How should I fix this?
 




IT Certification FAQ

 
|
Home
|
Microsoft
|
CISCO
|
CompTIA
|
Exam/Study FAQ
|
Employment FAQ
| Links  | Forums  |
Book Reviews


FAQFAQ  SearchSearch  MemberlistMemberlist  UsergroupsUsergroups  RegisterRegister  ProfileProfile  Log in to check your private messagesPrivate messages  Log inLog in

How should I fix this?

 
Post new topic   Reply to topic    Forum Index -> alt.certification.a-plus
Author Message
Kathy
Guest





PostPosted: Sat Aug 02, 2003 10:03 pm    Post subject: How should I fix this? Reply with quote

Hi everyone,

Within the past week my son got this message on his computer about three times so far saying that the computer is shutting down within 40 seconds and to close everything before it shuts down and it was authorized by NT administration, then it goes through and shuts down the computer. I asked him what exactly does it say and that is what he told me that it says. He uses a broadband connection and constantly has the computer on along with his IM program. I am thinking he needs to update his security updates through MS. I don't think he has any firewall program such as Black Ice or anything like that. He used to have it but I don't know why he doesn't have it anymore. The OS he is using is WinXP. Has anyone else had this problem before?

Thanks,
Kathy
A+
Back to top
Rick Blythin
Guest





PostPosted: Sat Aug 02, 2003 11:37 pm    Post subject: Re: How should I fix this? Reply with quote

Quote:
"Kathy" <computermonkeyNOSPAM@inbox.net> wrote in message
news:vinqsebsuij7f2@corp.supernews.com...
Hi everyone,

Within the past week my son got this message on his computer about three
times so far saying that the computer is shutting down within 40 seconds and

to close everything before it shuts >down and it was authorized by NT
administration, then it goes through and shuts down the computer. I asked
him what exactly does it say and that is what he told me that it says. He
uses a >broadband connection and constantly has the computer on along with
his IM program. I am thinking he needs to update his security updates
through MS. I don't think he has any firewall >program such as Black Ice or
anything like that. He used to have it but I don't know why he doesn't have
it anymore. The OS he is using is WinXP. Has anyone else had this problem
before?
Quote:

Thanks,
Kathy
A+

Hi Kathy,

What is the pop-up message he's getting?. The most common pop-ups are spam
using the 'messenger' service it's just a matter of blocking certain ports.
If he's on broadband then he really should have a firewall. The build-in XP
doesn't cut it. I personally switched from ZoneAlarm to Kerio which is very
small and light on resources. But I consider it more of a 'techy' firewall
since you really need to understand TCP/IP & ports and it take more set-up
to run efficient. For the average user Zone Alarm is probably one of the
better ones.

If you could post the message that would help a lot. Also advise him to get
a firewall if he doesn't have one already Z.A has there free version which
does a decent job. You'd be amazed how much traffic trying probing your
computer on broadband!.

Rick
--
A+, Network+
Back to top
Kathy
Guest





PostPosted: Sun Aug 03, 2003 12:53 am    Post subject: Re: How should I fix this? Reply with quote

Hi Rick,

No it's not messenger service pop-ups. I got rid of that for him a while ago
and he hasn't gotten any of those pop-ups since It is an actual windows
pop-up box and the message actually counts down the numbers from 40 to 0, as
for seconds. There is nothing in this box to click either, no OK, no Cancel,
no X to x-out of it, nothing. It just randomly pops-up and actually shuts
the computer down. When this first started I told him to get a firewall
program, but he's a kid and he thinks he knows it all, so what good it was
to tell him. I will keep after him about getting ZA though. I'm sure he'll
get sick of it doing this and maybe come to his senses. I just thought I
would ask about this to make sure I was on the right track about solving the
problem.

Thanks :-)
Kathy
A+

"Rick Blythin" <mosguy@gosympatico.ca> wrote in message
news:yxTWa.1711$Ji1.345156@news20.bellglobal.com...
Quote:
Hi Kathy,

What is the pop-up message he's getting?. The most common pop-ups are
spam
using the 'messenger' service it's just a matter of blocking certain
ports.
If he's on broadband then he really should have a firewall. The build-in
XP
doesn't cut it. I personally switched from ZoneAlarm to Kerio which is
very
small and light on resources. But I consider it more of a 'techy' firewall
since you really need to understand TCP/IP & ports and it take more set-up
to run efficient. For the average user Zone Alarm is probably one of the
better ones.

If you could post the message that would help a lot. Also advise him to
get
a firewall if he doesn't have one already Z.A has there free version which
does a decent job. You'd be amazed how much traffic trying probing your
computer on broadband!.

Rick
--
A+, Network+

Back to top
RussS
Guest





PostPosted: Sun Aug 03, 2003 2:49 am    Post subject: Re: How should I fix this? Reply with quote

Hey Kathy

I think it may be a virus. I do remember hearing something similar late
last year but have not come across it myself.
Rus your sons virus checker and perhaps an anti trojan scanner
http://download.com.com/3000-2239-10191193.html?tag=lst-0-1 and a spyware
scanner http://download.com.com/3000-2144-10194058.html?tag=lst-0-1 .
As some virus actually disable antivirus software when I have something I
can not explain I also go to http://housecall.trendmicro.com/ and run their
free online scan just to check.

I agree with Rick - Kerio is a great firewall and if you are able to set it
up for your son would I think be a safer option than Zonealarm.
http://download.com.com/3000-2092-9032150.html?tag=lst-0-3

I also forgot to mention that there are a couple virus out there that can
disable certain firewalls so it is worthwhile checking if your sons firewall
was uninstalled by him or somehow disabled.


Russ
Back to top
Jed
Guest





PostPosted: Sun Aug 03, 2003 1:15 pm    Post subject: Re: How should I fix this? Reply with quote

"Kathy" <computermonkeyNOSPAM@inbox.net> wrote in
news:vio4u9cqg2v38a@corp.supernews.com:

Quote:
...It is an
actual windows pop-up box and the message actually counts down the
numbers from 40 to 0, as for seconds. There is nothing in this box to
click either, no OK, no Cancel, no X to x-out of it, nothing. It just
randomly pops-up and actually shuts the computer down. When this first
started I told him to get a firewall program, but he's a kid and he
thinks he knows it all, so what good it was to tell him. I will keep
after him about getting ZA though. I'm sure he'll get sick of it doing
this and maybe come to his senses. I just thought I would ask about
this to make sure I was on the right track about solving the problem.

Thanks :-)
Kathy
A+

Hi Kathy,


It sounds like the XP commandline shutdown command has been issued. The
next time this happens go to the command line and type in shutdown -a.
This will abort the shutdown sequence. The dialog box you are seeing is
activated when the shutdown command is given on the command line. Your
son's system may be compromised. After you abort the process you may
want to examine the system event logs to see if you can determine when
the command was issued and by what application or user and for what
reason. You son's system may have a back door application running. With
all the stuff that is going on out here in the digital wild's it's
probably going to be a good worm hunt for you.

Let me know how it works out.

Jed
Back to top
Barry Watzman
Guest





PostPosted: Mon Aug 04, 2003 7:26 pm    Post subject: Re: How should I fix this? Reply with quote

If he has a broadband connection, he should be operating behind a
router, even if he is not sharing the connection. A broadband
connection directly to a PC is, in my view, almost irresponsibly unsafe.

At this point, there is a chance that his computer has become
"possessed" by virus or virus-like agent. The first things that I would
do are run a virus scan using updated virus software and get a router if
there is not one installed. I'd use a router rather than a firewall
"program"; the software approaches can be effective, but they can be
difficult to setup and can cause more problems than they solve, while a
$29.95 router will provide the necessary protection with no or minimal
configuration or impact on other functions.


Kathy wrote:

Quote:
Hi everyone,

Within the past week my son got this message on his computer about three
times so far saying that the computer is shutting down within 40 seconds
and to close everything before it shuts down and it was authorized by NT
administration, then it goes through and shuts down the computer. I
asked him what exactly does it say and that is what he told me that it
says. He uses a broadband connection and constantly has the computer on
along with his IM program. I am thinking he needs to update his security
updates through MS. I don't think he has any firewall program such as
Black Ice or anything like that. He used to have it but I don't know why
he doesn't have it anymore. The OS he is using is WinXP. Has anyone else
had this problem before?

Thanks,
Kathy
A+
Back to top
Navin R. Johnson
Guest





PostPosted: Mon Aug 04, 2003 8:52 pm    Post subject: Re: How should I fix this? Reply with quote

On Sat, 2 Aug 2003 13:03:01 -0400, "Kathy"
<computermonkeyNOSPAM@inbox.net> wrote:

Quote:
Hi everyone,

Within the past week my son got this message on his computer about three times so far saying that the computer is shutting down within 40 seconds and to close everything before it shuts down and it was authorized by NT administration, then it goes through and shuts down the computer. I asked him what exactly does it say and that is what he told me that it says. He uses a broadband connection and constantly has the computer on along with his IM program. I am thinking he needs to update his security updates through MS. I don't think he has any firewall program such as Black Ice or anything like that. He used to have it but I don't know why he doesn't have it anymore. The OS he is using is WinXP. Has anyone else had this problem before?

Thanks,
Kathy
A+

This couldn't be coming from some CPU temp or fan speed monitoring
software could it? Maybe it's trying to tell you something is getting
hot?? Try getting rid of all the startup progs with msconfig. Also, some
CD burning programs have a checkbox that says 'shut down the computer
when finished' or something to that effect. Other than that I'd scan for
viruses and/or trojans. Maybe someone opened a back door from the TCP
connection. Good luck.

NRJ





"Very funny Scotty..... Now beam down my clothes!"
Back to top
Kathy
Guest





PostPosted: Tue Aug 12, 2003 12:49 am    Post subject: Re: How should I fix this? Reply with quote

Hey Guys,

Problem solved :-) he finally came to his senses and asked me for help...I
guess he was getting sick of it. First I ran the av scanner....found
nothing. Then for the heck of it, I downloaded the security updates from
microsoft and after that he didn't get these windows boxes anymore. Actually
I didn't think the security updates would fix the problem, but I was amazed
that it did. I let it go for a few more days to see what would happen and so
far he hasn't gotten these boxes...it was 5 days since he got them. So
yesterday I downloaded ZA for him...he didn't especially like it too well
that I did this, but "Oh well"....anyway, I had to do something because he
wasn't doing nothing about his broadband connection being wide open. Yes we
also did talk about a router and we will eventually get one.

Thanks again
Have a great day :-)

Kathy
A+

"Navin R. Johnson" <TheJerk@optigrab.net> wrote in message
news:6pvsiv0bh6rn0891c3o6mps7d11fesf7j3@4ax.com...
Quote:
On Sat, 2 Aug 2003 13:03:01 -0400, "Kathy"
computermonkeyNOSPAM@inbox.net> wrote:

Hi everyone,

Within the past week my son got this message on his computer about three
times so far saying that the computer is shutting down within 40 seconds and

to close everything before it shuts down and it was authorized by NT
administration, then it goes through and shuts down the computer. I asked
him what exactly does it say and that is what he told me that it says. He
uses a broadband connection and constantly has the computer on along with
his IM program. I am thinking he needs to update his security updates
through MS. I don't think he has any firewall program such as Black Ice or
anything like that. He used to have it but I don't know why he doesn't have
it anymore. The OS he is using is WinXP. Has anyone else had this problem
before?
Quote:

Thanks,
Kathy
A+

This couldn't be coming from some CPU temp or fan speed monitoring
software could it? Maybe it's trying to tell you something is getting
hot?? Try getting rid of all the startup progs with msconfig. Also, some
CD burning programs have a checkbox that says 'shut down the computer
when finished' or something to that effect. Other than that I'd scan for
viruses and/or trojans. Maybe someone opened a back door from the TCP
connection. Good luck.

NRJ





"Very funny Scotty..... Now beam down my clothes!"
Back to top
Augie
Guest





PostPosted: Fri Aug 15, 2003 10:16 pm    Post subject: Re: How should I fix this? Reply with quote

It could be a violation of the RPC. Look out............
"Kathy" <computermonkeyNOSPAM@inbox.net> wrote in message news:vinqsebsuij7f2@corp.supernews.com...
Hi everyone,

Within the past week my son got this message on his computer about three times so far saying that the computer is shutting down within 40 seconds and to close everything before it shuts down and it was authorized by NT administration, then it goes through and shuts down the computer. I asked him what exactly does it say and that is what he told me that it says. He uses a broadband connection and constantly has the computer on along with his IM program. I am thinking he needs to update his security updates through MS. I don't think he has any firewall program such as Black Ice or anything like that. He used to have it but I don't know why he doesn't have it anymore. The OS he is using is WinXP. Has anyone else had this problem before?

Thanks,
Kathy
A+
Back to top
Kathy
Guest





PostPosted: Fri Aug 15, 2003 11:53 pm    Post subject: Re: How should I fix this? Reply with quote

I actually think it was that worm he had gotten. The one they made a big deal about on the news the other night because it's strange that it stopped after I downloaded the updates from microsoft.

Cheers,
Kathy
A+
"Augie" <nav@rocketmail.com> wrote in message news:bhj4ju$4tck$1@ID-155382.news.uni-berlin.de...
It could be a violation of the RPC. Look out............
Back to top
Ghost
Guest





PostPosted: Sat Aug 16, 2003 4:53 am    Post subject: Re: How should I fix this? Reply with quote

In article <bhj4ju$4tck$1@ID-155382.news.uni-berlin.de>, "Augie"
<nav@rocketmail.com> wrote:

Quote:
This is a multi-part message in MIME format.

------=_NextPart_000_0050_01C36361.CAA6EA60
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

It could be a violation of the RPC. Look out............
"Kathy" <computermonkeyNOSPAM@inbox.net> wrote in message =
news:vinqsebsuij7f2@corp.supernews.com...
Hi everyone,

Within the past week my son got this message on his computer about =
three times so far saying that the computer is shutting down within 40 =
seconds and to close everything before it shuts down and it was =
authorized by NT administration, then it goes through and shuts down the =
computer. I asked him what exactly does it say and that is what he told =
me that it says. He uses a broadband connection and constantly has the =
computer on along with his IM program. I am thinking he needs to update =
his security updates through MS. I don't think he has any firewall =
program such as Black Ice or anything like that. He used to have it but =
I don't know why he doesn't have it anymore. The OS he is using is =
WinXP. Has anyone else had this problem before?

Thanks,
Kathy
A+



Sounds like the Blaster worm to me...
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Forum Index -> alt.certification.a-plus All times are GMT
Page 1 of 1

 

Copyright © 2002-2006 Web-S-Sense Pty. Ltd. All rights reserved.

Powered by phpBB
Advertising | Policies/Disclaimers | Contact us | Link to us


Featured Sites: Free Antivirus and Antispyware Info | Free PC Support | MCSE Directory