Author Topic: virus for winxp: remote process control failure  (Read 2284 times)

Offline Creamo

  • Parolee
  • Platinum Member
  • ******
  • Posts: 5976
      • http://www.fatchicksinpartyhats.com
virus for winxp: remote process control failure
« Reply #30 on: August 12, 2003, 12:37:32 PM »
Quote
Originally posted by Curval
My home machine has this...turned up this morning.

I'm p*ssed....my wife's relatives have been playing around on my computer and someone must have downloaded something.

:mad: :mad:


And you got crabs from the toilet seat...

Nope, it searches for an open port and yer done. Unpatched Windows, and no firewall, you got it.

Offline Curval

  • Plutonium Member
  • *******
  • Posts: 11572
      • http://n/a
virus for winxp: remote process control failure
« Reply #31 on: August 12, 2003, 12:47:00 PM »
Really?  You mean I cannot blame this on relatives....DAMN.  :)

Okay...patching tonight, and virus software going on too.

Thanks guys.

Now, how do I get rid of these crabs?
Some will fall in love with life and drink it from a fountain that is pouring like an avalanche coming down the mountain

Offline Creamo

  • Parolee
  • Platinum Member
  • ******
  • Posts: 5976
      • http://www.fatchicksinpartyhats.com
virus for winxp: remote process control failure
« Reply #32 on: August 12, 2003, 12:53:55 PM »
The non-electric vaccum pump.

whoopee it's hard to sell a goof here.

Offline Furball

  • Plutonium Member
  • *******
  • Posts: 15781
virus for winxp: remote process control failure
« Reply #33 on: August 12, 2003, 01:00:58 PM »
i got it last night too. scared the crap outta me!

Quote
W32.Blaster.Worm is a worm that will exploit the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. It will attempt to download and run the file Msblast.exe.

You should block access to TCP port 4444 at the firewall level, and block the following ports, if they do not use the applicaitons listed:


TCP Port 135, "DCOM RPC"
UDP Port 69, "TFTP"

The worm also attempts to perform a Denial of Service on windowsupdate.com. This is an attempt to disable your ability to patch you computer against the DCOM RPC vulnerability.

Click here for more information on the vulnerability being exploited by this worm and to find out which Symantec products can help mitigate risk from this vulnerability.

NOTE: This threat will be detected by virus definitions having:
Defs Version: 50811s
Sequence Number: 24254
Extended Version: 8/11/2003 rev. 19

Also Known As: W32/Lovsan.worm [McAfee]

Type: Worm
Infection Length: 6,176 bytes



Systems Affected: Windows 2000, Windows XP
Systems Not Affected: Linux, Macintosh, OS/2, UNIX
CVE References: CAN-2003-0352


This is what NAV said about it, i removed the file, removed the registry key and patched computer.  Everything seems fine now!
I am not ashamed to confess that I am ignorant of what I do not know.
-Cicero

-- The Blue Knights --

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
virus for winxp: remote process control failure
« Reply #34 on: August 12, 2003, 01:08:52 PM »
Uhmm..just clarification:  An "open" port is a port on your computer that has some software attached to it causing it to be visible.

Also, see this post: http://www.hitechcreations.com/forums/showthread.php?s=&threadid=93762
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline Curval

  • Plutonium Member
  • *******
  • Posts: 11572
      • http://n/a
virus for winxp: remote process control failure
« Reply #35 on: August 12, 2003, 01:27:46 PM »
So...logically if my wife's relatives downloaded the software that is attached to my port..they are still to blame.

Cool.  Thanks Skuzzy.
Some will fall in love with life and drink it from a fountain that is pouring like an avalanche coming down the mountain

Offline Wanker

  • Platinum Member
  • ******
  • Posts: 4030
virus for winxp: remote process control failure
« Reply #36 on: August 12, 2003, 01:34:10 PM »
Quote
Now, how do I get rid of these crabs?


I recommend seeing your pharmacist. She probably has some oitment that you can apply to your groin area.

May want to check the wife for crabs, too. Those little devils go everywhere




















:D

Offline hyena426

  • Silver Member
  • ****
  • Posts: 1756
virus for winxp: remote process control failure
« Reply #37 on: August 12, 2003, 03:32:48 PM »
all my freinds who dont have a firewall got it,,,i told them along time ago it would be a good idea to run zonealarm ,,,but no,,they wouldnt lisin,,lol,,but the ones i convinced to down load a firewall,,they got no virus at all,,crazy to your ip ports nakid online,,lol

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
virus for winxp: remote process control failure
« Reply #38 on: August 12, 2003, 03:48:43 PM »
It's all in how it is setup hyena.  I have never used a firewall, and still don't and still will not catch this bugger, or any other bugger released on the net.
There is the brute force approach, and the elegant approach in securing network and computer systems.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline boxboy28

  • Gold Member
  • *****
  • Posts: 2265
      • http://none
virus for winxp: remote process control failure
« Reply #39 on: August 12, 2003, 04:19:23 PM »
Ok since i didn t check my system this morning ( i think i shut it down last night but....)
So If i have it when i get home will it still let you start the system and get the patch + remove it? Or is this thing gonna make the system un usable?
^"^Nazgul^"^    fly with the undead!
Jaxxo got nice tata's  and Lyric is Andre the giant with blond hair!

Offline Curval

  • Plutonium Member
  • *******
  • Posts: 11572
      • http://n/a
virus for winxp: remote process control failure
« Reply #40 on: August 12, 2003, 04:35:20 PM »
Box..just follow what is said on the link provided by Ozark.  You will be able to boot up no problem...it isn't a file destroying virus as far as I could see.  I got that remote access control failure message this morning and it shut down my machibe.  But, I was able to boot up again no problem.

I'm now clean of this virus and patched.

Thanks all.
Some will fall in love with life and drink it from a fountain that is pouring like an avalanche coming down the mountain

Offline boxboy28

  • Gold Member
  • *****
  • Posts: 2265
      • http://none
virus for winxp: remote process control failure
« Reply #41 on: August 12, 2003, 04:43:22 PM »
COOL TY curval!
^"^Nazgul^"^    fly with the undead!
Jaxxo got nice tata's  and Lyric is Andre the giant with blond hair!

Offline daddog

  • Aces High CM Staff (Retired)
  • Plutonium Member
  • *******
  • Posts: 15082
      • http://www.332nd.org
virus for winxp: remote process control failure
« Reply #42 on: August 12, 2003, 05:20:14 PM »
This thing nailed me. I called several squadies yesterday about it and banana called me at 7:30 AM to tell me what I had. I could not even stay online long enough yesterday and this AM to read my e-mails or the BB's to find the answers to my questions.

Deleted the W32Blaster in the Task Mgr. Then downloaded the FixBlast which removed it. I then was reading all the BB's and e-mails while I was trying to download the updates to close the door to this nasty bug. During that I reinfected my system. Ugh.. had to go though it all again, but did not have any luck the first couple of tries. I could not find it in the Task Mgr. Finally was online long enough to download the XP update. Problem was I did not know if I needed the XP 64 bit or the XP 32 bit. I downloaded the 64. Wrong! Keep in mind I am up in the Sierra Nevada Mts on a slow dial up. So now I am downloading the 32 bit. Crossing my fingers I can get this fixed. :rolleyes:
Noses in the wind since 1997
332nd Flying Mongrels
daddog
Knowing for Sure

Offline Curval

  • Plutonium Member
  • *******
  • Posts: 11572
      • http://n/a
virus for winxp: remote process control failure
« Reply #43 on: August 12, 2003, 06:39:48 PM »
I wasn't sure about the 64 or 32 bit version either..I guess I got lucky and got the right one...I went with 32 (in Windows there is a System32 directory which is what I based my decision on.)

Sounds like you and I are at about the same tech level daddog...and these types of viruses/worms hurt guys like us the most.:(
Some will fall in love with life and drink it from a fountain that is pouring like an avalanche coming down the mountain

Offline AKIron

  • Plutonium Member
  • *******
  • Posts: 12772
virus for winxp: remote process control failure
« Reply #44 on: August 12, 2003, 06:40:33 PM »
Quote
Originally posted by muckmaw
Iron-

I've got a firewall on my PC...I think it's a McCaffee job. Yes, it's a big white M in a red square. (Geez, I know nothing about computers).

Anyway, it was a free trial but I never dowloaded it. I just keep resetting the clock on my computer back 2 weeks to keep it going.

Is this protection enough? Should I pay for the damn thing or keep bumping my computer back 2 weeks?


Muck, depends, if you have a broadband connection I'd definitely get a hardware firewall. CompUSA often has 'em for $40. If you have dialup there are many good software firewalls, personally I despise everything McAfee because of the headaches they've given me over the years. Zonealarm's pretty good.

Here's one reason a hardware firewall is better. Your PC isn't exposed to the attack and there's no Microsoft running on the firewall interface to be hacked/cracked/phracked.
Here we put salt on Margaritas, not sidewalks.