heres my story, here i am browsing pgatour.com when BOOM outta nowhere i get a message saying “windows must now restart because the remote procedure call service terminated unexpectdly” then it gave me 1 min to save all my work then it restarts. this is the 5th time it has happened to me, i am running windows xp home edition, can anyone help me? i checked out my help file and other sources on the internet but they dont explain how to solve this problem.
Just been there and done that with my girlfriend’s computer.
http://boards.straightdope.com/sdmb/showthread.php?threadid=202359
We did as advised in the above-referenced thread and the behavior stopped.
You have been hit by the RPC-DCOM exploit. This allows a remote user to gain administrator access to your computer by exploiting the Remote Procedure Call service, thus allowing them to install programs of their choice, access your files, or use your computer to attack remote users. You will know you’re infected when you see a message about an “NT AUTHORITY” error saying that the system will shut down in 60 seconds.
First, install the patch from Microsoft. You can download the patch and read more information at Microsoft Technet.
After this is installed, go to start, run, and type in msconfig. Go to the startup tab and UNCHECK “msblaster.exe”. Restart the computer, enter safemode by pressing the F8 key before windows loads and choosing Safemode from the menu that appears, and delete msblaster.exe. This is one of the several viruses that may have been installed.
WARNING: It is entirely possible that other viruses or trojans could have been installed. Furthermore, there may still be keyloggers or file servers running. Keyloggers will send your passwords or any credit card data you type in to a remote user. A file server could be hosting child pornography, pirated software, or other illegal content. I strongly suggest that you format your computer, then install the patch on a clean system BEFORE you connect it to the internet.