|
| Notices |
DriverHeaven is currently recruiting for the AWOMO Beta Test / Elite Op Team. AWOMO is a digital download service for games, and we're looking to expand the beta team. If you're interested. Sign up as a member here at DriverHeaven and then head HERE to submit your details. Thanks
For more info on AWOMO visit their site HERE
Welcome to the DriverHeaven.net forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us. |
 |
Jan 24, 2004, 12:47 PM
|
#1
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Remote Procedure Call (RPC)
I have been having a problem with new XP installs. For some reason (and this same problem has occured on more than 10 new builds now) when I open apps like mcafee AV or the epson printer driver installation or anything else for that matter after about 10seconds, they close themselves without any error messages. If I open the program again, the same thing happens. I was getting really anoyed with this and then I got an error a couple of minutes later.
This message was telling me that the PC is to be shut down in one minute because the Remote Procedure Call (RPC) has terminated unexpectidly. I went into the services and told the RPC to restart the service instead of rebooting the PC.
Now this seems to have done the trick but I'm not sure why it might be happening.
This all started when I shut down my perferctly normal, working pc and then turned it back on 20minutes later to find my hard disks were corrupt and all my data gone. I have not been able to get XP to install normally after that.
Any ideas.
|
|
|
Jan 24, 2004, 01:11 PM
|
#2
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Location: Virginia, USA
Posts: 3,568
Rep Power: 0
|
Yup, you have the blaster worm or one of its variants.
First, d/l this and run it asap before your system reboots. http://grc.com/files/DCOMbob.exe
Go to the 3rd tab and immediately click on the "Disable DCOM" button. When you reboot, you will not be forced to shut down again.
Second, go here and d/l the removal tool http://www.symantec.com/avcenter/
Then go to Windows Update and update your windows, all critical updates.
|
|
|
Jan 24, 2004, 01:25 PM
|
#3
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
I'm not sure how this can be a virus though. My hard disks were formatted completley before starting the rebuilds. The Machine wasn't connected to the internet so couldnt be picking it up from there. The only software was the windows disk which is definatley clean of any viruses.
My anti virus software is up to date and doesn't see any problems so I'm inclined to think this is something to do with hardware.
|
|
|
Jan 24, 2004, 01:28 PM
|
#4
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Location: Virginia, USA
Posts: 3,568
Rep Power: 0
|
I am standing by what I said. I've seen it hundreds of times. You get a 60 second count down before your system restarts. It is the Blaster Worm or one of its variants. You can at least keep your system from shutting down by disabling DCOM. I recommend to at least disable the dcom and then do the symantec security response and then do the virus scan. You will see that I am correct.
|
|
|
Jan 24, 2004, 01:49 PM
|
#5
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Thanks man, that seems to have done the trick. I am now throwing every known blaster removal tool at my machine now. I'm puzzled as to where the virus came from though.
Having said all that - I was having major problems getting the FarCry demo to unpack and had to do it manually. My old (Norton crap) anti virus was causing the data.cab file not to extract but made it loop at a certain point but didn't recognise it as a virus. I stupidly removed Norton and got the files extracted. about 24 hours after removing norton AV, the problems began.
Damn Damn Damn! 
|
|
|
Jan 24, 2004, 02:02 PM
|
#6
|
|
DriverHeaven Extreme Member
Join Date: Oct 2003
Location: Gefle, Sweden
Posts: 3,226
|
Quote:
Originally posted by Logla
I'm puzzled as to where the virus came from though.
|
WinXP has a huge security hole from where this can come through automatically on any system that is not protected in one way or another. Microsoft oftenly gets a lot of undeserved flak for various things, but this one issue is so huge that it cannot be exaggerated.

|
|
|
Jan 24, 2004, 02:28 PM
|
#7
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Quote:
Originally posted by mkk
WinXP has a huge security hole from where this can come through automatically on any system that is not protected in one way or another. Microsoft oftenly gets a lot of undeserved flak for various things, but this one issue is so huge that it cannot be exaggerated.
|
Oh I appreciate this flaw however, how can the virus come through if the computer is physically disconnected from the internet?
|
|
|
Jan 24, 2004, 04:54 PM
|
#8
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Location: Virginia, USA
Posts: 3,568
Rep Power: 0
|
You most likely got it when you connected to do updates of your anti-virus. If you have the Messenger service on or DCOM turned on, then you can be infected. All it takes is a second.
This is why I am either behind a firewall when I first connect a winxp /win2k machine to the net even if it is dial up. Put on a software firewall. You can get it via dial up as well. (seen it very many times)
It doens't always start causing problems right away either. It can take a bit which is what may have happened in your case. OR if you are on a LAN, then someone or another machine on the LAN has it and spread it to you.
|
|
|
Jan 26, 2004, 06:30 AM
|
#10
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Used stinger - didn't find anything. Wierd
Something else I thought a bit wierd. When I used DCOMbobulator to disable DCOM, it opened DCOM on port 1025 and switched on UPnP. I have since configured the firewall to stealth that port and I've turned off UPnP. Everything seems ok now but I have not found one instance of any virus on the machine so far. Everything is up to date so I should be ok but this is really wierd and has me a bit worried.
|
|
|
Jan 26, 2004, 06:56 AM
|
#11
|
|
Member
Join Date: Mar 2003
Posts: 5,989
|
if there's no more 'RPC has terminated unexpectidly' error. i think you should be OK,
when you've got a good firewall, AV with def/dat files uptodate and all the Win Updates security patches. anyway, during this period try running Windows Task Manager (Ctrl-Shift-Esc) frequently and sometimes check the Startup tab in System configulation Utility (msconfig), look for someting install, not by you.
and stop by Shields UP! site to check your FW sometimes and if you have any ports listing as close or open... pls post back and will check more into it.
|
|
|
Jan 26, 2004, 08:44 AM
|
#12
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Checked shields up! and got 100% True Stealth - all ports stealthed.
I have just had an RPC error about 20mins ago. It happened whilst trying to install the Farcry demo again. That download was from a different source and was a different type of file to that of the one that caused nortons to start looping the file.
|
|
|
Jan 26, 2004, 11:35 AM
|
#13
|
|
Member
Join Date: Mar 2003
Posts: 5,989
|
Quote:
Originally posted by Logla
I have just had an RPC error about 20mins ago.
|
other than the Blaster Worm, i cant think of anything that cause prob with RPC service in XP. (there's afew in NT/2k.. Not in XP)
i think we'll have to go from event logs info.
go to Administrative Tools -> Event Viwer, see for any Error(type)
in Application, Security and System..
D-click on each Error you find in there,
and hightlight and copy the "Event ID:" , "Sourec:" and "Description:",
then post the info here,
here's an example of format and info....
-----------
System
Sourec: NetBT
Event ID: 4311
Description: Initialization failed because the driver device could not be created.
----------
Application
Sourec: XXXXXXX
Event ID: XXXX
Description: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
-----------
|
|
|
Jan 26, 2004, 12:53 PM
|
#14
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Event Source: USER32
Event ID: 1074
Description:
The process winlogon.exe has initiated the restart of XXXXX-XXXXXXXX for the following reason: No title for this reason could be found
Minor Reason: 0xff
Shutdown Type: reboot
Comment: Windows must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly
What I notice before this was :
Event Type: Warning
Event Source: atapi
Event Category: None
Event ID: 26
Description:
The driver has detected that device \Device\Ide\IdePort1 has old or out-of-date firmware. Reduced performance may result.
and
Event Type: Warning
Event Source: Disk
Event Category: None
Event ID: 51
Description:
An error was detected on device \Device\Harddisk0\D during a paging operation.
I dont think (or rather I hope) that this is my RAID0 array, but the 20gig disk I had before removing it yesterday to put in my mp3 server. Its been playing up in the BIOS in that sometimes the BIOS doesn't pick the disk up or sometimes the CD-ROM that is on the same channel is missing. The jumpers and everything were all ok and I couldn't find a firmware upgrade for the drive (old maxtor 20gig).
|
|
|
Jan 26, 2004, 01:47 PM
|
#15
|
|
Member
Join Date: Mar 2003
Posts: 5,989
|
Quote:
Originally posted by Logla
Event Source: USER32
Event ID: 1074
Description:
The process winlogon.exe has initiated the restart of XXXXX-XXXXXXXX for the following reason: No title for this reason could be found
Minor Reason: 0xff
Shutdown Type: reboot
Comment: Windows must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly
|
go to - http://www.sysinternals.com/ntw2k/fr.../procexp.shtml
and D/L Process Explorer (x86 - 230 KB) - free
make sure to D/L the one that say - you plan on using Process Explorer on WinNT/2K/XP
extract the zip file (procexpnt.zip), and run it.
on the top window of the program, click WINLOGON.EXE,
at the below window, scroll down to see handle "0xFF"
see if you can any info there.
more info about Event ID: 1074
Description of the Shutdown Event Tracker
http://support.microsoft.com/default...=kb;ja;Q293814
Last edited by Net; Jan 26, 2004 at 02:26 PM.
|
|
|
Jan 26, 2004, 03:07 PM
|
#16
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Can't find 0xFF but there is a 0xF4 and a 0xF8 - are those ones related?
|
|
|
Jan 26, 2004, 05:38 PM
|
#17
|
|
Member
Join Date: Mar 2003
Posts: 5,989
|
Quote:
Originally posted by Logla
Can't find 0xFF but there is a 0xF4 and a 0xF8 - are those ones related?
|
i dont think the two were related with the prob., one of that is winlogon/notify registry,
i've seen the other but its not.
re RPC service terminated unexpectedly in your event ID 1074,
you did not enable the Shutdown Event Tracker nor edit registry for it,
and if you did it would be listed as "Information", Not an Error.
as of now all the info i've found for XP is still about the blaster,
Check the blaster again - http://aumha.org/search.htm
and this.. http://www.kellys-korner-xp.com/xp_qr.htm#rpc
scroll down the page and look for "Remote Procedure Call (RPC) Exploit"
here's information about event ID 51 - http://support.microsoft.com/default...=kb;ja;Q244780
if you have the error at every reboot then maybe hardwares or pagefile related,
if there's no more then its common warning to many controllers.
and the event ID 26 should be ended now..
|
|
|
Jan 26, 2004, 06:45 PM
|
#18
|
|
I = Greatest Dood
Join Date: Nov 2003
Location: PuNk
Posts: 5,854
Rep Power: 42
|
i picked upt he problem only seconds after connecting to the internet.....
|
|
|
Jan 27, 2004, 03:50 AM
|
#19
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Panging, thanks for your help on this.
Problem is now gone and all is ok since I removed the other hard disk and installed it in my server. The server is now having problems, not with shutting down but disconnecting itself from the network. I cant find a virus on the disk but I think there may be a problem with it. Its a reconditioned 20Gig that I got from an old machine at work which was being decommisioned.
I'm going to try a different disk in the server and see what happens.
|
|
|
Jan 27, 2004, 04:43 AM
|
#20
|
|
Member
Join Date: Mar 2003
Posts: 5,989
|
i'm very glad that your main PC is sorted and any time Logla. 
i'm not sure about the old disk, i'd format it again,
-> FDISK and delete all parttitions, then FDISK /MBR and reset.
-> FDISK create a new, FORMAT
|
|
|
Jan 31, 2004, 09:53 AM
|
#21
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
AAAARRRRGGGGHH!
ITS HAPPENING AGAIN!!!
I've just rebuilt my file server.
Exactly the same things are happening but I can't get rid of them.
I can't get McAfee to stay up for more than 20 seconds in order to do a system scan. Stinger finds nothing on the computer. I can't even install the security updates. Everytime I try to run one of them, they just close down not even halfway through. Even if I try to install them from windows update, when I reboot, the machine still says that they need to be installed and I continue to have problems. My main machine is now fine and I dont have any problems but I dare not connect the two incase the main one gets infected.
Any ideas?
|
|
|
Jan 31, 2004, 10:13 AM
|
#22
|
|
DriverHeaven Extreme Member
Join Date: May 2003
Posts: 3,302
Rep Power: 0
|
Got it sorted - all it took was to boot into safe mode and install the update in there. I could have saved myself three bloody hours if I had of considered that earlier.
|
|
|
|
|
|