Announcement

Collapse
No announcement yet.

ARRRGGG! Every XP rig in our building spontaniously rebooting!?! Please help...

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • ARRRGGG! Every XP rig in our building spontaniously rebooting!?! Please help...

    OK.
    This started happening this morning at work.
    Every machine in the building that has XP, and is connected to the network is rebooting every few minutes.
    I expected it was an outside attacker, as our network was pathetically unprotected. (DSL modem->hub(s)->PCs...no firewall of any kind)
    Convinced the boss to let me go buy a router with a firewall.
    Got it hooked up.
    No change. XP rigs are still rebooting at will. 9x machine seem unaffected.

    This is the message I'm getting (which caused me to this it was an outside attacker):

    This system is shutting down.
    Please save all work in progress and log off.
    Any unsaved changes will be lost.
    This shutdown was initiated by NT Authority\System.
    Time before shutdown xx.xx.xx (counts down from 1 min)
    Message:
    Windows must restart because the Remote Procedure Call (RPC) service terminated unexpectedly.
    Please...anyone got an idea WTF is going on here>???
    Core2 Duo E7500 2.93, Asus P5Q Pro Turbo, 4gig 1066 DDR2, 1gig Asus ENGTS250, SB X-Fi Gamer ,WD Caviar Black 1tb, Plextor PX-880SA, Dual Samsung 2494s

  • #2
    Found this...hopefully it will help....

    Core2 Duo E7500 2.93, Asus P5Q Pro Turbo, 4gig 1066 DDR2, 1gig Asus ENGTS250, SB X-Fi Gamer ,WD Caviar Black 1tb, Plextor PX-880SA, Dual Samsung 2494s

    Comment


    • #3
      Hi Kruzin!
      Its a worm! Check this thread for details: http://forums.murc.ws/showthread.php?s=&threadid=43662

      Cheers
      Ovi

      P.S. The anti-virus sites (Symantec etc) also have posted info on this.

      Comment


      • #4
        We do run a current virus scanner (symantec NAV). Not so sure it's a virus.
        That security hotfix from MS in my last post (which I see is also in that thread you linked to) seems to have fixed them right up...
        Core2 Duo E7500 2.93, Asus P5Q Pro Turbo, 4gig 1066 DDR2, 1gig Asus ENGTS250, SB X-Fi Gamer ,WD Caviar Black 1tb, Plextor PX-880SA, Dual Samsung 2494s

        Comment


        • #5
          Its probably a worm called ms blaster
          Symantec security research centers around the world provide unparalleled analysis of and protection from IT security threats that include malware, security risks, vulnerabilities, and spam.


          It (probably) send nukes out to random ip's, generating them on the fly using your ips first packed (213 for me)

          The worm is using a well known windows exploit, that used the RPC to couse the system to restart. And every infected computer is sending out nukes - its like judgment day .

          And thats my theory about it.

          Thats how i protected myself:

          Used kerio firewall to block all incoming traffic from any address to windows c:\windows\system32\svchost.exe, on the tcp 135 port.

          And it works.

          Comment


          • #6
            I'm just running my Linksys router as a firewall. Can I fix this without blocking port 135 entirely (what I've done for now)?

            Gpar_
            The Internet - where men are men, women are men, and teenage girls are FBI agents!

            I'm the least you could do
            If only life were as easy as you
            I'm the least you could do, oh yeah
            If only life were as easy as you
            I would still get screwed

            Comment


            • #7
              Look at the link in my second post.
              There is a hotfix from MS that fixed all the XP rigs at work.
              Core2 Duo E7500 2.93, Asus P5Q Pro Turbo, 4gig 1066 DDR2, 1gig Asus ENGTS250, SB X-Fi Gamer ,WD Caviar Black 1tb, Plextor PX-880SA, Dual Samsung 2494s

              Comment


              • #8
                Ok, for those of you paranoid about such things and distrustful of MS's fix...

                Block:

                TCP 135
                UDP 69
                TCP 4444

                And you're safe.

                NOW, if you already have the damn thing and can't get anything to stay up for more than a minute...

                Set your system date back to July. It only runs ... today onward. It is/was timed. You'll still be infected, but the popup will say "rebooting in... 30 days", which is IMHO plenty of time for you to fix it.

                Gpar_
                The Internet - where men are men, women are men, and teenage girls are FBI agents!

                I'm the least you could do
                If only life were as easy as you
                I'm the least you could do, oh yeah
                If only life were as easy as you
                I would still get screwed

                Comment


                • #9
                  I've had no ill effects from the fix/patch. I've been running machines using it for almost as long as the patch has been out. That's 9 Windows 2000SP4 machines and 10 XP SP1. THough I have to say I never had the problem in the first place with my Linksys firewall blocking the incoming traffic and my virus scanner churning 24/7.
                  Last edited by High_Jumbllama; 11 August 2003, 18:08.

                  Comment


                  • #10
                    Weird...this just happened to my friend today as well...was there some kind of mass hack going on today?

                    Comment


                    • #11
                      At least 3 posts on the topic on this page (changes daily) with a method of killing the thing if you have not kept up to date .
                      Lawrence

                      Comment


                      • #12
                        We updated 60+ computers with MS's patch a week ago and no problems known so far. Today was another round of the thing going off for those with affected computers.
                        Gigabyte GA-K8N Ultra 9, Opteron 170 Denmark 2x2Ghz, 2 GB Corsair XMS, Gigabyte 6600, Gentoo Linux
                        Motion Computing M1400 -- Tablet PC, Ubuntu Linux

                        "if I said you had a beautiful body would you take your pants off and dance around a bit?" --Zapp Brannigan

                        Comment


                        • #13
                          I was lucky at home. I just recently patched my machine. My machine is on the DMZ so I would have been screwed, but my other machine is not patched but safely behind the firewall

                          Sometimes it's nice to know that a product you are using(linksys) is doing it's job. hmmm...now that I think about it, I am running zonealarm on my machine so I would have been OK there to.

                          Anybody running a software or hardware firewall that had a problem?

                          Dave
                          Ladies and gentlemen, take my advice, pull down your pants and slide on the ice.

                          Comment


                          • #14
                            *sigh*
                            I was browsing the Windows Update website and was just going to download all patches when it struck. That's what I call good timing.
                            Tiny Personal Firewall doesn't seem to catch it for me, but Symantec does.
                            I wonder if it would be a good idea to install Symantec Antivirus again
                            <font size="-4">User error:
                            Replace user and try again.
                            System 1: P4 2.8@3.25, P4C800-E Deluxe, 1024MB 3200 CL2, 160+120 GB WD, XP Pro, Skystar 2, Matrox Parhelia 128R, Chieftec Dragon Full Tower (Silver).
                            System 2: P4 2.0, Intel 845, 1024MB Generic RAM, 80GB WD, XP Pro, Promise Ultra133 TX2, GF3 Ti500. Resides in a neat Compaq case.
                            </font>

                            Comment


                            • #15
                              I read on a site now that 'shutdown -a' aborts the reboot and restarts the RPC server.
                              Try it.
                              <font size="-4">User error:
                              Replace user and try again.
                              System 1: P4 2.8@3.25, P4C800-E Deluxe, 1024MB 3200 CL2, 160+120 GB WD, XP Pro, Skystar 2, Matrox Parhelia 128R, Chieftec Dragon Full Tower (Silver).
                              System 2: P4 2.0, Intel 845, 1024MB Generic RAM, 80GB WD, XP Pro, Promise Ultra133 TX2, GF3 Ti500. Resides in a neat Compaq case.
                              </font>

                              Comment

                              Working...
                              X