Unexpected Shutdown

R

revaaronmatt

On my parent's computer they are getting an NT Authority
System error that says "remote procedure call has
terminated unexpectantly" and then gives them 1 minute to
save everything and then it shuts down and restarts
automatically....

Any ideas for a fix?
 
R

Rod Potter

You are infected with Blaster.
Go to http://www.kellys-korner-xp.com/xp_qr.htm#rpc and download the removal
tool.
Run the tool to remove the worm,then follow the onscreen prompts to download
the patch.
Make sure you download the 32bit patch if you are running XP.

There are more variants out now.
The exes for 2 of the variants are teekids.exe and penis32.exe
Kelly's script kills all known variants.
As more variants are found Kelly and Doug are adding removal instructions to
the script to kill them as well.

If you are having trouble staying up to get the patch and removal tool:
When the shutdown prompt appears,go to start/run and type
shutdown -a to abort the shutdown process to allow you to stay up and
online.
 
D

Denis Wong

It's the Blaster worm, I guess? Install a firewall (or turn on XP's
firewall) and then go to Windows Update for the patch that fixes this
vulnerbility.
 
G

Guest

You have the MSBlaster worm. To remove it, do the
following:

The following instructions are in three parts
1. Stop it from running
2. Remove it from your system
3. Make sure it doesn't come back

Before beginning, if you have an always-on internet
connection,
it's a good idea to disconnect it.

1. Stop it from running
Press Ctrl-Alt-Delete to bring up the Task Manager, then
on the
Processes tab, click msblast.exe and then "End process."
Reply
"Yes" to the warning message that comes up.

This stops the worm from running, so your system will not
shut
down. However, it doesn't remove it, and if that's all you
do, it
will start up again the next time you boot.
***
2. Remove it from your system

a. Start the registry editor program, regedit, by going to
Start
| Run, and typing REGEDIT
Navigate to
HKEY_Local_Machine\Software\Microsoft\Windows\Current
Version\Run by clicking the plus signs next to each of the
folders in the left hand pane. When you get to the last of
them,
Run, click the word Run itself.
Find an entry called "Windows Auto Update" on the right
side.
Right-click it and delete it.

b. Do a Windows search for msblast, and delete all files
found.
The worm is now gone, and won't start again the next time
you
boot. But if that's all you do, you can get reinfected
just as
you did the first time.
***
3. Make sure it doesn't come back

a. Make sure you're running a firewall that prevents worms
like
this from getting in. You can enable the built-in Windows
XP
firewall, or download and install another one such as the
free
version of ZoneAlarm. To enable the built-in firewall, go
to
Control Panel, double-click Networking and Internet
Connections,
then click Network Connections. Right-click your
connection, then
click Properties, and on the Advanced tab, click the option
"Protect my computer and network...". Note: the built in
firewall only monitors incoming traffic not outgoing(ie
spyware, trojans, etc.. you may have on your system).

b. If you've disconnected your internet connection,
reconnect it.
Download and install the Microsoft patch at
http://download.microsoft.com/download/9/8/b/98bcfad8-afbc-
458f-aaee-b7a52a983f01/WindowsXP-KB823980-x86-ENU.exe
That will remove the vulnerability that the worm exploits.

c. Be sure you are running an anti-virus program, and that
you
regularly download the latest updated virus definitions.

-----------------------------------------------------------
-----------------------------------------------------------
------------------------
If you connected the PC to the Internet without
having first
installed the KB824146 Hotfix, without having first
installed an
antivirus application with current virus definition
files, and before
enabling a firewall, you're very likely to get infected
from any of
the thousands of PCs on the Internet that are constantly
broadcasting
the Blaster and/or Welchia worms. It only takes a few
seconds of
exposure.

To stay on-line long enough to get the necessary
updates, patches,
and removal tools, click Start > Run, and enter "shutdown -
a" when the
next RPC countdown begins. This will abort the shut
down. Also, make
sure you've enabled a firewall before starting, to
preclude any more
intrusions while getting the updates/patches/tools.

Microsoft Security Bulletin MS03-39
http://support.microsoft.com/?kbid=824146

What You Should Know About the Blaster Worm
http://www.microsoft.com/security/incident/blast.asp

Protect Your PC
http://www.microsoft.com/security/protect/default.asp

W32.Blaster.Worm a.k.a. W32/Lovesan.Worm
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm
..html

W32.Blaster.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm
..removal.tool.html

W32.Welchia.Worm a.k.a. W32/Nachi.Worm
http://securityresponse.symantec.com/avcenter/venc/data/w32
..welchia.worm.html

W32.Welchia.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.welchia.worm
..removal.tool.html
 
K

Ken Blake

In (e-mail address removed)
You have the MSBlaster worm. To remove it, do the
following:

The following instructions are in three parts
1. Stop it from running
2. Remove it from your system
3. Make sure it doesn't come back


If you're going to quote my words, at least have the decency to
credit me.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

Remote Procedure Call 4
RPC Terminates 3
Remote Procedure Call 2
Getting System Shutdown 5
unexpectant reboot 4
system shutdown 4
Remote Procedure Call (RPC) terminated unexpectantly. 2
Shutdown 1

Top