NT AUTHORITY\SYSTEM

message from =?Utf-8?B?SUFO?= on 1 Jun 2004
HAD A PROBLEM WHEN I WENT ONTO THE NET. PROBLEM IS NOW TELLING ME THAT THE SYSTEM HAS TO SHUTDOWN BECAUSE OF `NT AUTHORITY\SYSTEM`. SOMETHING TO DO WITH A REMOTE PROCEDURE CALL. CAN SOMEONE PLEASE HELP
 
Bruce Chambers replied to =?Utf-8?B?SUFO?= on 1 Jun 2004
Greetings --

First of all, please unstick your CapsLock key. Posting in all
caps, as you have done, is the Usenet equivalent of shouting, and is
considered very rude. More importantly, posting in all caps makes the
post very hard to read, further reducing your chances of getting help.

If you connected the PC to the Internet without having first
enabled a firewall, without having first installed an antivirus
application with current virus definition files, and before installing
the KB828471 Hotfix, you're very likely to get infected from any of
the thousands of PCs on the Internet that are constantly broadcasting
the Blaster and/or Welchia worms. It only takes a few seconds of
exposure.

To stay on-line long enough to get the necessary updates, patches,
and removal tools, click Start > Run, and enter "shutdown -a" when the
next RPC countdown begins. This will abort the shut down. Also, make
sure you've enabled a firewall before starting, to preclude any more
intrusions while getting the updates/patches/tools.

MS04-012 Cumulative Update for Microsoft RPC-DCOM
http://support.microsoft.com/default.aspx?scid=kb;en-us;828741

What You Should Know About the Blaster Worm
http://www.microsoft.com/security/incident/blast.asp

W32.Blaster.Worm a.k.a. W32/Lovesan.Worm
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

W32.Blaster.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

W32.Welchia.Worm a.k.a. W32/Nachi.Worm
http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html

W32.Welchia.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.welchia.worm.removal.tool.html

McAfee AVERT Stinger
http://us.mcafee.com/virusInfo/default.asp?id=stinger

Bruce Chambers
 
roger replied to =?Utf-8?B?SUFO?= on 01 Jun 2004
Hi Ian,

Go to Start > Run and type
shutdown -a

This will stop the countdown and give you time to troubleshoot.
You have the blaster virus, you must enable a firewall, either XP's
own or a third-party one, like Zone Alarm, free at www.zonealarm.com

HOW TO: Enable or Disable Internet Connection Firewall in Windows XP
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q283673

Microsoft Security Bulletin MS03-39
http://support.microsoft.com/?kbid=824146

What You Should Know About the Blaster Worm
http://www.microsoft.com/security/incident/blast.asp

W32.Blaster.Worm a.k.a. W32/Lovesan.Worm
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

W32.Blaster.Worm Removal Tool
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

Also keep your system updated going to Windows Update.

Good luck
 
Cerridwen replied to =?Utf-8?B?SUFO?= on 1 Jun 2004
1) Lose the caps. It's considered yelling, is incredibly rude and makes
your posts very hard to read.

2) Another NSF! Does your mother still wipe your arse too?! If you have
time to post, you have time to search - http://groups.google.com - and
that's more help than you deserve! This question is asked and answered over
10 times *A DAY*. The reason you're asking is you're too damned lazy to wipe
your own arse and you expect someone else to do it for you. Well it ain't
gonna happen, bub. Wipe it yerself!
 

Archived message: NT AUTHORITY\SYSTEM (Microsoft Windows XP)