10-22-2003, 01:53 PM | #1 |
Jack Burton
Join Date: May 31, 2002
Location: Ireland
Posts: 5,854
|
So this is a problem with my mates' computer. He was infected with the blaster worm a month or so back and asked me to sort it out for him. When I went down I found it running under MSBlast.exe, disabled it, looked in the registry but did not find it so got the critical patch for XP and thought it sorted. Time passed and his system seemed fine. Great.
Just recently he had reinstalled XP and began to get this RPC error again (about a day or so after reinstallation), with XP shutting down after a 60(?) second countdown. I immediately thought he had somehow gotten re-infected so went down there to sort it out. When I checked the the task manager there was no sign of MSblast.exe so I disabled the RPC to 'take no action' so I could buy myself some time to look around his system. It started doing alot of weird shit to be honest. In the task manager there was no telltale MSblast.exe but there was a blank line...like it had no description under 'Image Name' except for the path after it. Basically something was running but it had no name at all. I suspected maybe a variant of the blaster worm, hiding itself under a blank in the task manager so I clicked 'End task' and stopped it. I went back into services.msc to re-enable to RPC back to default and for some reason I could not bring up the properties menu to do this, I clicked and nothing happend. I clicked on other things (files, apllications etc.) and none would bring up a properties menu when asked to. When I tried to run media player it gave a message of 'Low Memory'. I downloaded the symantec Blaster worm removal tool and ran it. No blaster worm detected. Well after messing around with it my mate said he'd been thinking of re-installing XP again since he'd done this recently and this would be a better time than any since there was basically nothing on the drive yet. I said ■■■■ it and let him go ahead and do this, warning him that he must patch XP and get up to date as soon as he reinstalls. Well, he reinstalled and it looked fine, he downloaded half of the patches (he's on dial-up) then just called me right now (2 days after) to say the RPC error had started again! I'm now thinking it may not be the blaster worm at all. He says that when he clicks on media player it again gives him a 'low memory'. I told him I really didn't have a clue what it is and would ask around before arriving with the intention of fixing it. Again, it's my friends computer so I can't provide specific details on the problem only that it sounds like the one I already looked at not 2 days previous. Does anyone have any idea/experience on this? If i disable to RPC protocol and just patch for the blaster worm (regardless of symantec saying there is none detected) you think it will be okay? Or should I still try to find the root of the problem? [ 10-22-2003, 01:54 PM: Message edited by: SpiritWarrior ]
__________________
Still I feel like a child when I look at the moon, maybe I grew up a little too soon... |
10-22-2003, 02:08 PM | #2 |
Hathor
Join Date: February 18, 2002
Location: Vienna
Age: 43
Posts: 2,248
|
if you really suspect a virus download one of the great free anti-virus tools (AVG or Panda)
__________________
\"I am forever spellbound by the frailty of life\"<br /><br /> Faceman |
10-22-2003, 02:26 PM | #3 |
Jack Burton
Join Date: May 31, 2002
Location: Ireland
Posts: 5,854
|
Tried Norton, MCAfee, and the symantec tool.
__________________
Still I feel like a child when I look at the moon, maybe I grew up a little too soon... |
10-22-2003, 04:15 PM | #4 |
Apophis
Join Date: July 10, 2001
Location: By a big blue lake, Canada
Age: 50
Posts: 4,628
|
Disable the DCOM service on that machine, it's never used anyway... You can find more info about that here. The program is called DCOMbobulator.
__________________
Confuzzled by nature. |
10-22-2003, 06:06 PM | #5 |
Jack Burton
Join Date: May 31, 2002
Location: Ireland
Posts: 5,854
|
Ok will have a look at it. Although from what I can see that's already involved in the patch. I dled the manual patch for it at http://www.heise.de/english/newsticker/news/39464 so I'm hoping that will address just the worm since he's on dialup and it takes hours to fully patch a new system. I'll see what I can do.
__________________
Still I feel like a child when I look at the moon, maybe I grew up a little too soon... |
10-22-2003, 07:18 PM | #6 | |
Apophis
Join Date: July 10, 2001
Location: By a big blue lake, Canada
Age: 50
Posts: 4,628
|
Quote:
__________________
Confuzzled by nature. |
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
New Version of Spyware Blaster is NICE!! | Larry_OHF | General Conversation Archives (11/2000 - 01/2005) | 2 | 04-15-2004 01:39 PM |
Are you a good worm or a bad worm? | Rokenn | General Conversation Archives (11/2000 - 01/2005) | 3 | 08-20-2003 01:21 AM |
I need computer help ( about Blaster.worm ) | Kakero | General Conversation Archives (11/2000 - 01/2005) | 15 | 08-16-2003 04:16 AM |
I have a worm! I have a worm! :-( | Vedran | General Conversation Archives (11/2000 - 01/2005) | 5 | 01-25-2003 01:55 PM |
Variant portraits | Nanobyte | Baldurs Gate II: Shadows of Amn & Throne of Bhaal | 6 | 11-15-2002 11:57 AM |