Re: Have Virus - Need Help



From: "Michael Fischer" <MichaelFischer@xxxxxxxxxxxxxxxxxxxxxxxxx>

| I'm running Windows XP SP2 and every time I log on I receive NT SYSTEM
| AUTHORITY message and the machine reboots in one minute. In researching how
| to fix it (still haven't been able to) I now know how to stop the shutdown or
| fool it by changing the clock and have the timer run longer, but no tools
| (whether from Microsoft or Kelley's Korner or wherever I got the tool
| installed in AV-CLS or anywhere else I've found anything) detect a virus. I
| did find a registry entry where
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "windows
| auto update" = "msblast.exe". I removed that registry entry and one for
| mslaugh.exe. I could not find files named msblast or mslaugh anywhere on the
| PC. Anybody have any ideas?

They are certauinly indications of the Lovsan/Blaster worm that uses TCP port 135 to infect
a PC through a vulnerability in RPC/RPCSS DCOM.

However if you are running WinXP SP2 you should'nt be getting this via a TCP port 135
exploitation attempt.

The following is the pertinent patch -- KB828741
http://www.microsoft.com/downloads/details.aspx?FamilyId=D488BBBB-DA77-448D-8FF0-0A649A0D8FC3&displaylang=en

If you get a NT SYSTEM AUTHORITY shutdown message and you are connected to the internet,
disconnectr form the Internet. If you get the message and you are NOT connected to the
Internet then it is NOT a TCP port 135 explouiatation attempt but something has gone awry
with the RPC/DCOM sub-system.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm





.



Relevant Pages

  • RE: XP Performance
    ... Im running a Celeron in the same MhZ range as a P2 with XP sp2 and its not ... As a matter of fact, I would say the performance has increased ... > I have a Pentium II and I am running windows xp on it. ... I understand why its slow on the internet but not when I ...
    (microsoft.public.windowsxp.perform_maintain)
  • IE 6 does not work
    ... I'm running Windows XP v5.1 SP2 with 4 users. ... displayed" as soon as you try to connect to the internet. ... I re-did the shortcut to no avail. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: You might not have permission to use the network resource, Contact the administrator
    ... I have two computers hooked on a router both running windows xp sp2. ... Both connect to the internet fine. ... If you have forgotten where you posted or can't find your post, use Google Groups Advanced Search and search for your name. ...
    (microsoft.public.windowsxp.network_web)
  • CashBack,BullsEyeNetwork
    ... computer i am running Windows XP with SP2 and i go into ... not do this a ton of popups come up and internet explorer ... does not work and when i restart for some reason and log ...
    (microsoft.public.windowsxp.network_web)
  • Re: Delayed Write failed
    ... The data has been lost. ... The users are running Windows XP SP2. ... caused by a failure of your computer hardware or network connection. ...
    (microsoft.public.windowsxp.general)