|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: Feb 2003
Posts: 2,192
|
please help I have a very bad virus on my computer
Hi guys I dont know how the hell this happened but today at random times I get this small windows message that says:
---------------------------------------------- this system is shutting down. please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY\SYSTEM will be shut down in : 0:59 ... 0:59....0:00 message: windows must now restart because the remote procedure called (rpc) service terminated unexpectedly ------------------------------------------------ How do I fix this? I have never seen something like this before. how could this have happened? I have AVG and it found a virus but i could not heal or delete ormove to vault. this was befoe this happened so I dont exactly remember the name but the 2nd virus was patch.exe |
|
|
|
|
|
#2 |
|
Confirmed User
Join Date: Feb 2003
Posts: 2,192
|
it is happenign righ now! SHIT!!! =(((
|
|
|
|
|
|
#3 |
|
Confirmed User
Join Date: Feb 2003
Posts: 2,192
|
Iam running XP. can someone help me please?
|
|
|
|
|
|
#4 | |
|
Confirmed User
Join Date: Apr 2002
Location: Los Angeles
Posts: 6,102
|
Quote:
http://f-prot.com/ Download F-Prot. Copy the free DOS version into your boot disk. Boot with the disk and run f-prot. This program kills all viruses. |
|
|
|
|
|
|
#5 |
|
Confirmed User
Industry Role:
Join Date: Jan 2001
Location: Outback of bumfuck Aussie
Posts: 5,761
|
__________________
Buy great domains from drunken burned out old webmaster CHEAP bullseyeporn.com art-met.com and more. Learn how to make a easy extra $500 per week |
|
|
|
|
|
#6 | |
|
Confirmed User
Join Date: Feb 2003
Posts: 2,192
|
Quote:
damn =( how can I fix this file? |
|
|
|
|
|
|
#7 |
|
Registered User
Join Date: Aug 2003
Posts: 2
|
It means that the virus/worm was executed/run with a LocalSystem account. This would be true for a network-aware virus like FunLove and Bugbear. These viruses connect to open shares anonymously, therefore the default rights provided by the OS would be a LocalSystem account unless specified otherwise on the share.
you need to have a personal firewall on your pc. All share folders must be password protected and if you are using imesh or on of those do not share files. Lock the shared folder with a password. since it is the NT Authority/system account this is a internal account and the system does change its passwords regularly for security purposes. You would not see this account in user manager just like you don't see the group everyone. You, of course, have Zone Alarm or other personal firewall installed and antivirus installed so you have nothing to worry about. If not you need to get on of these like right now! someone must have been poking around on your network... do you have a terminal service installed? it can be done by a DOS worm, if it is a DOS worm if it occured simultaneously on a group of networked computers open the task manager and end processes like csrss.exe, snmp.exesvchodt, svchost.exe if you can end these it is not a worm or virus in the DOS system. in order for it not to gain entry the second time, also check out your terminal services like VNC... remote desktop, pc anywhere... someone might be playing with you... also you can download a trojan cleaner, if you accidentally downloaded a back orifice or any trojan virus which gives out access hope some of this helps!! |
|
|
|
|
|
#8 |
|
Confirmed User
Join Date: Feb 2003
Posts: 2,192
|
Hi I did a system restore to go back 3 days ago and it seems to be ok now. I also scanned with my virus scanner again and it found a trojan horse backdoor-net bus virus =( It healed the virus but whoever did this had access to all of my files right ///
I want to install a firewall but the damn thing thinks everything is a threat to the computer. I dont know which file to block with it and which to allow. |
|
|
|
|
|
#9 | |
|
So Fucking Banned
Join Date: Sep 2001
Location: shell beach
Posts: 7,938
|
Quote:
... but if you wanna use an idiot proove firewall, you better use sygate ... I am a fulltime idiot myself and had no problems with it. |
|
|
|
|
|
|
#10 | |
|
Confirmed User
Join Date: Jul 2002
Location: Magrathea
Posts: 6,493
|
Quote:
SpaceAce |
|
|
|
|
|
|
#11 | |
|
Registered User
Join Date: Feb 2003
Posts: 489
|
Quote:
|
|
|
|
|
|
|
#12 |
|
Registered User
Join Date: Feb 2003
Posts: 489
|
can anybody help>? wtf is going on/
|
|
|
|
|
|
#13 | |
|
Confirmed User
Join Date: Feb 2003
Posts: 2,192
|
Quote:
The virus is : trojan horse backdoor. netbus |
|
|
|
|
|
|
#14 |
|
Jesus loves bacon
Industry Role:
Join Date: Feb 2001
Location: Sin City, Motherfucker
Posts: 19,969
|
netbus is still around?
__________________
Support my new movie “The Second Coming” |
|
|
|
|
|
#15 |
|
Confirmed User
Join Date: Jul 2001
Location: See sig
Posts: 6,989
|
format c:
(someone had to |
|
|
|
|
|
#16 |
|
Confirmed User
Join Date: Sep 2002
Location: Oakville, Canada
Posts: 9,134
|
__________________
Free agent |
|
|
|