PDA

View Full Version : Some probs during accessing the internet..


anjul
January 9th 04, 09:43 PM
hi,
Im sending u the whole system log files....
pls reply me with sollution soon.


Event Type: Information
Event Source: RemoteAccess
Event Category: None
Event ID: 20158
Date: 17-Aug-03
Time: 10:46:03 PM
User: N/A
Computer: MASTERPIECE
Description:
The user adgeru@nda successfully established a connection=20
to Vsnl using the device COM4.

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.


Event Type: Information
Event Source: USER32
Event Category: None
Event ID: 1074
Date: 17-Aug-03
Time: 10:49:09 PM
User: NT AUTHORITY\SYSTEM
Computer: MASTERPIECE
Description:
The process winlogon.exe has initiated the restart of=20
MASTERPIECE for the following reason: No title for this=20
reason could be found
Minor Reason: 0xff
Shutdown Type: reboot
Comment: Windows must now restart because the Remote=20
Procedure Call (RPC) service terminated unexpectedly

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: ff 00 00 00 =FF... =20




Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 17-Aug-03
Time: 10:49:11 PM
User: N/A
Computer: MASTERPIECE
Description:
The Remote Procedure Call (RPC) service terminated=20
unexpectedly. It has done this 1 time(s). The following=20
corrective action will be taken in 60000 milliseconds:=20
Reboot the machine.

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.




Event Type: Information
Event Source: RemoteAccess
Event Category: None
Event ID: 20159
Date: 17-Aug-03
Time: 10:51:30 PM
User: N/A
Computer: MASTERPIECE
Description:
The connection to Vsnl made by user adgeru@nda using=20
device COM4 was disconnected.

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.




Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 17-Aug-03
Time: 10:51:32 PM
User: N/A
Computer: MASTERPIECE
Description:
The Remote Procedure Call (RPC) service entered the=20
running state.

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.



Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 17-Aug-03
Time: 10:51:32 PM
User: N/A
Computer: MASTERPIECE
Description:
The Terminal Services service entered the running state.

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.



Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7035
Date: 17-Aug-03
Time: 10:51:32 PM
User: NT AUTHORITY\SYSTEM
Computer: MASTERPIECE
Description:
The Fast User Switching Compatibility service was=20
successfully sent a start control.

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.




Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 17-Aug-03
Time: 11:38:10 PM
User: N/A
Computer: MASTERPIECE
Description:
The Remote Procedure Call (RPC) service terminated=20
unexpectedly. It has done this 1 time(s). The following=20
corrective action will be taken in 60000 milliseconds:=20
Reboot the machine.

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.




Event Type: Information
Event Source: USER32
Event Category: None
Event ID: 1074
Date: 17-Aug-03
Time: 11:38:09 PM
User: NT AUTHORITY\SYSTEM
Computer: MASTERPIECE
Description:
The process winlogon.exe has initiated the restart of=20
MASTERPIECE for the following reason: No title for this=20
reason could be found
Minor Reason: 0xff
Shutdown Type: reboot
Comment: Windows must now restart because the Remote=20
Procedure Call (RPC) service terminated unexpectedly

For more information, see Help and Support Center at=20
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: ff 00 00 00 =FF... =20




etc......

waiting for early reply.

Yours'
-Anjul.

Ron Lowe
January 9th 04, 09:43 PM
"anjul" > wrote in message
...
hi,
Im sending u the whole system log files....
pls reply me with sollution soon.

<snippage>




You have been infected with the W32/Lovsan worm,
also refered to as the msblast worm, or RPC worm:

http://www.microsoft.com/security/incident/blast.asp


Also, you may want to visit windowsupdate from time to time and
pick up the latest Critical updates. These are often released to plug
any security hole before any malicious code is in the wild which
exploits that hole. This security hole was plugged around a month ago.



--
Best Regards
Ron Lowe
MVP - Windows Networking

Google