RPC shuts down my computer

  • Thread starter Thread starter Kerri
  • Start date Start date
K

Kerri

I just upgraded from win98 to winxp and all went well
until I went on internet. Every time I get on internet,
my computer pops up with box after 20 minutes saying
something about my RPC and it is shutting down my
computer in 30 seconds. It shuts my computer off. What
does this mean and how do I fix it?
 
Kerri said:
I just upgraded from win98 to winxp and all went well
until I went on internet. Every time I get on internet,
my computer pops up with box after 20 minutes saying
something about my RPC and it is shutting down my
computer in 30 seconds. It shuts my computer off. What
does this mean and how do I fix it?

It means you missed the news.
Which is, in itself, frightening.

Congratulations! You have a virus!
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html

There are removal instructions there for both versions
(including tools to help you.)
Know that even if you have the normal updates for Norton, the definitions
for "B" through "D" were added by May 4. You can go to Symantec's site and
get the
manual update if you like.

If it starts to shutdown on you, click Start > Run, and enter "shutdown -a".
(no quotes.) That will stop the shutdown and let you continue fixing.

Note that Microsoft is not sending you patches in emails nor should you EVER
open attachments you did not expect in emails. You simply posted your
un-munged email address to the thousands of newsgroups that this is spread
to around the world and it has been "harvested".


My other suggestions to you include:

Please Notice that if you use AOL, you should at least upgrade to 9.0 or
greater before doing any of the fixes. I know you can get AOL 9.0 at almost
any convenience store, gas station, super market or other retail outlet in
the world, so this should not be a problem.


Turn on that firewall...
http://www.microsoft.com/WindowsXP/home/using/howto/homenet/icf.asp
(It has been reported that it now works with AOL 9.0+)


Make sure you have all the updates (critical) installed from:
http://windowsupdate.microsoft.com/
(Scan for updates, Review and Install)


Get rid of the spy/ad/mal-ware..
(Yes - using MORE than one of these..
I recommend at least the first three. Also..
UPDATE the definitions for them before using.)

Spybot Search and Destroy
http://www.safer-networking.net/

Lavasoft AdAware
http://www.lavasoft.de

CWSShredder
http://www.spywareinfo.com/~merijn/downloads.html

Hijack This!
http://mjc1.com/mirror/hjt/

I also like "The Cleaner" and "SpywareBlaster" and "SpywareGuard".
- http://www.moosoft.com/
- http://www.javacoolsoftware.com/

The first is a PAY product, but useable for 30 days - it has found and
eliminated problems in the past the others did not. The latter two are
prevention mechanisms. SpywareBlaster is a FANTASTIC free product, I
suggest
getting this after you cleanup and keeping it updated as well....

And Assortment of Others:
http://spywareinfo.com/

ALSO - Be sure to IMMUNIZE after you clean up. SpywareBlaster and Spybot
Search and destroy both have these features - use both!


After you cleanup your PC somewhat of spy/ad/mal-ware, verify your antivirus
software is updated and run a full scan of your computer. If you have no
antivirus software - get one NOW! Grisoft AntiVirus:
http://www.grisoft.com/us/us_dwnl_free.php


Empty your Temporary Internet Files and shrink the size it stores to about
80 to 120MB (seems to be an optimal size for the normal user)

- Open ONE copy of Internet Explorer.
- Select TOOLS -> Internet Options.
- Under the General tab in the "Temporary Internet Files" section,
do the following:
- Click on "Delete Cookies" (click OK)
- Click on "Settings" and change the
"Amount of disk space to use:" to something between 80MB
and 120MB. (Betting it is MUCH larger right now.)
- Click OK.
- Click on "Delete Files" and select to
"Delete all offline contents" (the checkbox) and click
OK. (If you had a LOT, this could take 2-10 minutes or
more.)
- Once it is done, click OK, close Internet Explorer
- Re-open Internet Explorer.


Uninstall any software you do not use often/ever. (If you have something
installed but never use it, uninstall it.) If you go through Control
Panel -> Add/Remove Programs and see things you seldom if ever use, it is to
your advantage to remove it.


Also, if you are tired of Web Page Pop-Ups/Unders.. You could try the
Google Toolbar.
http://toolbar.google.com/


Stop loading applications at logon.. run MSCONFIG and look under the startup
tab for things you DON'T want to startup! Search the Internet with Google
to discover what things are safe to remove and what things may even be
malware infecting your computer.


Better control your email and lessen the amount of time you spend dealing
with SPAM:
SpamBayes
http://sourceforge.net/projects/spambayes/
or
Spamihilator.
http://www.spamihilator.com
 
Hi Kerri,

Common issue.

To stop the reboots: Go to Start/Run and type in: services.msc. Scroll down
to Remote Procedure Call (RPC)/Recovery/First Failure/Restart the Service.
Or go to Start/Run/CMD and type in: shutdown -a.

Close Windows Explorer, run the edit on line 257 which includes the prompt
for the patch once your system has been cleaned.

This script removes all variants of the W32.Blaster.Worm (original, B, C, D,
E and F) and will inform you whether or not the patch is already installed.
http://www.kellys-korner-xp.com/xp_tweaks.htm. Direct download:
http://www.kellys-korner-xp.com/regs_edits/msblast.vbs

More information here:
http://www.kellys-korner-xp.com/xp_qr.htm#rpc

MS Blaster Tool: http://tinyurl.com/3h8kw
 
you get the shutdown message...

Go to; Start --> Run
enter; shutdown -a

This will halt the shutdown and give you a chance to Download the McAfee worm removal tool,
Stinger: http://vil.nai.com/vil/stinger/ or the Microsoft Lovsan/Blaster and Nachi/Welchia
Removal Tool
http://www.microsoft.com/downloads/...8B-FE98-493F-AD76-BF673A38B4CF&displaylang=en
and install the following patch for the RPC/RPCSS and DCOM Vulnerabilities that are
addressed by Microsoft Security Bulletin MS04-012 - KB828741
http://support.microsoft.com/default.aspx?scid=kb;en-us;828741 and finally
http://www.microsoft.com/technet/security/bulletin/ms04-012.mspx

Please read: http://www.microsoft.com/security/incident/blast.asp

You also need a FireWall. If you don't patch the PC and not use a FireWall then you will
just be re-infected.

I also suggest the installation of *ALL* MS Critical Updates ASAP.

Dave







| I just upgraded from win98 to winxp and all went well
| until I went on internet. Every time I get on internet,
| my computer pops up with box after 20 minutes saying
| something about my RPC and it is shutting down my
| computer in 30 seconds. It shuts my computer off. What
| does this mean and how do I fix it?
 
Additional info for users...
Stinger fro NAI-McAfee http://vil.nai.com/vil/stinger/ will
detect and remove over 40 of these nasty recent viruses and
worms. It is a free download and will fit on and run from a
floppy or your hard drive.

SpyBot S&D version 1.3.5 is available at www.majorgeeks.com
Look for the spyware tools button on the left side of the
page, then scroll to SpyBot. It will work very well.


--
The people think the Constitution protects their rights;
But government sees it as an obstacle to be overcome.


| Kerri wrote:
| > I just upgraded from win98 to winxp and all went well
| > until I went on internet. Every time I get on internet,
| > my computer pops up with box after 20 minutes saying
| > something about my RPC and it is shutting down my
| > computer in 30 seconds. It shuts my computer off. What
| > does this mean and how do I fix it?
|
| It means you missed the news.
| Which is, in itself, frightening.
|
| Congratulations! You have a virus!
|
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.worm.html
|
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html
|
| There are removal instructions there for both versions
| (including tools to help you.)
| Know that even if you have the normal updates for Norton,
the definitions
| for "B" through "D" were added by May 4. You can go to
Symantec's site and
| get the
| manual update if you like.
|
| If it starts to shutdown on you, click Start > Run, and
enter "shutdown -a".
| (no quotes.) That will stop the shutdown and let you
continue fixing.
|
| Note that Microsoft is not sending you patches in emails
nor should you EVER
| open attachments you did not expect in emails. You simply
posted your
| un-munged email address to the thousands of newsgroups
that this is spread
| to around the world and it has been "harvested".
|
|
| My other suggestions to you include:
|
| Please Notice that if you use AOL, you should at least
upgrade to 9.0 or
| greater before doing any of the fixes. I know you can get
AOL 9.0 at almost
| any convenience store, gas station, super market or other
retail outlet in
| the world, so this should not be a problem.
|
|
| Turn on that firewall...
|
http://www.microsoft.com/WindowsXP/home/using/howto/homenet/icf.asp
| (It has been reported that it now works with AOL 9.0+)
|
|
| Make sure you have all the updates (critical) installed
from:
| http://windowsupdate.microsoft.com/
| (Scan for updates, Review and Install)
|
|
| Get rid of the spy/ad/mal-ware..
| (Yes - using MORE than one of these..
| I recommend at least the first three. Also..
| UPDATE the definitions for them before using.)
|
| Spybot Search and Destroy
| http://www.safer-networking.net/
|
| Lavasoft AdAware
| http://www.lavasoft.de
|
| CWSShredder
| http://www.spywareinfo.com/~merijn/downloads.html
|
| Hijack This!
| http://mjc1.com/mirror/hjt/
|
| I also like "The Cleaner" and "SpywareBlaster" and
"SpywareGuard".
| - http://www.moosoft.com/
| - http://www.javacoolsoftware.com/
|
| The first is a PAY product, but useable for 30 days - it
has found and
| eliminated problems in the past the others did not. The
latter two are
| prevention mechanisms. SpywareBlaster is a FANTASTIC free
product, I
| suggest
| getting this after you cleanup and keeping it updated as
well....
|
| And Assortment of Others:
| http://spywareinfo.com/
|
| ALSO - Be sure to IMMUNIZE after you clean up.
SpywareBlaster and Spybot
| Search and destroy both have these features - use both!
|
|
| After you cleanup your PC somewhat of spy/ad/mal-ware,
verify your antivirus
| software is updated and run a full scan of your computer.
If you have no
| antivirus software - get one NOW! Grisoft AntiVirus:
| http://www.grisoft.com/us/us_dwnl_free.php
|
|
| Empty your Temporary Internet Files and shrink the size it
stores to about
| 80 to 120MB (seems to be an optimal size for the normal
user)
|
| - Open ONE copy of Internet Explorer.
| - Select TOOLS -> Internet Options.
| - Under the General tab in the "Temporary Internet Files"
section,
| do the following:
| - Click on "Delete Cookies" (click OK)
| - Click on "Settings" and change the
| "Amount of disk space to use:" to something between
80MB
| and 120MB. (Betting it is MUCH larger right now.)
| - Click OK.
| - Click on "Delete Files" and select to
| "Delete all offline contents" (the checkbox) and click
| OK. (If you had a LOT, this could take 2-10 minutes or
| more.)
| - Once it is done, click OK, close Internet Explorer
| - Re-open Internet Explorer.
|
|
| Uninstall any software you do not use often/ever. (If you
have something
| installed but never use it, uninstall it.) If you go
through Control
| Panel -> Add/Remove Programs and see things you seldom if
ever use, it is to
| your advantage to remove it.
|
|
| Also, if you are tired of Web Page Pop-Ups/Unders.. You
could try the
| Google Toolbar.
| http://toolbar.google.com/
|
|
| Stop loading applications at logon.. run MSCONFIG and look
under the startup
| tab for things you DON'T want to startup! Search the
Internet with Google
| to discover what things are safe to remove and what things
may even be
| malware infecting your computer.
|
|
| Better control your email and lessen the amount of time
you spend dealing
| with SPAM:
| SpamBayes
| http://sourceforge.net/projects/spambayes/
| or
| Spamihilator.
| http://www.spamihilator.com
|
| --
| <- Shenan ->
| --
|
|
 
I really wish some of you people would get the facts straight. Sasser
does NOT exploit the RPC vulnerability, it exploits the LSASS
vulnerability. RPC is attacked by Blaster and Welchia worms.

Steve
 
Greetings --

If you connected the PC to the Internet without having first
enabled a firewall, without having first installed an antivirus
application with current virus definition files, and before installing
the KB824146 Hotfix, you're very likely to get infected from any of
the thousands of PCs on the Internet that are constantly broadcasting
the Blaster and/or Welchia worms. It only takes a few seconds of
exposure.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next RPC countdown begins. This will abort the shut down. Also, make
sure you've enabled a firewall before starting, to preclude any more
intrusions while getting the updates/patches/tools.

MS04-012 Cumulative Update for Microsoft RPC-DCOM
http://support.microsoft.com/default.aspx?scid=kb;en-us;828741

What You Should Know About the Blaster Worm
http://www.microsoft.com/security/incident/blast.asp

W32.Blaster.Worm a.k.a. W32/Lovesan.Worm
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

W32.Blaster.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

W32.Welchia.Worm a.k.a. W32/Nachi.Worm
http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html

W32.Welchia.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.welchia.worm.removal.tool.html

McAfee AVERT Stinger
http://us.mcafee.com/virusInfo/default.asp?id=stinger


Bruce Chambers

--
Help us help you:




You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
Bruce:

Time to update your info. The vulnerabilities of RPC/RPCSS and DCOM are now addressed by
Microsoft Security Bulletin MS04-012 - KB828741 which supercedes KB824146.

Dave




| Greetings --
|
| If you connected the PC to the Internet without having first
| enabled a firewall, without having first installed an antivirus
| application with current virus definition files, and before installing
| the KB824146 Hotfix, you're very likely to get infected from any of
| the thousands of PCs on the Internet that are constantly broadcasting
| the Blaster and/or Welchia worms. It only takes a few seconds of
| exposure.
|
| To stay on-line long enough to get the necessary updates, patches,
| and removal tools, click Start > Run, and enter "shutdown -a" when the
| next RPC countdown begins. This will abort the shut down. Also, make
| sure you've enabled a firewall before starting, to preclude any more
| intrusions while getting the updates/patches/tools.
|
| MS04-012 Cumulative Update for Microsoft RPC-DCOM
| http://support.microsoft.com/default.aspx?scid=kb;en-us;828741
|
| What You Should Know About the Blaster Worm
| http://www.microsoft.com/security/incident/blast.asp
|
| W32.Blaster.Worm a.k.a. W32/Lovesan.Worm
| http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html
|
| W32.Blaster.Worm Removal Tool
| http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
|
| W32.Welchia.Worm a.k.a. W32/Nachi.Worm
| http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html
|
| W32.Welchia.Worm Removal Tool
| http://www.symantec.com/avcenter/venc/data/w32.welchia.worm.removal.tool.html
|
| McAfee AVERT Stinger
| http://us.mcafee.com/virusInfo/default.asp?id=stinger
|
|
| Bruce Chambers
|
| --
| Help us help you:
|
|
|
|
| You can have peace. Or you can have freedom. Don't ever count on
| having both at once. -- RAH
|
|
| | >I just upgraded from win98 to winxp and all went well
| > until I went on internet. Every time I get on internet,
| > my computer pops up with box after 20 minutes saying
| > something about my RPC and it is shutting down my
| > computer in 30 seconds. It shuts my computer off. What
| > does this mean and how do I fix it?
|
|
 
Greetings --

Yeah, I forget to double-check the text when I fixed the URL.
It's fixed on future posts.

Bruce Chambers

--
Help us help you:




You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
I see that -- You are one of the best responders. :-)

Dave





| Greetings --
|
| Yeah, I forget to double-check the text when I fixed the URL.
| It's fixed on future posts.
|
| Bruce Chambers
|
| --
| Help us help you:
|
|
|
|
| You can have peace. Or you can have freedom. Don't ever count on
| having both at once. -- RAH
|
|
| | > Bruce:
| >
| > Time to update your info. The vulnerabilities of RPC/RPCSS and DCOM
| > are now addressed by
| > Microsoft Security Bulletin MS04-012 - KB828741 which supercedes
| > KB824146.
| >
| > Dave
| >
| >
| >
| >
|
|
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

XP wont shut down 8
RPC shutting down my computer 6
RPC 1
Can't shut computer off 68
What difference between "Shut Down" and "Turn Off"? 8
SFC wont check files rpc server running 4
RPC Shut down 3
RPC 1

Back
Top