Nasty Worm going around

Monday, August 11, 2003 by Frogboy | Discussion: WinCustomize News

This hasn't shown up on any news sites yet that I know of but there is a really nasty worm going around the net that uses an exploit in RPC on XP. Make sure you have the latest updates to Windows XP installed or you will get zapped by this at some point.


It will cause a crash in RPC which will force your machine to reboot 60 seconds later (With a count down). It's a PITA to remove too once you get it.

First Previous Page 1 of 3 Next Last
crissy14
Reply #1 Monday, August 11, 2003 6:02 PM
At the risk of sounding stupid.......What does RCP stand for?
kthxbye
Reply #2 Monday, August 11, 2003 6:19 PM
RPC: Remote Procedure Call.

In a nutshell, it (the RPC service,) is one of the critical services of Windows NT. ^.^
yrag2
Reply #3 Monday, August 11, 2003 6:25 PM
https://grc.com/x/portprobe=135 is a direct link to test if your port 135 is open or closed. Open is bad....closed or stealth is good.
BasketWeaver
Reply #4 Monday, August 11, 2003 6:27 PM
Thank you!
Pooya1770
Reply #5 Monday, August 11, 2003 6:37 PM
ok even i have this bug now .. i wish i knew how 2 get rid of it .. its very very annoying .. i hope none of u get it ..
[email protected]
Reply #6 Monday, August 11, 2003 6:43 PM

Use REGEDIT.EXE and wipe out the value referencing MSBLAST.EXE at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.


Reboot. \windows\system32\msblast.exe (location may vary slightly depending on OS) should now no longer be running. Get rid of it.


Use WindowsUpdate to make sure you're patched or grab it by following the links for your OS from here: http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS03-026.asp

Xerraire
Reply #7 Monday, August 11, 2003 6:53 PM
here is a direct link to the update
http://microsoft.com/downloads/details.aspx?FamilyId=2354406C-C5B6-44AC-9532-3DE40F69C074&displaylang=en

Thanks so much for telling us about this!

Barb
Sugaree
Reply #8 Monday, August 11, 2003 6:59 PM
Grrrrrrrr I got it and I never get anything

O well all better now
RadialFX
Reply #9 Monday, August 11, 2003 7:21 PM
Seems no matter what I do, the link above still reports that port 135 is "Open". I've applied the patch, changed the registry entry for DCOM service, even used DCOM config to disable and it still says...."OPEN". Am I suffering from another bout of "headuperectus" or just is it just full-blown Dumass Inc.?
Millicona
Reply #10 Monday, August 11, 2003 7:24 PM
i think it piggybacks on windows update
paulbrittgarcia
Reply #11 Monday, August 11, 2003 7:31 PM
I got it too!

>
antu^jamban
Reply #12 Monday, August 11, 2003 7:40 PM
thanx for the infos... nasty worms. checked my port. its stealth yay . ehmm i guess my system is protected. even tho my 135 port is stealth (according to the grc test),i would still like to know how to close it..
crissy14
Reply #13 Monday, August 11, 2003 7:44 PM
Cool! my port is closed! (gee, that sounds a little nasty) But, it doesnt surprise me. We have two puters networked here and we have them as tight as a drum
crissy14
Reply #14 Monday, August 11, 2003 7:46 PM
kthxbye
thx for the info on RPC
dan.wright
Reply #15 Monday, August 11, 2003 7:57 PM
This thing pounded us today. We had 12 servers RPC service all die at the same time and subsequenly it started spreading around to the desktops. Unfortunately it's almost impossible to keep up with the Microsoft/Anti-Virus patching machine
BtEO
Reply #16 Monday, August 11, 2003 8:16 PM
Just a heads up... despite my port being stealthed i still got hit somehow

Edit: got hit cause it's more than port 135 to worry about
http://isc.sans.org/diary.html?date=2003-08-11
Anthony R
Reply #17 Monday, August 11, 2003 8:52 PM
I got it everytime I tried to open my computer a countdown would start ...I went to get that patch from Microsoft and applied it and so far no countdown I hope it stays like
Anthony R
Reply #18 Monday, August 11, 2003 8:53 PM
Thanks for the info I thought I was flippin me lid
Larry Kuperman
Reply #19 Monday, August 11, 2003 9:16 PM
I recently switched to Trend Micro's Anti Virus software and have been very satisfied.

Like most of the major Anti-Virus companies, Trend Micro offers a free on-line scan. House Call is available from http://housecall.trendmicro.com/

Manual removal instructions are available from http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MSBLAST.A

I hope that this helps.
ZiUL
Reply #20 Monday, August 11, 2003 9:17 PM
Ok... I got this thing and I was able to stop the shutdown process:
start > run > shutdown -a

done...

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01