Pro PC. The machine can shut
down unexpectedly, giving this message: "Remote Procedure
Call. Servive terminated unexpectedly" We are then given 1
minute to log out, before the PC reboots.

Has anyone any ideas what the problem might be. This is a
brand new build on the PC.

Regards

Jim
 
Hi Jim,

It's a virus called blaster or lovesan. Information:

http://www.kellys-korner-xp.com/xp_qr.htm#rpc
http://vil.nai.com/vil/content/v_100499.htm
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html
http://www.bigblackglasses.com/Article.aspx?Article=342

You need the patch described here to protect against it:

MS03-026: Buffer Overrun in RPC Interface May Allow Code Execution
http://support.microsoft.com/?kbid=823980

Problem is, you needed to install the patch BEFORE you got infected to avoid
it.

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Win9x
Windows isn't rocket science! That's my other hobby!

Associate Expert - WinXP - Expert Zone
 
Hello Jim,

Your friends machine is infected with the Blaster virus or a variant
thereof.

To temporarily keep us from shutting down, do the following:

1) Got to Start and choose Run and type in "Services.msc" (without the
quotation marks)
2) Scroll down until your see "Remote Procedure Call (RPC)". It will be
Started and set to Automatic.
3) Double-click on "Remote Procedure Call (RPC)" and then choose the
Recovery tab.
4) Change the failure actions from "Restart the Computer" to "Take No
Action".

Next turn on the Internet Connection Firewall.

To turn on ICF, follow these steps:

a. Click "Start", and then click "Control Panel".
b. In Control Panel, double-click "Networking and
Internet Connections", and then click "Network Connections".
c. Right-click the connection where you want to turn on Internet Connection
Firewall, and then click "Properties".
d. Click the "Advanced" tab, and then
click to select the "Protect my computer or network by limiting or
preventing access to this computer from the Internet" check box.

If we have anti virus installed, we need to scan the system with the latest
virus definitions.
You will also want to go to your ant virus company's web site and look for a
removal tool for the virus.

Install the following patch to prevent re-infection:

http://www.microsoft.com/downloads/...AE-A1BA-4D4A-B424-95D32CFC8CBA&displaylang=en

Then go to Windows Update and install all necessary updates.

Hope this helps!

Regards,

Mike Lieser, MCSA, MCSE, CNA
Microsoft SBS Product Support

Get Secure! - www.microsoft.com/security

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Greetings --

If you connected the PC to the Internet without having first
enabling a firewall, without having first installed an antivirus
application with current virus definition files, and/or before
installing the KB824146 Hotfix, you're very likely to get infected
from any of the thousands of PCs on the Internet that are constantly
broadcasting the Blaster and/or Welchia worms. It only takes a few
seconds of exposure.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next RPC countdown begins. This will abort the shut down. Also, make
sure you've enabled a firewall before starting, to preclude any more
intrusions while getting the updates/patches/tools.

Microsoft Security Bulletin MS03-39
http://support.microsoft.com/?kbid=824146

What You Should Know About the Blaster Worm
http://www.microsoft.com/security/incident/blast.asp

W32.Blaster.Worm a.k.a. W32/Lovesan.Worm
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

W32.Blaster.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

W32.Welchia.Worm a.k.a. W32/Nachi.Worm
http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html

W32.Welchia.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.welchia.worm.removal.tool.html

McAfee AVERT Stinger
http://us.mcafee.com/virusInfo/default.asp?id=stinger


Bruce Chambers

--
Help us help you:



You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
Back
Top