|  | 
        
         |  | 
        
         |  Jarworski
             from The Grove (United Kingdom) on 2003-08-11 11:06 [#00817641] Points: 10836 Status: Lurker
 | 
| 
     
 
 | I keep getting a system shutdown error, it's turning my PC off as soon as I get on, it gives me a minute arrghh!!! BRB
 with more info
 
 
 
 | 
        
         |   | 
        
         |  Jarworski
             from The Grove (United Kingdom) on 2003-08-11 11:09 [#00817646] Points: 10836 Status: Lurker | Followup to Jarworski: #00817641
 | 
| 
     
 
 | It says Windows must now restart because the Remote Procedure Call service terminated unexpectedly
 
 This shutdown was initiated by the NT AUTHORITY\SYSTEM
 
 Help!!!!
 
 
 
 | 
        
         |   | 
        
         |  Jarworski
             from The Grove (United Kingdom) on 2003-08-11 11:12 [#00817650] Points: 10836 Status: Lurker
 | 
| 
     
 
 | Godfuckingdammit, it's doing it every time without fail now... I have no idea what's going on... but if anyone does,
 I'll suck your toes for a week if you help me!
 
 *disapears again*
 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-11 11:12 [#00817652] Points: 27325 Status: Lurker
 | 
| 
     
 
 | That sounds alot like it would have been achieved through a trojan horse.
 
 but that would just be speculation on my part.
 
 
 
 | 
        
         |   | 
        
         |  earthleakage
             from tell the world you're winning on 2003-08-11 11:17 [#00817661] Points: 27859 Status: Regular
 | 
| 
     
 
 | my toes you say? well it's a tempting offer, there's no doubt about that but i'm too busy eating and watching tv.
 sorry.
 
 
 
 | 
        
         |   | 
        
         |  pomme de terre
             from obscure body in the SK System on 2003-08-11 11:17 [#00817662] Points: 11943 Status: Moderator | Show recordbag
 | 
| 
     
 
 | temp fix.. 
 in your control panel, go to administrative tools then to
 components services. then under the folder on the left you
 will see something that says Services ( local )
 
 then on the right hand side scroll down to the "remote
 procedure call" highlight it right click and go to
 properties, then you can choose what happens when your rpc
 has a problem. it is automatically set to reboot in 30
 seconds or something, but u can set it to do nothing or to
 run a program or a command line .
 
 are you running any p2p file sharing pgms?
 
 do a virus scan as soon as you are operational..
 
 
 
 | 
        
         |   | 
        
         |  pomme de terre
             from obscure body in the SK System on 2003-08-11 11:22 [#00817670] Points: 11943 Status: Moderator | Show recordbag
 | 
| 
     
 
 | http://securityresponse.symantec.com/avcenter/security/Cont ent/8205.html
 
 hmm..
 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-11 11:33 [#00817692] Points: 27325 Status: Lurker
 | 
| 
     
 
 | *bumps 
 
 
 | 
        
         |   | 
        
         |  afxNUMB
             from So.Flo on 2003-08-11 13:28 [#00817839] Points: 7099 Status: Regular
 | 
| 
     
 
 | same problem? 
 
 
 | 
        
         |   | 
        
         |  Oddioblender
             from Fort Worth, TX (United States) on 2003-08-11 13:32 [#00817849] Points: 9601 Status: Lurker
 | 
| 
     
 
 | you've probably got a trojan worm. the same shit happened to my comp almost a year ago.
 
 get norton anti-virus and clean that shit up.
 Or, look for a file like this:
 "SOFUNNY.EXE" or "msdos34"
 
 actually i'm not completely sure on the msdos one - i know
 it starts with msdos because it's disguised as a system
 file, but it isn't. it definitely ends with a two-digit
 number.
 
 
 
 | 
        
         |   | 
        
         |  Jarworski
             from The Grove (United Kingdom) on 2003-08-11 14:09 [#00817894] Points: 10836 Status: Lurker
 | 
| 
     
 
 | Cheers for responding guys - especially pomme. I managed to keep it on long enough to nuke it with Norton thanks to that
 temp fix. Did it just before the missus tried to format the
 drive, phew!!!
 
 
 
 | 
        
         |   | 
        
         |  Clic
             on 2003-08-11 14:42 [#00817921] Points: 5232 Status: Regular
 | 
| 
     
 
 | Fuck, this is happening to me now. I already scanned it with McAfee, but it said it found nothing...
 
 
 
 | 
        
         |   | 
        
         |  soon
             from the moon and 2002-07-30 12:55 on 2003-08-11 14:42 [#00817922] Points: 227 Status: Regular
 | 
| 
     
 
 | i am so sleepy. please slaughter me. says: omg
 i am so sleepy. please slaughter me. says:
 help kaleb!
 i am so sleepy. please slaughter me. says:
 do you know what this means "generic hot process for win32
 services has encountered a problem and needs to close"
 i am so sleepy. please slaughter me. says:
 and it keeps popping up, then shutting down my comp
 automactically...
 
 
 
 | 
        
         |   | 
        
         |  soon
             from the moon and 2002-07-30 12:55 on 2003-08-11 14:44 [#00817925] Points: 227 Status: Regular | Followup to soon: #00817922
 | 
| 
     
 
 | i went to check an email while my brother was making himself a sandwhich. I saw he had this in his MSN message box and i
 thought i'd post it here. I'll tell him i did and maybe this
 can be fixed?
 
 
 
 | 
        
         |   | 
        
         |  pomme de terre
             from obscure body in the SK System on 2003-08-11 15:11 [#00817942] Points: 11943 Status: Moderator | Followup to Clic: #00817921 | Show recordbag
 | 
| 
     
 
 | http://housecall.trendmicro.com/ 
 go here and get a scan online.. alot of times this thing
 will pick up stuff other pgms miss..
 
 
 
 | 
        
         |   | 
        
         |  Phresch
             from fucking Trondheim (Norway) on 2003-08-11 16:52 [#00817992] Points: 9989 Status: Lurker | Show recordbag
 | 
| 
     
 
 | argh, i get the same thing!!! 10 se xleft shit1 
 
 
 | 
        
         |   | 
        
         |  Jarworski
             from The Grove (United Kingdom) on 2003-08-11 16:55 [#00817997] Points: 10836 Status: Lurker
 | 
| 
     
 
 | Fuck, what is it with this thing? Actually I haven't killed it, it's still going on... I've turned off the reset thing
 but it's still there... I ran the online virus check and it
 turned out clean, but it's there man. If anyone
 figures out how to really fuck this thing up and destroy
 it's testicles, post it puuulease.
 
 
 
 | 
        
         |   | 
        
         |  giginger
             from Milky Beans (United Kingdom) on 2003-08-11 17:05 [#00818003] Points: 26335 Status: Regular | Show recordbag
 | 
| 
     
 
 | Generic Host Process for Win32 Services? What the fuck is that?
 
 szAppName : svchost.exe     szAppVer : 5.1.2600.0
 szModName : unknown
 szModVer : 0.0.0.0     offset : 00000000
 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-11 17:06 [#00818004] Points: 27325 Status: Lurker | Followup to soon: #00817925
 | 
| 
     
 
 | Thanks alex. 
 And thanks pomme. It seemed to work i guess but maybe not
 permenantly according to Jar's last post. Hmmm
 
 When i talk to sylvia later i'll see if things are fixed for
 good. There has to be a solution out there!
 
 
 
 | 
        
         |   | 
        
         |  giginger
             from Milky Beans (United Kingdom) on 2003-08-11 17:11 [#00818005] Points: 26335 Status: Regular | Show recordbag
 | 
| 
     
 
 | For me it all started with tftp.exe trying to connect to the internet. I blocked and all hell broke loose getting hte
 same as Jar. Restarted and allowed it then msblast,exe tried
 to connect. Same problem. I searched for the files and
 msblast.exe was made today.
 
 
 
 | 
        
         |   | 
        
         |  Ophecks
             from Nova Scotia (Canada) on 2003-08-11 17:18 [#00818009] Points: 19190 Status: Moderator | Followup to Jarworski: #00817641 | Show recordbag
 | 
| 
     
 
 | Holy SHIT, I went through the EXACT same thing today, drove me to near tears.
 
 I unchecked ''allow remote help'' and ''automatic updates'',
 and it's fine now.
 
 I can't believe we had the same problem. Cosmic... I thought
 God hated me and me alone.
 
 
 
 | 
        
         |   | 
        
         |  Ophecks
             from Nova Scotia (Canada) on 2003-08-11 17:20 [#00818010] Points: 19190 Status: Moderator | Show recordbag
 | 
| 
     
 
 | I took the LITTLE time I had to burn a CD full of important files incase I was fucked... hehe, tense moments. My burner
 trying to outrun my system crash. Man. Had to wipe sweat
 from my brow.
 
 
 
 | 
        
         |   | 
        
         |  Clic
             on 2003-08-11 17:22 [#00818011] Points: 5232 Status: Regular
 | 
| 
     
 
 | The house call scan turned up something with "worm" in the title, and cleaned it. Everything seems okay right now, but
 we'll see. Either way, thanks, Pomme.
 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-11 17:24 [#00818016] Points: 27325 Status: Lurker
 | 
| 
     
 
 | Discovered on August 11, 2003, Worm/Lovsan.A, attempts to use the RPC Buffer Overrun vulnerability (a security hole)
 within un-patched Microsoft Windows NT, Windows 2000,
 Windows XP and Microsoft Windows server(TM) 2003 operating
 systems. This Internet worm does not afDiscovered on August
 11, 2003, Worm/Lovsan.A, attempts to use the RPC Buffer
 Overrun vulnerability (a security hole) within un-patched
 Microsoft Windows NT, Windows 2000, Windows XP and Microsoft
 Windows server(TM) 2003 operating systems. This Internet
 worm does not affect Linux, Unix and Apple users.fect Linux,
 Unix and Apple users.
 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-11 17:25 [#00818018] Points: 27325 Status: Lurker
 | 
| 
     
 
 | Worm/Lovsan.A will download and run the file msblast.exe using the Trivial File Transfer Protocol (Tftp).
 
 
 
 | 
        
         |   | 
        
         |  Clic
             on 2003-08-11 17:26 [#00818020] Points: 5232 Status: Regular | Followup to virginpusher: #00818018
 | 
| 
     
 
 | That was it, I believe. 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-11 17:31 [#00818024] Points: 27325 Status: Lurker
 | 
| 
     
 
 | Press Release Source: Central Command, Inc. 
 Internet Virus Alert: Central Command Warns Of New RPC
 Computer Worm Named Worm/Lovsan.A
 Monday August 11, 7:00 pm ET
 New Internet worm exploiting the known RPC Buffer Overrun
 vulnerability gains momentum
 
 http://biz.yahoo.com/prnews/030811/nym178_1.html
 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-11 17:41 [#00818030] Points: 27325 Status: Lurker
 | 
| 
     
 
 | [giginger] Just checked my firewall. It's going mental. SVCHOST.EXE	SVCHOST.EXE	modem-2653.bear.dialup.pol.co.uk	11
 [giginger] Allow activity for application 72	Inbound	TCP
 [giginger] That's where it's sending info and receiving it
 from.
 [giginger] Created a new firewall rule to stop anything at
 that address.
 
 let's see if that works
 
 
 
 | 
        
         |   | 
        
         |  xceque
             on 2003-08-11 18:22 [#00818063] Points: 5888 Status: Moderator | Show recordbag
 | 
| 
     
 
 | This appears to be a new security issue for the loveable ol' Microsoft. Get the patch here asap:
 http://microsoft.com/technet/treeview/default.asp?url=/te...
 
 and all will be well.
 
 (Only needed for systems running
 Windows NT 4.0 Server
 Windows NT 4.0 Terminal Server Edition
 Windows 2000
 Windows XP 32 bit Edition
 Windows XP 64 bit Edition
 Windows Server 2003 32 bit Edition
 Windows Server 2003 64 bit Edition)
 
 Who'd have thought that WinME would have a benefit, eh?
 
 
 
 | 
        
         |   | 
        
         |  Duble0Syx
             from Columbus, OH (United States) on 2003-08-11 18:31 [#00818078] Points: 3436 Status: Lurker
 | 
| 
     
 
 | thats the only thing winMe has going for it.  It never seems to have these strange security holes.  Proly because no one
 wants to fuck up computers running winME because they feel
 sorry for people who use it.  that and winME is plenty
 fucked up without any outside help.
 
 
 
 | 
        
         |   | 
        
         |  Oddioblender
             from Fort Worth, TX (United States) on 2003-08-11 18:34 [#00818080] Points: 9601 Status: Lurker | Followup to Duble0Syx: #00818078
 | 
| 
     
 
 | indeed. :( 
 
 
 | 
        
         |   | 
        
         |  Phresch
             from fucking Trondheim (Norway) on 2003-08-11 18:36 [#00818083] Points: 9989 Status: Lurker | Show recordbag
 | 
| 
     
 
 | fuckin hell....here we go again.... 
 
 
 | 
        
         |   | 
        
         |  Duble0Syx
             from Columbus, OH (United States) on 2003-08-11 18:42 [#00818089] Points: 3436 Status: Lurker
 | 
| 
     
 
 | I've never gotten windows' security patches, and my computer has never been killed by any such thing.  And just get
 symantec ghost, do a clean install with all your needed
 programs and then make a ghost image.  Now I just have to
 install one things rather than 5 million things.
 
 
 
 | 
        
         |   | 
        
         |  virginpusher
             from County Clare on 2003-08-12 00:28 [#00818347] Points: 27325 Status: Lurker
 | 
| 
     
 
 | bump 
 
 
 | 
        
         |   | 
        
         |  Junktion
             from Northern Jutland (Denmark) on 2003-08-12 00:31 [#00818351] Points: 9713 Status: Lurker
 | 
| 
     
 
 | again, i would recommend that you download the emergency rescue disks on a remote computer (requres 7 free
 floppys), and boot with it. Don't know if it will fix it,
 but i have seen it deal with worse problems. If it still
 fucks up, try the Windows XP rebiuld-thingy on the Windows
 XP boot cd
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 01:02 [#00818363] Points: 12687 Status: Lurker
 | 
| 
     
 
 | This is on the intranet in work : 
 Hi all,
 
 To assist our customers currently experiencing problems with
 the PC rebooting due to the W32.Blaster.worm, please use the
 following email template to send them information regarding
 the Microsoft patch to resolve the problem.
 
 To send the email carry out the following.
 
 Goto the general email section relevent to your product
 support.
 Click Blank email template.
 Cut and paste the details below into the email and send to
 the customer.
 
 Thanks
 
 John
 
 ...........................................................
 .............................................
 
 Ntl:home customers may currently be experiencing problems
 with their PC arising from a possible Windows vulnerability.
 The virus/worm in question which exploits this vulnerability
 is called W32.Blaster.Worm and it affects the following
 versions of windows:-
 
 Microsoft IIS, Windows 2000, Windows NT, Windows XP.
 
 In order to prevent your machine from repeatedly rebooting
 please visit the following link:-
 
 http://www.microsoft.com/technet/treeview/?url=/technet/sec
 urity/bulletin/MS03-026.asp
 
 Choose the link, which matches your operating system
 (Windows XP users should in most cases select the link
 entitled "Windows XP 32 bit Edition"). On the following page
 Click the "Download" link on the right. A dialogue box will
 appear in which you should select the "Run this program from
 its current location" option, and then click 'OK'.
 
 Follow the instructions clicking 'Next' where appropriate.
 Restart your machine when requested to do so by the patch.
 
 You should now find that your PC and connection are restored
 to a working state.
 
 Prior to downloading this patch, ntl:home advise that you
 ensure your firewall and antivirus software is running at
 all times
 
 If you continue to experience problems of the same nature,
 please call the Technical Support Bureau on your relevant
 support number.
 
 Regards,
 
 ntl: Support Team
 Technical Support Bureau
 
 
 
 
 | 
        
         |   | 
        
         |  mimi
             on 2003-08-12 01:04 [#00818364] Points: 5721 Status: Regular
 | 
| 
     
 
 | i have downloaded AVG and am scanning my other pc as we speak -- still hasn't found anything.
 
 
 
 | 
        
         |   | 
        
         |  mimi
             on 2003-08-12 01:07 [#00818367] Points: 5721 Status: Regular
 | 
| 
     
 
 | thanks everybody for posting the link for the patch!  glad to know i'm not the only one to end up with this horrific
 beast -- atleast this means there's a solution!
 
 
 
 | 
        
         |   | 
        
         |  Duble0Syx
             from Columbus, OH (United States) on 2003-08-12 01:09 [#00818370] Points: 3436 Status: Lurker
 | 
| 
     
 
 | There is always a solution, though it sometimes = reinstalling.  Hope it works out.
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 01:18 [#00818374] Points: 12687 Status: Lurker
 | 
| 
     
 
 | every call I've had today has been about this. I've been here 20 mins and that's all that I've heard
 
 "my pc keeps restarting !!!"
 
 It's gonna be a hell of a day =o\
 
 
 
 | 
        
         |   | 
        
         |  giginger
             from Milky Beans (United Kingdom) on 2003-08-12 01:43 [#00818377] Points: 26335 Status: Regular | Show recordbag
 | 
| 
     
 
 | Thanks people. Hopefully I'll be getting this sorted. You should link them to this board pOgO :D
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 01:51 [#00818380] Points: 12687 Status: Lurker
 | 
| 
     
 
 | another thing to to do is to disconnect from the internet, enable a firewall then reconnect. This should resolve it
 enough for you to download the patch as it seems to be going
 for open ports
 
 
 
 | 
        
         |   | 
        
         |  Jarworski
             from The Grove (United Kingdom) on 2003-08-12 02:28 [#00818401] Points: 10836 Status: Lurker | Followup to pOgO: #00818380
 | 
| 
     
 
 | I d/led the patch this morning - did I do the right thing? :/
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 02:31 [#00818402] Points: 12687 Status: Lurker | Followup to Jarworski: #00818401
 | 
| 
     
 
 | eep 
 dunno
 
 we'll see when we get home, we can always download it again
 
 There's 100 call queueing atm and they're ALL about this
 stupid fugging thing
 
 bet it's on the news tonight
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 02:36 [#00818407] Points: 12687 Status: Lurker
 | 
| 
     
 
 | Actually, it should be fine as long as we keep the firewall running
 
 sygate's doing my head in a bit, but I know xp's own is
 blocking the w32 so I may give that a go
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 03:28 [#00818432] Points: 12687 Status: Lurker
 | 
| 
     
 
 | getting some info in form microsoft in a sec (hopefully =os)
 
 will keep you updated
 
 try pressing F10 if your still getting the restart error, it
 may cancle the restart
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 04:01 [#00818450] Points: 12687 Status: Lurker
 | 
| 
     
 
 | uuummm.... okay 
 it looks like the virus is changing cause the calls that
 seem to be coming in now are having errors when trying to
 enable XP's firewall
 
 Yavo : what time are you finishing? I'm finishing @ 4, if
 you get home before me, don't do anything till I get there
 
 
 
 | 
        
         |   | 
        
         |  Jarworski
             from The Grove (United Kingdom) on 2003-08-12 04:02 [#00818452] Points: 10836 Status: Lurker | Followup to pOgO: #00818450
 | 
| 
     
 
 | Later than 4, more like 6 
 I think deleting the msblast.exe is a good idea for a start
 
 
 
 | 
        
         |   | 
        
         |  pOgO
             from behind your belly button fluff on 2003-08-12 04:09 [#00818454] Points: 12687 Status: Lurker | Followup to Jarworski: #00818452
 | 
| 
     
 
 | I don;t think it actulayy stays on the pc, it's more like a DOS attack that just goes for open ports
 
 
 
 | 
        
         |   | 
        
         |  Phobiazero
             from the next Xltronic (Sweden) on 2003-08-12 04:10 [#00818455] Points: 10507 Status: Webmaster | Show recordbag
 | 
| 
     
 
 | my ISP got the virus yesterday evening and because of that i had no internet access until 9am this morning.
 
 update your scan engines, folks!
 
 blah! w32/blaster
 
 
 
 | 
        
         |   | 
        
         | Messageboard index
 
 
        
 |