M
Matt
I have had RPC (Remote Procedure Call) Errors from the RPC
Service on port 135 on our computer since yesterday. I
narrowed it down to this command line "C:\WINDOWS\system32
\svchost -k rpcss". I was able to duplicate this error by
killing this process manually. I found msblaster.exe
running in the processes list and researched it, but to no
avail. I disassembled the file and am currently looking
for any suspicious code. I have found fragments of
strings such as "bill gates you made this possible" and "I
just...want you to know...love sam. I placed this file in
the recycle bin, but upon subsequent reboots and dialups,
it seems to return to the processes list. I have deleted
it four different times. I am only in 10th grade and am
teaching myself microsoft programming and networking,
unfortunately, I haven't learned a lot about this area yet
and am unable to repair this. I have added the error
information from the system event log for your use. I have
also seen remote guest logins from other unfamiliar
workstations in the security audits. There has also been
a serious error resulting in a blue screen and memory
dump, though, this seems to have resulted from a fault in
the nv4.dll "NVidia" driver and not msblaster.exe.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 8/12/2003
Time: 7:40:14 PM
User: N/A
Computer: *****
Description:
The Remote Procedure Call (RPC) service terminated
unexpectedly. It has done this 1 time(s). The following
corrective action will be taken in 60000 milliseconds:
Reboot the machine.
Thanks for any assistance,
Matt
Service on port 135 on our computer since yesterday. I
narrowed it down to this command line "C:\WINDOWS\system32
\svchost -k rpcss". I was able to duplicate this error by
killing this process manually. I found msblaster.exe
running in the processes list and researched it, but to no
avail. I disassembled the file and am currently looking
for any suspicious code. I have found fragments of
strings such as "bill gates you made this possible" and "I
just...want you to know...love sam. I placed this file in
the recycle bin, but upon subsequent reboots and dialups,
it seems to return to the processes list. I have deleted
it four different times. I am only in 10th grade and am
teaching myself microsoft programming and networking,
unfortunately, I haven't learned a lot about this area yet
and am unable to repair this. I have added the error
information from the system event log for your use. I have
also seen remote guest logins from other unfamiliar
workstations in the security audits. There has also been
a serious error resulting in a blue screen and memory
dump, though, this seems to have resulted from a fault in
the nv4.dll "NVidia" driver and not msblaster.exe.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 8/12/2003
Time: 7:40:14 PM
User: N/A
Computer: *****
Description:
The Remote Procedure Call (RPC) service terminated
unexpectedly. It has done this 1 time(s). The following
corrective action will be taken in 60000 milliseconds:
Reboot the machine.
Thanks for any assistance,
Matt