A Digital Age Deserves A Digital Leader

Windows DCOM RPC Vulnerability Exploit Proliferating

Postby *Starz* » Tue Aug 12, 2003 6:11 am

Thanks Weaver...printing out your instructions...just because... :thumbs:
[align=center]Image

~ You Are Never Given A Wish Without Being Given The Power To Make It Come True ~[/align]
PRO Level 16
User avatar
Posts: 1893
Joined: Sat Aug 17, 2002 1:05 am
Location: Great Smoky Mountains

Postby Mac33 » Tue Aug 12, 2003 9:40 am

Thanks Weaver for coming back to us on this one. Greatly appreciated, and i hope everything is now back in order at your workplace.
all the best :yesnod:
PROfessional Member
User avatar
Posts: 4910
Joined: Tue Mar 12, 2002 4:55 pm
Location: Scotland

Postby Empath » Tue Aug 12, 2003 1:08 pm

I tried to update using Windowsupdate, but for some strange reason it keeps looping back to the 'update now' screen.
I tried to use the security patch, but the program wouldn't let me install it, saying something about vertifying the integrity of the Update.inf file....
I tried using that worm remover from Symatec, scanned the computer, says no worms detected, turn off firewall, restart warning pops up again.

Ack... does that mean I have to leave the firewall on forever?

(Note, I've deleted the registry file and the msblast.exe... does it keep reinfecting systems everytime I go onto the internet?)
PRO New Member
Posts: 9
Joined: Tue Apr 29, 2003 10:32 am
Location: Happy Valley

Postby BitTorrent » Tue Aug 12, 2003 1:08 pm

Myself and two friends all got hit with this worm last night. i downloaded the tool from Symantec to clean it.. the tool also automatically redirected me to M$'s site to download the critical patch, and all is fine now! here is the link to download the tool from symantec:

http://securityresponse.symantec.com/av ... .tool.html

W32.Blaster.Worm Removal Tool
Discovered on: August 11, 2003
Last Updated on: August 11, 2003 08:01:58 PM PDT

Symantec Security Response has developed a removal tool to clean the W32.Blaster.Worm infections.

What the tool does

The W32.Blaster.Worm Removal Tool does the following:

Terminates the W32.Blaster.Worm viral processes.
Deletes the W32.Blaster.Worm files.
Deletes the dropped files.
Deletes the registry values that the worm added.
PRO Level 2
User avatar
Posts: 35
Joined: Tue Jun 24, 2003 11:49 pm
Location: Northeast USA

Postby *Starz* » Tue Aug 12, 2003 3:55 pm

This one seems to be getting around...thanks for the information Bit Torrent... :thumbs:
[align=center]Image

~ You Are Never Given A Wish Without Being Given The Power To Make It Come True ~[/align]
PRO Level 16
User avatar
Posts: 1893
Joined: Sat Aug 17, 2002 1:05 am
Location: Great Smoky Mountains

Postby Weaver » Tue Aug 12, 2003 4:19 pm

does it keep reinfecting systems everytime I go onto the internet?


Not to sound like a smartass, but yes, that is what worms are designed to do. If you use the Symantec tool without patching the Windows vulnerability then yes you can and probably will get infected again. Updating virus definitions will also help.

-Weaver
Public Keys

The primary purpose of the DATA statement is to give names to constants; instead of referring to pi as 3.141592653589793 at every appearance, the variable PI can be given that value with a DATA statement and used instead of the longer form of the constant. This also simplifies modifying the program, should the value of pi change.
-- FORTRAN manual for Xerox Computers
PROfessional Member
User avatar
Posts: 1967
Joined: Wed Jun 19, 2002 12:05 am
Location: /home/weaver/

Postby SCJwl » Tue Aug 12, 2003 5:14 pm

I had this mother yesterday. I know it did. Sucker kept on rebooting and shutting down anything I was doing. And then telling me it was going to reboot in 60 seconds. I was so irritated. I couldn't even stay online after I posted a PM to Johnny so I trashed the OS and started fresh. What a pain.
I believe that imagination is stronger than knowledge - myth is more potent than history - dreams are more powerful than facts - hope always triumphs over experience - laughter is the cure for grief - love is stronger than death
Robert Fulghum


Image
PROfessional Member
User avatar
Posts: 707
Joined: Mon Mar 11, 2002 4:45 pm
Location: South Carolina

Postby Weaver » Tue Aug 12, 2003 6:44 pm

so I trashed the OS and started fresh


That's one way to handle it.

-Weaver
Public Keys

The primary purpose of the DATA statement is to give names to constants; instead of referring to pi as 3.141592653589793 at every appearance, the variable PI can be given that value with a DATA statement and used instead of the longer form of the constant. This also simplifies modifying the program, should the value of pi change.
-- FORTRAN manual for Xerox Computers
PROfessional Member
User avatar
Posts: 1967
Joined: Wed Jun 19, 2002 12:05 am
Location: /home/weaver/

Postby SCgone » Wed Aug 13, 2003 2:16 am

Weaver wrote:
so I trashed the OS and started fresh


That's one way to handle it.

-Weaver


She tends to do that a lot.
Last edited by SCgone on Wed Aug 13, 2003 10:46 pm, edited 1 time in total.
PRO PLATINUM
Posts: 6879
Joined: Thu Mar 14, 2002 11:59 pm
Location: South Carolina, USA

Postby Empath » Wed Aug 13, 2003 7:31 am

Weaver wrote:
Not to sound like a smartass, but yes, that is what worms are designed to do. If you use the Symantec tool without patching the Windows vulnerability then yes you can and probably will get infected again. Updating virus definitions will also help.

-Weaver


Ack... I can't download the patch from the Windows Update website for some strange reason... the 'Update Now' page keeps looping and looping whenever I press the button. Are there any alternative sites to the patch?
PRO New Member
Posts: 9
Joined: Tue Apr 29, 2003 10:32 am
Location: Happy Valley

PreviousNext

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 3 guests

cron
cron