Visit the Ironworks Gaming Website Email the Webmaster Graphics Library Rules and Regulations Help Support Ironworks Forum with a Donation to Keep us Online - We rely totally on Donations from members Donation goal Meter

Ironworks Gaming Radio

Ironworks Gaming Forum

Go Back   Ironworks Gaming Forum > Ironworks Gaming Forums > General Discussion > General Conversation Archives (11/2000 - 01/2005)
FAQ Calendar Arcade Today's Posts Search

 
 
Thread Tools Search this Thread
Old 10-22-2003, 01:53 PM   #1
SpiritWarrior
Jack Burton
 

Join Date: May 31, 2002
Location: Ireland
Posts: 5,854
So this is a problem with my mates' computer. He was infected with the blaster worm a month or so back and asked me to sort it out for him. When I went down I found it running under MSBlast.exe, disabled it, looked in the registry but did not find it so got the critical patch for XP and thought it sorted. Time passed and his system seemed fine. Great.

Just recently he had reinstalled XP and began to get this RPC error again (about a day or so after reinstallation), with XP shutting down after a 60(?) second countdown. I immediately thought he had somehow gotten re-infected so went down there to sort it out. When I checked the the task manager there was no sign of MSblast.exe so I disabled the RPC to 'take no action' so I could buy myself some time to look around his system.

It started doing alot of weird shit to be honest. In the task manager there was no telltale MSblast.exe but there was a blank line...like it had no description under 'Image Name' except for the path after it. Basically something was running but it had no name at all. I suspected maybe a variant of the blaster worm, hiding itself under a blank in the task manager so I clicked 'End task' and stopped it. I went back into services.msc to re-enable to RPC back to default and for some reason I could not bring up the properties menu to do this, I clicked and nothing happend. I clicked on other things (files, apllications etc.) and none would bring up a properties menu when asked to. When I tried to run media player it gave a message of 'Low Memory'. I downloaded the symantec Blaster worm removal tool and ran it. No blaster worm detected.

Well after messing around with it my mate said he'd been thinking of re-installing XP again since he'd done this recently and this would be a better time than any since there was basically nothing on the drive yet. I said ■■■■ it and let him go ahead and do this, warning him that he must patch XP and get up to date as soon as he reinstalls. Well, he reinstalled and it looked fine, he downloaded half of the patches (he's on dial-up) then just called me right now (2 days after) to say the RPC error had started again! I'm now thinking it may not be the blaster worm at all. He says that when he clicks on media player it again gives him a 'low memory'. I told him I really didn't have a clue what it is and would ask around before arriving with the intention of fixing it. Again, it's my friends computer so I can't provide specific details on the problem only that it sounds like the one I already looked at not 2 days previous. Does anyone have any idea/experience on this? If i disable to RPC protocol and just patch for the blaster worm (regardless of symantec saying there is none detected) you think it will be okay? Or should I still try to find the root of the problem?

[ 10-22-2003, 01:54 PM: Message edited by: SpiritWarrior ]
__________________
Still I feel like a child when I look at the moon, maybe I grew up a little too soon...
SpiritWarrior is offline  
Old 10-22-2003, 02:08 PM   #2
Faceman
Hathor
 

Join Date: February 18, 2002
Location: Vienna
Age: 42
Posts: 2,248
if you really suspect a virus download one of the great free anti-virus tools (AVG or Panda)
__________________
\"I am forever spellbound by the frailty of life\"<br /><br /> Faceman
Faceman is offline  
Old 10-22-2003, 02:26 PM   #3
SpiritWarrior
Jack Burton
 

Join Date: May 31, 2002
Location: Ireland
Posts: 5,854
Tried Norton, MCAfee, and the symantec tool.
__________________
Still I feel like a child when I look at the moon, maybe I grew up a little too soon...
SpiritWarrior is offline  
Old 10-22-2003, 04:15 PM   #4
WillowIX
Apophis
 

Join Date: July 10, 2001
Location: By a big blue lake, Canada
Age: 50
Posts: 4,628
Disable the DCOM service on that machine, it's never used anyway... You can find more info about that here. The program is called DCOMbobulator.
__________________
Confuzzled by nature.
WillowIX is offline  
Old 10-22-2003, 06:06 PM   #5
SpiritWarrior
Jack Burton
 

Join Date: May 31, 2002
Location: Ireland
Posts: 5,854
Ok will have a look at it. Although from what I can see that's already involved in the patch. I dled the manual patch for it at http://www.heise.de/english/newsticker/news/39464 so I'm hoping that will address just the worm since he's on dialup and it takes hours to fully patch a new system. I'll see what I can do.
__________________
Still I feel like a child when I look at the moon, maybe I grew up a little too soon...
SpiritWarrior is offline  
Old 10-22-2003, 07:18 PM   #6
WillowIX
Apophis
 

Join Date: July 10, 2001
Location: By a big blue lake, Canada
Age: 50
Posts: 4,628
Quote:
Originally posted by SpiritWarrior:
Ok will have a look at it. Although from what I can see that's already involved in the patch. I dled the manual patch for it at http://www.heise.de/english/newsticker/news/39464 so I'm hoping that will address just the worm since he's on dialup and it takes hours to fully patch a new system. I'll see what I can do.
No Microsoft's patch does NOT disable the DCOM service. It just solves one exploit but leaves the service running.
__________________
Confuzzled by nature.
WillowIX is offline  
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
New Version of Spyware Blaster is NICE!! Larry_OHF General Conversation Archives (11/2000 - 01/2005) 2 04-15-2004 01:39 PM
Are you a good worm or a bad worm? Rokenn General Conversation Archives (11/2000 - 01/2005) 3 08-20-2003 01:21 AM
I need computer help ( about Blaster.worm ) Kakero General Conversation Archives (11/2000 - 01/2005) 15 08-16-2003 04:16 AM
I have a worm! I have a worm! :-( Vedran General Conversation Archives (11/2000 - 01/2005) 5 01-25-2003 01:55 PM
Variant portraits Nanobyte Baldurs Gate II: Shadows of Amn & Throne of Bhaal 6 11-15-2002 11:57 AM


All times are GMT -4. The time now is 03:35 AM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
©2024 Ironworks Gaming & ©2024 The Great Escape Studios TM - All Rights Reserved