Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
5/11/2005 3:49:44 PM EDT
Hey guys,

I have an issue with my computer. I keep getting these automatic shutdowns caused by the remote procedure call terminated unexpectedly.  I went into the admin tools and eliminated the automatic shutdown, but now it blue screen crachs after a while.  I think it's a fucking virus, but I am trying to get a project done and don't have time to mess around with it.  The one thing that that looks fishy to me is that I have 5 processes named svchost.exe  I am doing a full Panda scan right now, but was hoping someone here could help me out.

Thanks,
Echap
5/11/2005 3:58:40 PM EDT
[#1]
www.liutilities.com/products/wintaskspro/processlibrary/svchost

This should fix it and the problem it says is what is happening.
5/11/2005 3:59:15 PM EDT
[#2]
svchost - svchost.exe - Process Information
Process File: svchost or svchost.exe
Process Name: Microsoft Service Host Process
 
Description:
svchost.exe is a system process belonging to the Microsoft Windows Operating System which handles processes executed from DLLs. This program is important for the stable and secure running of your computer and should not be terminated. Note: svchost.exe is a process which is registered as the W32.Welchia.Worm. It takes advantage of the Windows LSASS vulnerability, which creates a buffer overflow and instigates your computer to shut down. To see more information about this vulnerability please look at the following Microsoft bulletin: www.microsoft.com/technet/security/bulletin/ms04-011.mspx  This is a registered security risk and should be removed immediately. Please see additional details regarding this process

Go to  free.grisoft.com/freeweb.php/doc/1 and download the free AVG software. Its the best ive used and it should fix you up..... Sounds like you have a worm on your PC......
5/11/2005 4:07:02 PM EDT
[#3]
Is that update not part of SP2 for WinXP?

I am running WInXP Pro and have Panda platinum Antivirus that updates every day automatically.

Edit to add, it said that SP2 did not need this patch.

Any other ideas?  This is pissing me off (the worm or virus, not you guys)

5/11/2005 4:15:09 PM EDT
[#4]
control panel
performance and maint.
admin tools
services


remote procedure call

go to the recovery panel
select take no action for all the boxes.
apply reboot

that should turn off the reboots so you can apply the fix.

you may have to work fast!!
5/11/2005 4:20:04 PM EDT
[#5]
FDISK:
5/11/2005 4:24:02 PM EDT
[#6]

Quoted:
control panel
performance and maint.
admin tools
services


remote procedure call

go to the recovery panel
select take no action for all the boxes.
apply reboot

that should turn off the reboots so you can apply the fix.

you may have to work fast!!



Thanks, already did that one.  

Just did a scan for the W32,welchia worm and the Symatec tool said that I did not have it.  

Maybe fdisk is not such a bad idea.   I hate MS windoze.

5/11/2005 4:43:22 PM EDT
[#7]
Did Panda detect any trojans, viruses, or hijackers on your PC?   After looking more it seems svchost.exe  can be used by alot of different spyware programs as well as windows programs. Probably why you have so many.  Here is a way to check your system and see what services are useing the svchost.exe to run... YOu should get a screen looking like this


support.microsoft.com/?kbid=314056

You may be able to use it to see if they are valid programs or functions. If they are you could have another issue and svchost.exe may have nothing to do with it..... See whats associated with it and let us know... Will keep looking into it more.

Also a little more info on another virus/worm associated with it.  

windowsxp.mvps.org/svchost.htm



This kinda thing interests me sooo much. Im not A+ certified but I try and have run circles around some guys I know that are..... Now to just get a techy job instead of pissy auto parts sales lol  
5/11/2005 4:57:54 PM EDT
[#8]

Quoted:
This kinda thing interests me sooo much. Im not A+ certified but I try and have run circles around some guys I know that are..... Now to just get a techy job instead of pissy auto parts sales lol  



You don't have to have an A+ to get a computer job.
5/11/2005 5:00:57 PM EDT
[#9]
LOL Ive applied multiple times at every local shop in my area in the past two years and not one call back... Ill keep trying lol
5/11/2005 5:44:18 PM EDT
[#10]

Quoted:
Did Panda detect any trojans, viruses, or hijackers on your PC?   ...snip  



No, ran it in safe mode and it came up clean.  I also made sure it was updated as of today.  
5/11/2005 5:53:15 PM EDT
[#11]
you may have memory issues such as bad memory. run memtest86. burn this image onto a cdrom as an image. then restart and boot from the cd. let the program run for a few hours while it test your memory.
5/11/2005 5:59:38 PM EDT
[#12]
Run this MS tool: www.microsoft.com/security/malwareremove/default.mspx

Run an online scan here: housecall.trendmicro.com/
5/11/2005 6:02:42 PM EDT
[#13]
You might also check your event viewer and look at the system and app logs.
5/11/2005 6:03:17 PM EDT
[#14]

Quoted:
Run this MS tool: www.microsoft.com/security/malwareremove/default.mspx

Run an online scan here: housecall.trendmicro.com/



The Microsoft scan was clean.  I also loaded the new microsoft spyware buster beta version and that scan said I was clean.  I am going to try the memtest asl sugested above.  

THANKS GUYS!!!!
Eric

5/11/2005 6:06:40 PM EDT
[#15]
The blaster virus won't show up in a virus scan, because the shutdown is caused by signals from other computers on the internet.

Download and install this patch from Microsoft, which should fix it.

Edit:  The patch is slightly bigger than a floppy, so you may need to burn it to CD from another computer, depending on whether yours will stay up long enough to download without rebooting.

After your project is done, make absolutely certain that you upgrade to SP2 before you do anything else on that computer.  At least yours is turning itself off to let you know that not having security updates is a bad thing.
5/11/2005 7:20:27 PM EDT
[#16]
the quickest way to keep it from shutting down is to kick on the firewall.  

Or you can from a command prompt type shutdown -a until you get the patch applied