Terminated RPC Process. Can't boot PC now

By ImmortalFreak
Oct 28, 2008
  1. So today I was on my computer and I randomly started hearing random audio. I was looking through the processes and when I went to delete what I thought it was, I clicked the wrong thing not knowing and terminated it.

    It then told me my computer was shutting down in "X" seconds, and it counted down. I then deleted the Iexplore process the problem was, but was unable to do anything about the restart.

    My computer restarted and now I get this - "STOP: c0000218 unknown hard error" right when I get to where I would normally log in.

    Now, I can get into safe mode, but I can't get into regular mode. When I checked my event manager, it said winlogon.exe has initiated the restart and there was no title... It said it was a minor error 0xff, and the comments were that it restarted becuase the Remote Procedure Call (RPC) service was unexpectedly terminated.

    Any suggestions?
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Find the Error(s)in the Event Viewer that correspond to the crash:

    Start> Run> cmd> type in eventvwr

    Description of the Event Viewer:
    Do this on each the System and the Applications logs:
    Click to open the log> look for the Error> right click on the Error> Properties> Click on Copy button, top right, below the down arrow and Paste here (Ctrl V)

    You can ignore the Categories 1 and 2. If you have a recurring Error with same ID#, same Source and same Description, only one copy is needed. You don't need to include the lines of code in the box below the Description, if any.

    Please do not copy the entire Event log. Only the corresponding Errors. The RPC Service is one that needs to be set to Automatic. Other Services depend on it to run, so let's check that:
    Start> Run> services.msc> find RPC (Remote Procedure Call) and right click> Properties> set Startup type to Automatic> Start the Service. If you click on the Dependencies tab, you will note all the other Services that depend on RPC to run.

    NOTE: you will see several 'Remote' words. When you do the right click, you will see the full name. You don't want the RPC Locator (the is set to Manual)- you want just the RPC.
  3. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    Thanks for the reply!

    The stuff I posted was not an error, it was "Information" from the event viewer.

    I was unable to find any errors that would correspond with this crash. There was an error regarding AVG Watch Dog, but I highly doubt that was it. :)

    However, I will double check that when I get home today, I'll be back aroudn by 2:30 PST.

    I really appreciate your help.
  4. almcneil

    almcneil TS Guru Posts: 1,277

    Restart in Safe Mode and disable your audio device. Then restart in Normal Mode and see if you reach the Dessktop.

    I think you messed up something to do with your audio device accidentally. Or it may be a Windows service that is not being started or corrupted.

    Repost with results pls.

    -- Andy
  5. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    As you now realize, Information Events go on all the time, are 'normal' and are not investigated for problems.

    doesn't give us anything to work with.

    Check the RPC Service, make sure of the setting as advised. It is possible that a system Restore to date right before you tried to solve the sound problem might also work.
  6. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    I have had System Restore off. =\ And I the Remote Procedure Call (RPC) was already Started and set to automatic.

    But anyway, you were right, there're quite a few of the exact same errors. All starting last night after it happened.

    System errors:
    **I’ve gotten 12+ errors containing this same ID.
    Event Type: Error
    Event Source: Service Control Manager
    Event Category: None
    Event ID: 7001
    Date: 10/27/2008
    Time: 9:24:26 PM
    User: N/A
    Computer: SPECTER
    The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
    A device attached to the system is not functioning.

    **This is likely irrelevant, but I figured I’d include it just incase.

    Event Type: Error
    Event Source: DCOM
    Event Category: None
    Event ID: 10005
    Date: 10/27/2008
    Time: 9:05:17 PM
    Computer: SPECTER
    DCOM got error "This service cannot be started in Safe Mode " attempting to start the service EventSystem with arguments "" in order to run the server:

    Application errors:
    Event Type: Error
    Event Source: EventSystem
    Event Category: (50)
    Event ID: 4609
    Date: 10/27/2008
    Time: 7:40:26 PM
    User: N/A
    Computer: SPECTER
    The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070005 from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

    Event Type: Error
    Event Source: VSS
    Event Category: None
    Event ID: 8193
    Date: 10/27/2008
    Time: 7:40:26 PM
    User: N/A
    Computer: SPECTER
    Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.

    Application warnings:
    Event Type: Warning
    Event Source: Userenv
    Event Category: None
    Event ID: 1517
    Date: 10/27/2008
    Time: 7:41:51 PM
    Computer: SPECTER
    Windows saved user SPECTER registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.

    This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

    Thanks in advance, guys!

    By the way, I disabled my audio device and that didn't work.
  7. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    As alarming as it was to see all those Errors, here's the breakdown:

    Time: 7:40:26 PM- 2 Also indicate you were in Safe Mode.
    Time: 9:05:17 PM and 9:24:26 PM indicate that your were in Safe Mode at the time. So these are negligible as they don't start in Safe Mode and are therefore not an 'error'.
    This isn't good news. I believe you are experiencing what is called a Trojan.Shutdown. This is actually a virus. This threat copies its file(s) to your hard disk. Its typical file name is Trojan.Shutdown. Then it creates new startup key with name Trojan.Shutdown and value (?). You can also find it in your processes list with name (?) or Trojan.Shutdown. This is also referred to as '(fake Shutdown Virus) -

    Malwarebytes combined with SuperAntispyware will remove this malware. Can you download the programs to a flash drive and run them from there on your system? You will find directions for both programs in Step 4 and 4 here:

    It will also be helpful if you follow these two programs with HijackThis in Step 7, then attach all three logs

    I must admit that this is the first time I have I've been in on what are the obvious symptoms of this malware. I usually see it on the other end- in the logs when it's removed. But putting together the 60 second countdown along with your inability to boot into Normal Mode, it paints the picture describing this infection. If you can get the program on a flash drive and run them, we should be able to clean the malware out and get you running full speed!
  8. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    And you know what... Just the day before I found a Trojan on my computer... That's why I went into Task Manager and started ending processes, because I saw no programs open, yet I was hearing this random audio.

    Good news, though. I have the first two programs already on my computer, I don't have the Hijack one, though. I'm starting my scans right now, I'll report back here.

    Man, this seems pretty coincidental, huh? I end a task and it makes me think it was me, but really a virus, haha.
  9. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    Attached are all three logs.

  10. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Good job! We have a better handle on it now:
    Mbam found and removed a Registry key with antispywarexp2009.
    SAS shows just about every Tracking Cookie available. Have SAS remove all.
    You need to reset the Cookies:
    Please re-open HiJackThis and scan.*Check* the boxes next to all the entries listed below:

    The really bad guys:
    Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis and reboot back into Safe Mode:

    Start> Run> type in ''msconfig' without the quotes> Selective Start-up> Startup tab> UNCHECK everything EXCEPT antivirus and firewall> Apply> OK.

    Start> Run> services.msc> find both Adobe Services and on each: right click> Properties> change Start up Type to Disabled.

    Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):
    (there may be more when you can run in Normal Mode and show programs)
    If you can, reboot into Normal Mode- you will get a nag message which you can close after checking 'don't show this message again'. Stay in Selective Startup.

    Scan with HijackThis again and attach the new log.
  11. almcneil

    almcneil TS Guru Posts: 1,277

    BINGO!! You've Been Hit by Spyware!!


    I recognize this. It's actually a spyware program that tries to install a music player on your computer (illicitedly) but messes it up. I've had two customers in the past who had this spyware infection.

    I recommend running the following 3 anti-spyware utilities (click on the name to get the download page at this site):

    Once you're done, repost with results and we'll proceed from there if necessary.

    -- Andy
  12. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    Good deal, I will go through all of those steps when I get home from school today.

    I have all three of the programs mentioned in the previous post, and I will run them while I'm gone.

    Thanks guys!
  13. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    Just did the hijack this fix, and the Spybot scan has been completed. AVG is in progress. Spybot foudn and fixed "MediaPlex" and it also found "Excite" but that's just one of my emails.

    Regarding AdAware and the Java/Adobe update, the computer is not recognizing my flash drive... It's not the drive, as it works on other computers, it just seems to be that one. I'm gonna restart after the AVG scan is done and check it then.

    About the antiWPA thing, when I bought the computer it had the illegal copy. I bought it for a friend for dirt cheap, so I can't necessarily say "Hey, buy the windows copy for the computer"... My brother gets them from his work for fairly cheap, so when he gets back from Texas we're going to get a copy for the computer here, maybe even Vista.

    That said, I removed all the stuff but that antiWPA thing with Hijackthis.
  14. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    Scans are done, I cannot remove Java or Adobe because "The windows installer service could not be accessed. Could also be safe mode, or the installer service is not installed correctly" Something to that effect.

    As far as Dial33 and DAEMON, those aren't listed. That said, I'm going to reboot.

    About the "Uncheck everything but AntiVirus & Firewall", I'm assuming that didn't mean critical things like the RPC and stuff, right?

    Anyways, I did all that stuff, tried restarting into regular, and it was a no go.. Same thing.

    Youguys sure it's a virus? It happened as I deleted the task, I don't remember which it was, though. =\ But after that the audio turned off when I deleted "iexplore something". So it was a hidden internet popup, or something. You know way more than me, but I figured it would be as simple as restarting the process I ended.
  15. almcneil

    almcneil TS Guru Posts: 1,277

    At this point, the malwayre (virus and.or spyware) is probably gone. What's left the corruption from it or the removal of it. I'd perform a Windows repair. Do you have the Windows installation CD for your computer?

    -- Andy
  16. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    I don't have one, but I can get one.

    Does the Windows Repair have to do with the Recovery Console? Because I can run that without the CD, apparently.
  17. almcneil

    almcneil TS Guru Posts: 1,277

    No, the Windows repair is a feature within the Windows installation CD. Recovery Console is also a feature within the Windows installation CD but can be obtained separately.

    What CD do you have?

    Make sure you get a copy of the Windows installation CD that MATCHES the Windows version you have.

    -- Andy
  18. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    I just called someone and they're going to bring it with them when they come over today... I personally have no CD yet.

    So when I get the CD, run the repair, and everything should be okay, or?
  19. almcneil

    almcneil TS Guru Posts: 1,277

    What the Windows repair does is check that the Windows system directory is correct and up to date. It checks for any files that are missing or corrupt and replaces it with the one from the CD. It also makes sure all the software pointers to the system files are up to date. Windows repair does not touch your personal files, programs or settings.

    If this is a system corruption problem, it's highly likely Windows repair nca fix it. Sometimes it doesnt. You just have to try it and see if it works. You have little to lose by trying it since you can't boot to Normal Mode anyway.

    -- Andy
  20. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    True that. Alright bro, the CD should be here in the next hour. I'll run it as soon as it gets here. Thanks a tun for all your help!
  21. almcneil

    almcneil TS Guru Posts: 1,277

    I won't be around at that time as I have a customer call. But either look up the Windows repair guide at this site or have someone else here help you.

    -- Andy
  22. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Andy, I've said this before and I will say it again- please do not come in in the middle of a malware cleaning process and suggest your 3 different programs. I have already begun with this and once again, you have interrupted. Our cleaning processes is structured as it is because it works well that way. And once it has begun and is in progress, your interruptions disturb that process and confuse the user as he now has to try and deal with 3 different programs.

    Yes, this is an open board. But that does not mean interrupting a work in process to send a user off in a different direction. This has gotten so bad, I have brought it to the attention of the moderators- again.

    The programs you are suggesting are good spyware/adware programs. But they are not for deep cleaning- rather for running on the systems regularly. Once malware access a system- especially when it's multiple infections, these programs are usually not sufficient to remove all of them.
  23. ImmortalFreak

    ImmortalFreak TS Rookie Topic Starter Posts: 17

    I'm sorry, I didn't mean to mess anything up by taking multiple sets of advice. I thought youguys were a team, hehe.

    On a side note, I did the repair and now I get a different error loading into regular mode. My brother had me go ahead and start the reinstall and see if that did anything, because after the repair I couldn't even access safemode. He said I'd just have to blow off my computer if all went well and I was able to get in to regular mode, or live with the cracked out settings. He said if not that, it's more than likely a hardware issue.

    But about the new error I get: Well, I went over to the other computer and now I can't even get that far, hehe.

    It's looping, it goes to the setup to install windows, and then I get this error:
    Sxs.dll:Syntax error in manifest of policy file D:\1386\asms\10\msft\windows\gdiplus\" on line 4

    Install failed D:\l386\ASMS (Data Error) Cyclic Redundancy Check

    Fatal Error:
    one of the components windows needs to continue the setup couldn't be installed (Data Error) Cyclic Redundancy Check

    It repeats the exact or very close to those same 3 errors several times in the log.

    So I exit the setup, reboot the PC and it loops right back to the "Installing Windows" step of the setup. If I boot in safemode it says it cannot continue setup in safe mode and then loops me back there.
  24. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    Teamwork is often seen on computer boards- the reason? We are not all of the same expertise and knowledge.However, when someone comes in to the middle of a malware cleaning thread and points a user to different programs to run, it is not teamwork and it causes confusion for the user.

    Since I did not advise the Windows repair, I am going to have to leave you with the person who did and hope he can get you out of the mess he caused.

    IF this does not get solved, please start a new thread, with reference to this thread, and we'll try to take it from the top again,. hopefully without interference.

    FYI: Re the syntax error: XP Upgrade Install problem - sxs.dll syntax error in manifest.
    Possible causes:
    1. a bad windows CD,or a bad CD-ROM drive !
    2. some sort of hardware issue.
    3. It appears that there's an issue with the dll recognizing your networking software. Is this a genuine Microsoft CD, a manufacturer's CD, or one that you got from someone else?
    4. the download or copying to a CD was corrupted

    From Bleeping Computer:
    Some suggestions from a google search for a part of the error message:
    Please note that some of the links refer to other filenames in the error message, so the fix will also reflect the error message.

    Probably the best link for real technical info:

    All of this having been said, I still suspect a faulty CD - and the fix is to try other CD's.
  25. momok

    momok TS Rookie Posts: 2,265

    Are you able to boot normally without the CD? What kind of errors, if any, do you face? Please list them out specifically and we'll see what we can do to help.
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...