malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by radiii64, Jul 7, 2006.

  1. radiii64

    radiii64 Private E-2

    i have a gateway system with a 633mhz chip
    win xp office
    40g h/d
    when i boot up i get a window that pops up and says
    this system is shutting down.
    save work,etc.
    initiated by NT AUTHORITY\SYSTEM
    windows must now restart because the remote call (rpc) service terminated unexpedly.
    before i started getting this message i was having a malware prob with a browser hihjack. which i believe i have removed.
    any help would be greatly appreciated.
     
  2. radiii64

    radiii64 Private E-2

    sorry
    it restarts 40seconds after this window pops up.
    and keeps doing this
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Sounds like the Blaster Worm, happens when Windows XP has not been upated to latest Service Packs and updates.... what Service Pack is your XP? you can find this by right clicking My Computer > Properties and on the general tab it will state under System if their is a Service Pack installed eg. Service Pack 1 ( SP1 ) or Service Pack 2 ( SP2 )


    you will need to follow this http://www.microsoft.com/security/incident/blast.mspx

    and even run this Blaster Worm Removal Tool

    then once finished that before you can update XP, if you are running a none SP2 you will ahve to clear your PC of all Malware as the Service Pack will not install correctly with Malware on the PC... so please follow the below guide,

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    .
     
  4. radiii64

    radiii64 Private E-2

    ok i was bale to check the system
    there are no service packs installed and i was wrong its xp professional
    i also believe its a bootleg
    ive tried to install the service packs and they wont load because of that.
    also i didnt see msblast listed when i hit ctrl/alt/delete
    the system wont stay running long enough to run anything.
    from power on to the shutdown is maybe 5 min max
    3 of those 5 are used in the boot process.
    once my background loads ive got a max of maybe 3 min
    before it starts shutting down and restarting
    i get the feeling im forked here
    thanks for the quick response
    any other ideas?
     
  5. radiii64

    radiii64 Private E-2

    anybody have any ideas?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the below tools onto another PC and copy them to the problem PC via a CD or any other method possible. Then run them on the problem PC and let us know the results. Also on the problem PC, boot it up with your network cable unplugged. This will some times help keep it running longer.

    Microsoft Blaster Worm Removal Tool

    Symantec W32.Sasser Removal Tool

    McAfee AVERT Stinger

    However note: If the PC is running an illegal copy of Windows and does not have the proper Windows Updates. You may be reinfected (even if you do get it fixed) with in a minute or two of connecting it to the internet.
     
  7. radiii64

    radiii64 Private E-2

    ok here i go
    after getting the items you suggested i turned the prob comp on
    and noticed that on startup that my avg kept popping up a window stating that it couldnt start.
    so went in to start up and disabled it as well as zonealarm seeing as how i wasnt connected to the net.
    this increased my " on " time to roughly 11 mins.
    no i do not get the rpc box the comp now just restarts without any warning.
    ok now to the items i downloaded.
    the ms blaster told me that ms03-26 needed to be installed
    so i searched the net and found windowsxp-kb823980-x86-ENU.exe that had the needed fix.
    now i get a window that tells me it could not verify the integrity of file update.inf. and to make sure the cryptographic service is running.
    as for the macafee avert and sasser tools the comp wont stay running long enough to complete them.
    my main concern for trying to fix this thing is that its a new western dig. h/d
    and i had a lot of pictures on it that i hadnt gotton on to disc.
    with the extended time i gained i have managed to get the pics on disc.
    i would now not have a prob with reformatting the h/d.
    i actually tried this before i posted here and got a window that told me it couldnt be done. sorry i forgot to write the reason down for this.
    is it poss to reformatt with the disc provided with the h/d?
    or does any 1 think that i can fix this prob?
    thanks
     
  8. radiii64

    radiii64 Private E-2

    update
    while looking for a file my wife needed on the prob comp
    i ran across the following - winsockxpfix.exe
    so i ran it. after which the comp stayed on without restarting for about
    a hr and a half. during that time i ran a 2005 version of stinger that found nothing. i then shut it down to post here and get the other dloads.
    i am getting ready to try running the new stinger and sasser dloads to see what happens.
    will post results later
    if any 1 has any other suggestions let me know
    thanks
     
  9. radiii64

    radiii64 Private E-2

    ok the stinger and sasser both ran all the way through
    without finding any probs.
    the prob comp seems to be staying on now
    however when i went to the device manager the list wouldnt
    come up.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your best bet is to try to run what Halo gave you in message # 3:
    You may have other non-malware problems! It sounds like you are running an unpatch OS which could get infected with some real nasty malware within 5 minutes of connecting to the internet.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds