University of Wisconsin Help Desk Knowledgebase


 ADVANCED

Windows - Remote Procedure Call Service Terminated


This document explains how to troubleshoot problems with the Remote Procedure Call in Windows.

SYMPTOM

Shortly after booting into windows you receive the following error:
This system is shutting down. Please save all work in progress and log off. Any unsaved changes will be lost. This shutdown was initiated by NT Authority/system.

Message: Windows must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly.

CAUSE

This error message is due to a buffer overrun vulnerability on Windows NT 4.0, 2000, XP, and Server 2003. The RPC service that runs on these systems does not properly check message inputs under certain circumstances. For more detailed information regarding this vulnerability see Microsoft Security Bulletin MS03-010.

Note: If an attacker is able to successfully exploit this vulnerability they could gain complete control over a remote computer. This would give the attacker the ability to take any action on the system that they want. For example, an attacker could change web pages, reformat the hard disk, and / or add new users to the local administrators group.

SOLUTION

To resolve this issue in Windows 2000 and XP you will need to perform the following steps:

Things to consider:
Information adapted from Microsoft and Symantec Antivirus Research Center (SARC).



Keywords: windows 2000 xp nt rpc vulnerability service terminated blaster worm removal unexpectedly windows restart pack remote procedure callDoc ID: 2048
Owner: Brian H.Group: Help Desk
Created: 2003-06-06Updated: 2009-08-04

Did this document help you to answer your question?