you are again here pete :):):)
Main Topics
Browse All TopicsHi guys! this is a very urgent problem that needs to be solved.... i have 5 XP machines all networked, 1 NT Server (we connect to this server through mapping).... and today... my system keeps on shutting down. The error is:
This system has to shut down NT Authority\System. The Windows has to restart because RPC (Remote Access service has terminated expectedly).
I use remote desktop to access my other system from the other office... PLEASE HELP ME!
Thank you....
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
More URLs:
http://www.bigblackglasses
http://www.microsoft.com/s
Worm Removal:
************
From Symantec: W32.Baster.Worm is exploiting the vulnerabilities of the RPC interface.
http://securityresponse.sy
From McAfee:
http://vil.nai.com/vil/con
http://vil.nai.com/vil/con
Sophos:
http://www.sophos.com/viru
======More Reading======
August 1st Week onwards:
~~~~~~~~~~~~~~~~~
This is caused by a worm someone unleashed on the internet. The short of it is that you should immediately disconnect from the internet so you don't get infected if you aren't already, enable a firewall, run a virus scan, and then go to http://windowsupdate.micro
To enable the built-in firewall, open the Network Connections control panel. Then right click on your internet connection, or the network card you use to connect to broadband and select properties. Go to the Advanced tab and check the checkbox labeled "Protect my computer and network by limiting or preventing access to this computer from the Internet."
There are online virus scanners out there. If you have a virus scanner on your computer, make sure you download the latest virus definitions for it.
===
Around the Internet, system administrators report strange "rebooting" of their Windows systems as they are being taken over remotely, and many firewall watchers report a jump in scans for port 135. This problem is especially explosive because an attacker can run a rogue program by merely sending packets to a remote machine using any one of various ports. One of these, port 135, is commonly used to send pop-up messages across a network.
===
If you don't have enough time download and apply the patch before the PC reboots,
Go to start > run > Services.msc.
Right click Remote Procedure Call.
Select Properties > Recovery.
On all three drop-down boxes in this window, select "Take no action."
This temp fix will give you the time to update. After the update, reverse the procedure to get RPC back.
===
Said here:
http://www.experts-exchang
It was said first by Pete, The above is only added info.
It is a new virus.
I had to remove this virus this morning at a client's.
Here was the procedure. It is not exactly as pointed out in prior posts, because of the ORDER of the actions and some details.
1. Disconnect the computer from the internet and from other computers.
2. Reboot.
3. Disable System Restore:
- Right click on My Computer
- System Restore
- Check the check box
- OK
4. Prevent the computer from rebooting because of a RPC problem:
- Start
- Run
- Write "services.msc" in the edit box
- OK
- Double-click on "Remote Procedure Call (RPC)"
- Click on Recovery
- Choose "Take no action" from all the combo boxes
- OK
- Close the window
5. Close the door for new instances of this virus (and others)
- Connect to the internet
- Download and install:
http://download.microsoft.
- Reboot
6. Remove the virus:
- Connect to the internet
- Download and run:
http://securityresponse.sy
7. Update your antivirus software.
8. Reboot
9. Just to be sure, run again the fixblast tool.
NOTE 1: Do not use Windows Update prior to removing the virus. If you do, it is likely that many MB of information need to be downloaded for a full update, and the virus will be nagging you meanwhile and rendering the computer unusable.
NOTE 2: If you happen not to be able to copy or execute a file, it is the virus' fault. Reboot and retry.
NOTE 3: If you update the antivirus software before removing the virus, it will detect the virus, nagging you even more, and not being able to remove the virus at all.
NOTE 4: After everything is OK, do run Windows Update and install all the critical updates. It's because you did not do this, in the first place that the virus got in.
Good luck
ptero
Business Accounts
Answer for Membership
by: PeteLongPosted on 2003-08-12 at 06:53:41ID: 9130037
Hello There
mantec.com /avcenter/ venc/data/ w32.blaste r.worm.htm l
ecurity/se curity_bul letins/ms0 3- 026.asp
ndows\Curr entVersion \Run\windo ws auto update
echnet/sec urity/bull etin/MS03- 026.asp.
ort/news/# blaster
om/?kbid=8 23980 fo/virus.a spx?ID=362 65
ries/CA-20 03-19.html
"svchost.exe" errors with RPC messeges and reboots
OR
"NT Authority...shut down in 1 min"
Soundslike youve got the "Blaster Worm"
http://securityresponse.sy
This is the hole it exploits
Your computer is being accessed. Download the MS03-026 patch from Microsoft.
http://www.microsoft.com/s
W32/Blaster-A is a worm that scans networks looking for computers vulnerable to Microsoft's DCOM RPC security exploit.
On finding a suitable victim the worm causes the remote machine to acquire a copy of the worm using TFTP, which is saved as msblast.exe in the Windows system folder.
Additionally the worm creates the following registry entry so as to run on system start:
HKLM\Software\Microsoft\Wi
After August 15 the worm will launch a distributed denial-of-service attack on windowsupdate.com
Microsoft has issued a patch for the vulnerability exploited by this worm. The patch is available from http://www.microsoft.com/t
The worm contains the following text, which does not get displayed:
I just want to say LOVE YOU SAN!! billy gates why do you make this possible ? Stop making money and fix your software!!
FROM www.sophos.com
Special removal istructions http://www.sophos.com/supp
Fixes Available here
http://support.microsoft.c
http://www3.ca.com/virusin
More Links
http://www.cert.org/adviso
PeteL