Nov 8, 2009
Pages: 1, 2

Rpc In Windows Xp - System shutdown in XP

free web hosting
Open Discussion > MODERATED AREA > Computers > Computer Security Issues & Exploits

Rpc In Windows Xp - System shutdown in XP

alan
Dear Friends, I use Windows XP Pro SP1. When I connect to the Internet, a Notification box comes with countdown of 60 Seconds saying that "This System is shutting down. Please save the work and log off. Any unsaved changes will be lost. This shutdown is initiated by NT/Authority System (Remote procedure call has shutdown unexpectedly)". And after the countdown, the system Restarts. This occurs very often. First of all what is NT/Authority system?. Is this is a hacking or a virus or OS Problem?. I have norton antivirus 2004 and it is up to date. Is there any solution to get rid from this Problem??? sad.gif sad.gif sad.gif

Comment/Reply (w/o sign-up)

dexter
I just did a quick google and it came up with this as an answer...

NT Authority\System RPC Exploit Worm

Here's the text:

QUOTE
By: Borrow -A- Geek @ ozzu.com
this is an important notice. as some of you may know iwork tech support for a cable internet provider. today was a living hell here at work, because litterally 10's of thousands of people flooded the call center with this worm that has unleashed its fury on ALL versions of windows, mostly windows XP and window 2000.

i was hit by this thing and it was a *BLEEP* to remove. (i didnt remove it my girlfriend actually did while i was stuck at work,(yup she is a guru like me, lol)) but it got taken care of. look for a post below real soon for the removal instructions.

Symptoms:

you get a windows message that says

System Shutdown:
This System is Shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by the NT AUTHORITY\SYSTEM

TIME BEFORE SHUTDOWN 00:00:60

Message:
Windows must now be restarted because the Remote Procedure Call (RPC) service. terminated unexpectedly

Technical Details
The Remote Procedure Call (RPC) protocol on the Windows operating systems provides a mechanism for a program running on one machine to execute code on another machine. Windows uses the Distributed Component Object Model (DCOM) to help manage communications of Windows components over a network, typically (but not always) the TCP/IP networks used in most environments. The DCOM interface to RPC accepts network connections on TCP port 135, and fails to validate message inputs during the instantiation of DCOM objects. By sending an appropriately malformed RPC message, an attacker can cause a vulnerable machine to execute arbitrary code within the security context of the RPC service, typically the SYSTEM context [1,2].

The researchers who discovered the vulnerability were able to create proof of concept exploits for Windows 2000/XP (running SP4 and SP1 respectively). They were also able to bypass the buffer overflow protections included as part of Windows 2003, and gain SYSTEM privileges there as well.

The vulnerable components of the Windows operating system are installed by default on all versions of Windows, and cannot be disabled without crippling a number of core Windows components.


references:

http://www.microsoft.com/technet/security/...in/MS03-026.asp

http://lsd-pl.net/special.html

http://www.cnn.com/2003/TECH/internet/08/1...k.ap/index.html


finding and identifying the problem:

Go and get the patch from here, choose the right version for your system. If
you don't know whether your system is "32 bit" or "64 bit" then its 32 bit.
http://support.microsoft.com/?kbid=823980

Next check your system for unusual processes that may be running. In
particular watch out for:
(NOTE, THIS LIST IS NOT EXCLUSIVE, KEEP AN EYE OUT FOR ANY UNUSUAL ACTIVITY)
MSBlast.exe
rpc.exe
rpctest.exe
dcomx.exe
lolx.exe
worm.exe

Scan with an up-to-date virus scanner to help with removal of nasties that
might be left on your system.
Next, visit http://windowsupdate.microsoft.com and grab hold of all
critical updates. Yes, all of them. Try to make a habit of doing this on a
regular basis. note tht critical updates are mentioned. not the standard updates. critical updates usually fix exploits to your computer that can cause problems by hackers or viruses.

 

 

 


Comment/Reply (w/o sign-up)

alan
Dear dexter,
I have just checked the system processes and found msblast.exe is running.
Even I give end task, I reappears after restart. So instead of making so much work to remove this worm, I have ordered XP SP2 CD from Microsoft and I hope that this will solve the Problem. biggrin.gif
---Thank you for Reply.

Comment/Reply (w/o sign-up)

bureX
Remove that worm first before installing SP2! Besides, it may take a while before you receive it!

First, end the msblast.exe task to make sure that your PC won't restart.

Then, go to this web site and scroll down to the bottom of the page where you will find the instructions on how to remove the worm:

http://www.pchell.com/virus/msblast.shtml

There are patches available from Microsoft also right here:

http://www.microsoft.com/downloads/details...&displaylang=en

PS: Try not to double post please...

Comment/Reply (w/o sign-up)

ramon
See the above posts, you are infected with an virus.
Also if you find you do not have enough time to complete the above procedure to remove the virus, do the following:
start -> Run --> type: "CMD" --> clic ok.
type the following in the black box (dosscreen):
shutdown -a <press enter>

The message will now disapear and you will have enough time to complete all the rest.

good luck.

Comment/Reply (w/o sign-up)

guangdian
I think if you have get the SP1 then this bug will not displayed.
but you have dink sp1. it's just a Xp bug but not a virus don't worry.

Comment/Reply (w/o sign-up)

Izlude
Theres another way of getting rid of that, not installing SP2 or typing shutdown -a ...


Open the Start Menu > Run .. > type "services.msc"

In that list find the "Remote Procedure Call (RPC)" item.
Right click > Properties > 'Recovery' tab

In First, Second and Subsequent Failures choose "Restart the service". Apply and you're done.

Note: I cant recommend this method with the LSASS bug/exploit. I tried it already but Windows started acting funny. Keep your firewall on for this one.

Comment/Reply (w/o sign-up)

Binod Singh
I have faced the same problem last week, I never thought that it would be a virus problem or windows XP bug.

My computer has not been upgraded to XP SP2.

But, when I installed Avast virus home edition and also upgraded my mozila firefox to 1.0.2 the message disapeared.

I don't know, which one acted. During installation avast antivirus has found one virus that was lovegate, which have been removed now.

Comment/Reply (w/o sign-up)

Matt1eD
In my old Win98 days I had that once (whilst trying to connect to my VPN). Left it and it went away! No virus/trojan e.t.c. scan picked it up.

Comment/Reply (w/o sign-up)

Casanova
Wow, is the msblast worm still circulating around? I rember having to deal with it more than a year ago, but then it eventually died out.

Comment/Reply (w/o sign-up)



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Pages: 1, 2
Similar Topics

Keywords : Rpc Windows Xp Shutdown Xp

  1. Microsoft Windows Dhcp Client Service Remote Code Execution Vulnerability - (1)
    What it is A exploit in the buggy OS of XP has been found, this one concering DHCP. OS effected
    Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows
    2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced
    Server SP4 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Datacenter Server SP1
    Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP3 Microsoft
    Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Professional Microsof...
  2. Windows Vista Sp1 Blocks Antivirus Programs - (5)
    Well it seems this is the first major problem for Vista SP 1 in the sense for those who have the
    following Secuirty Suites installed on your ocmputer that is running Vista. They block the
    following programs; Zone Alarm Security Suite 7.1, Trend Micro Internet Security 2008, BitDefender
    10, and the 2008 version of the Jiangmin antivirus. As for the reason why these programs don't
    work, Microsoft says "they are incompatible and so they must be block". Well not exactly like that
    but you get the point they also mention that other small programs might now work either b...
  3. Windows 7-windows Live Ties - Microsoft is at it again (0)
  4. Windows Xp Restarts When Using The Internet - (0)
    Hi Guys, I've had a problem with my computer. I thought it restarted only when using the
    internet but I was wrong. I found out that isn't the denominator. I tried disabling the internet
    to run a virus scan and the scan can't complete as the computer restarts too often. I followed
    the following instructions to read the dmp file the restart error generates. 1) Download and
    install the http://www.microsoft.com/whdc/devtools/deb...installx86.mspx Debugging Tools from
    Microsoft 2) Locate your latest memory.dmp file- C:\WINDOWS\ Minidump\Mini081505-01.dmp or...
  5. Windows Vista Less Secure Than Older Versions? - (7)
    my brother has windows vista and told me that it is safer than other versions of windows but
    according to other people they say that it has bugs and other stuff whick one of these are true?...
  6. Major Flaw In .ani File Found In Windows 98 Through Vista Creates Major Security Risk - Vista Aint that Secure at all (9)
    I was able to browse around this and found it interesting since this vunerability is found in 4
    Microsoft Operating Sytems, Windows 2000, Windows XP, Windows Vista, Windows 2003 Server. From the
    article Microsoft stated that their is a hole in the .ani files, which happen to be related tothe
    mouse cursor, when the mouse icon changes depending on what you do. They only mention that with
    this flaw it always hackers to break into someone computer and do their thing. But in another
    article relating to this attack it was mention that in order for this to happen a user has ...
  7. Some New Apple Ipods Contain A Virus From Windows! - (7)
    Here is the deal. I got this video ipod recently and it turns out that it had a worm on it. I was
    only one fo the few but it did have one. The virus is called RavMonE Virus. Here is a link to find
    out more about it. more info It doesn't affect macs only windows based computers. I plugged
    it up to the computer and my antivirus detected a worm and I was very surprised. I did some
    research and it turns out that some contracted company who builds the ipods for apple had computers
    connected to the ipods and they had been infected. These computers were windows...
  8. Windows Crashing. Can't Use Opera Or Firefox - deleted files in temp folder (3)
    Windows has been acting strangely by now, it freezes/clogs badly, I can't use Opera, MF or
    continue my tutorials due to this problem. It gets on my nerves as I think it was MY problem because
    I deleted MOST of the files in the Temp folder. CODE (Start>Run...>%Temp%) That folder,
    most of the files were deleted by me. I consulted my friend by half-screwed MSN, he said I "effed me
    up the arse" by doing that. He recommended me backing up and formatting. I never did that before so
    I think it will be most-likely half-impossible for me. And as I don't have a ...
  9. A Very Simple Security Tip - for Windows 2000/XP (13)
    We all know the difference between a limited user and an administrator user under Win2k/XP - you
    can't/can install major software, perform system maintainence, and other stuff. But using a
    limited user on a day-to-day basis also provides you with decent protection from a bunch of threats:
    if the malware is running under your limited-rights user, it can only do as much as you can. For
    instance, a limited rights user can't edit the HKLM hive of the Registry, so any malware running
    under the same user won't be able to touch that area. It's extremely simple t...
  10. Worm Disguises As Windows Genuine Advantage - be careful of the wgavn service ... (5)
    QUOTE IT security experts have warned of a worm that purports to be Microsoft's Windows
    Genuine Advantage (WGA) anti-piracy tool. WGA has recently been branded as 'spyware' in
    that it collects unnecessary hardware and software data from users' PCs. The Cuebot-K worm
    spreads via AOL Instant Messenger, registering itself as a new system driver service called
    'wgavn'. It carries the display name 'Windows Genuine Advantage Validation
    Notification', and runs automatically during system startup. Once in place the worm disables
    the Wi...
  11. Windows Xp Pro Exploit: Permission Setup Allows Access To Task Manager During Login - even if permissions deny this abiltity. (1)
    A friend of mine was temporarily banned from the computers at my school a while ago after he
    accidentially found a way into Task Manager, which is disabled on our network. He has had his
    permissions restored now, but has no idea why he got banned in the first place. However, recently he
    explained what he did to me, and I tested it. I soon found out that, by accident, we had both
    discovered that there is a Security Exploit in networking Windows XP Professional. The exploit is
    to do with network permissions. Windows XP recieves the permission data from the network as soon...
  12. Top 7 Antivirus For Windows - (13)
    This will help for those who likes to know if they are using one of the best Anti-virus programs.
    1. Platinum Internet Security 2005 2. PC-cillin Internet Security 2005 3. BitDefender Professional
    Edition 4. ZoneAlarm Internet Security Suite 5. F-Prot for Windows 6. Kaspersky Anti-Virus Personal
    7. G Data AntiVirusKit 2005 (AVK) Reference:
    http://antivirus.about.com/cs/beforeyoubuy/tp/aatpavwin.htm ...
  13. Serious Wmf Windows Exploit - No-one is safe right now (16)
    This has blown up big time in the last 3 days: http://www.f-secure.com/weblog/ ...
  14. Microsoft Plugs Windows Worm Holes - 14 flaws in Windows... (3)
    http://news.zdnet.com/2100-1009_22-5893344.html?tag=nl.e589 Here is another proof that the words
    'Windows' and 'Security' simply cannot go together... And yet another good reason
    for installing and start using Linux... Cheers! KoYoda...
  15. Windows Security Scanners - (0)
    hi all, In this topic I'm gonna start explain about windows security scanners , leave your
    comments and hope to enjoy /smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' />
    :: Nsauditor Network Security Auditor Nauditor is a network security scanner that allows to audit
    and monitor network computers for possible vulnerabilities , to see all open ports and owner program
    names, including the process loaded modules, kernel objects, memory details, remote address and
    state of connections, dns name, country where from, service associated with connect...
  16. [exploit] Microsoft Windows 2000 Plug And Play - (1)
    Microsoft Windows 2000 Plug and Play Universal Remote Exploit #2 (MS05-039) /*
    HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2 * * Copyright © 2005 houseofdabus. * * (MS05-039)
    Microsoft Windows Plug-and-Play Service Remote Overflow * Universal Exploit + no crash shellcode * *
    .:: ::. * * --------------------------------------------------------------------- * Description: * A
    remote code execution and local elevation of privilege * vulnerability exists in Plug and Play that
    could allow an * attacker who successfully exploited this vulnerability to take * complete con...
  17. [article] Windows Syscall Shellcode - (0)
    Hi friends, this article shows how shellcode can be written and executed on a Windows host without
    using any native API calls at all . By : Contact : Link to this article :
    http://securityfocus.com/infocus/1844 Removed personal info ...
  18. [exploit] Microsoft Windows 2000 Plug And Play - Universal Exploit (0)
    Microsoft Windows 2000 Plug and Play Universal Remote Exploit (MS05-039) /* Windows 2000
    universal exploit for MS05-039 -\x6d\x35\x6c\x30\x6e\x6e\x79- */ #include #include #include
    #include #include #include #include #pragma comment(lib, "mpr") #pragma comment(lib,
    "Rpcrt4") BYTE Data1 = {0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,
    0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,
    0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00,
    0x30,0x00,0x30,0x00,0x30,0x00,0x30,0x00,0x00,0x00,0x00,0x00, 0xFF,0xFF,0x00,0x00,0x...
  19. [exploit] Microsoft Windows Remote Desktop Dos - (0)
    Microsoft Windows Remote Desktop Protocol DoS Exploit (MS05-041) // Windows XP SP2
    'rdpwd.sys' Remote Kernel DoS // // Discovered by: // Tom Ferris // tommy
    security-protocols com // // Tested on: // Microsoft Windows XP SP2 // // Usage (SPIKE) :
    ./generic_send_tcp 192.168.1.100 3389 remoteass.spk 1 0 // // 8/9/2005 Security-Protocols.com // //
    This program is free software; you can redistribute it and/or modify it under // the terms of the
    GNU General Public License version 2, 1991 as published by // the Free Software Foundation.
    s_block_start("packet_1...
  20. Phishguard - Detects Spoofing Attacks - Windows Tools - Spoofing (1)
    QUOTE PhishGuard is a FREE service that detects and rapidly disables Internet "phishing" or
    "spoofing" attacks designed to steal critical financial data. Phishing attacks use fraudulent
    websites and emails that mimic well-known organizations in order to trick unsuspecting Internet
    users. A simple login or account number entry screen becomes a sophisticated trap. By assuming you
    are dealing with a trusted party, you can reveal financial information including credit card
    numbers, bank accounts, passwords, and social security numbers to the "bad guys". This type of att...
  21. Microsoft Windows Plug-and-play Exploit - (0)
    wow, you can get this famous vulnerabilty exploit here: http://www.milw0rm.com/id.php?id=1149
    have fun /smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /> ...
  22. Microsoft Windows Plug-and-play Service Remote Ove - (3)
    This is the c code you can compile it with lcc win 32 or gcc or virtual c++ ... /* Windows 2000
    universal exploit for MS05-039 -\x6d\x35\x6c\x30\x6e\x6e\x79- */ #define WIN32_LEAN_AND_MEAN
    #include #include #include #include #include #include #include #pragma comment(lib,
    "mpr") #pragma comment(lib, "Rpcrt4") BYTE Data1 =
    {0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,
    0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,
    0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00,
    0x30,0x00,0x30,0x00,0x30,0x00,0x30,0x00,0x00,...
  23. Security Hole In Windows Xp Found - Same (2)
    Good Evening i've found a security hole in win xp witch can cause a problem for bussiness
    users. if u have windows xp installed u can insert at the boot a windows 2000 cd and use the
    recovery console. in this way u'll gain admin-rights and change the passwords of all users and
    copy data onto removeable media. go into the bios-setup and set the boot ONLY from the harddisk and
    set a master-password sorry, but my english isn't very well 'cause i'm from
    austria... mfg STREETRULEZ ...
  24. Windows 2000 Security Hardening Guid - (2)
    Well I thing most users of here are using Microsoft , yea ? maybe some of them use Win2000 ,
    It's from microsoft >>> Overview This document provides administrator guidance for how to set up
    and configure secure Windows 2000 systems in several scenarios. This document is a baseline for
    other hardening guides published by Microsoft, such as the Microsoft Solutions for Security. This
    document is not meant as a replacement for the Windows 2000 Common Criteria Security Configuration
    Guide, but rather as a more generally applicable hardening guide which applies to a much ...
  25. How To Remove A Windows Service - (0)
    Find the tool INSTSRV.EXE, and download it to SYSTEM32 folder.. Then type the command, INSTSRV
    REMOVE I'll really happy if the attachment option is enabled......
  26. Windows Update Email Scam - its a trojen horse (8)
    QUOTE A new scam by hackers has some people believing they are receiving an e-mail about a
    critical update to Windows when in actuality they are installing a Trojan horse, Sophos said on
    Friday. The e-mail directs victims to a fake version of the Windows Update site, where there are
    links to download the malicious "patches." "The email uses the Microsoft branding and style so to
    the casual observer it appears to be legitimate," Gregg Mastoras, Senior Security Analyst at Sophos,
    told BetaNews. If users download the "patches," they are actually installing the Troj/DS...
  27. Windows Firewalls Lacking - Windows Firewalls Lacking (0)
    whyme says: COPIED AND PASTED THIS FROM :
    http://www.theregister.co.uk/2005/03/18/wi...er_firewall.com QUOTE For something as simple as
    a firewall for Windows servers, a good solution just doesn't exist. I have a problem: I
    can't seem to find a good host based firewall for my Windows servers. In fact, people constantly
    ask me what I recommend and I find myself with no good answer. Even though most of my servers are
    already behind firewalls, I like having additional protection on the server itself. Sometimes I use
    remotely co-located servers where I h...



Looking for rpc, windows, xp, system, shutdown, xp

Searching Video's for rpc, windows, xp, system, shutdown, xp
See Also,
advertisement


Rpc In Windows Xp - System shutdown in XP

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com