PDA

View Full Version : Nasty Virus : RPC error



Rob.J
08-12-2003, 02:43 AM
Pc keeps rebooting itself, anyone else had problems with "remote procedure call (RPC) service terminated" error message.

It seems to be hitting mucho peeps

Think i may have sorted it but now have another error to deal with....arggghhhhhhh

rob :(

O'love
08-12-2003, 02:46 AM
if you're on XP you should activate your firewall, if you're on another OS download and install ZoneAlarms (it's free)

Olaf

Rob.J
08-12-2003, 02:48 AM
Firewall has now been activated on XP

But now i have an error message about dcom.exe problems, at least i think imentioned dcom or something similar

rob

AD
08-12-2003, 03:00 AM
Rob, next time you get an error message hit your print screen button and paste it into an image editing program. Then type out the exact error message and I'll try to help you out.

AD
08-12-2003, 03:01 AM
BTW, a firewall does nothing to prevent a virus from getting to your computer, nor does it do anything to protect you from viruses. So a firewall isn't what you should be concerned with right now.

Rob.J
08-12-2003, 03:22 AM
Will do

Many thanks

rob

Jolyon
08-12-2003, 03:25 AM
Rob

I had this yesterday - it's a virus.

Go here and sort it out...

http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

Nege
08-12-2003, 03:29 AM
I've been trying to get rid of this all night graemlins/cussing.gif

Nege
08-12-2003, 03:30 AM
Ok it's gone now,(or it seems to be)
I went into the registry and deleted the exe file.
my OS was shutting down all day(Monday) graemlins/cussing.gif
Hope this works

[ August 12, 2003, 04:32 AM: Message edited by: Nege ]

Jolyon
08-12-2003, 03:33 AM
p.s. to stop your pc shutting down while you fix the problem...change the year on your clock to 2002.

Ben.
08-12-2003, 03:34 AM
http://windowsupdate.microsoft.com sounds like you need the latest security patch

Nege
08-12-2003, 03:46 AM
yeah,
all of this stuff seems to be working,
Wish I knew about all this 12 hrs ago.

upliftdisco365
08-12-2003, 05:37 AM
Originally posted by Ben.:
http://windowsupdate.microsoft.com sounds like you need the latest security patch I just installed this path. I kept getting an "NT Authority" window that would shut my PC down. I'd just sit there helpless watching it close. It seems OK now. I used the patch for 32-bit XP and have had no more problems.

O'love
08-12-2003, 05:53 AM
Originally posted by Albert Diaz:
BTW, a firewall does nothing to prevent a virus from getting to your computer, nor does it do anything to protect you from viruses. So a firewall isn't what you should be concerned with right now. i don't want to get to technical here, but this "Blaster" virus that is causing these problems doesn't need to be installed on the system itself, when your computer is unprotected, ie you have your RPC ports open to the internet, other infected computers on the internet try to connect to the RPC port and exploit a bug in unpatched RPC code, which will cause a buffer-overflow and crash your system...this will happen every time you reboot and connect to the internet...

the best solution for this kind of crap is to use a decent firewall and only open up the ports you definately need (ie 80 for HTTP, 21 for FTP etc.) .. and do this in combination with a good realtime virus-scanner that protects your system from getting infected and participating in this kind of shitty DDoS attacks..

Olaf

Molsten
08-12-2003, 06:04 AM
Yep its hit our company, all our IT guys are sorting it at the mo, seemed to get through our firewalls, its a feckin pain in the ass... AR15firing.gif

Bobby L
08-12-2003, 06:38 AM
Thank God for DHP. This sh*t kept f*cking with my PC all night. I didn't know it was a virus. I'm going to run home and try the fixes during my lunch break.

Thanks, Bobby

Matt U
08-12-2003, 07:27 AM
the file usually lies at:

C:\ Windows\ system32\ msblast.exe
If you're on Windows 2000 or NT it should be under
C:\ WINNT \ system32\ msblast.exe

get rid of it.

C hristian
08-12-2003, 07:33 AM
i got it too. damn!

Nege
08-12-2003, 07:41 AM
I'm cool now,
the symantec "fixblast" tool and the windows update patch works.

drilla
08-12-2003, 08:36 AM
this shit had me flippin' out yesterday.

i changed the rpc setting to "take no action" instead of rebooting and downloaded the fix...ran the fix. then i ended the process for "msblast.exe", then deleted it from it's directory which ended in the system32 folder.

it was stressful at first.

alex zen
08-12-2003, 08:42 AM
Originally posted by alexander james zen:
</font><blockquote>quote:</font><hr />Originally posted by deepred:
I just tried Spybot S&D and now my computer is running much faster!! It was getting slow and driving me insane. wow. hail.gif thank you graemlins/thumbsup.gif i tried spybot, now i have a W32.Blaster.Worm that keeps shuting down the puter evere 15 minutes. i try to scan for it but my puter shuts down before the scan is complete. shiiiiiiiiiiiit. </font>[/QUOTE]this what i got last night.

SuzanneT
08-12-2003, 12:02 PM
Arghhh! graemlins/scared.gif
THIS WORM IS KILLIN ME! 50 PC'S AND 3 SERVERS and counting

Barrie Moodswing
08-12-2003, 12:05 PM
What OS are you all using ? This happened to a few of my friends last night but they were running Windows XP, I ain't had this problem yet,The resolved it by getting the latest secuity patch for WIN XP.

Rob.J
08-12-2003, 02:58 PM
Sorry to come back to this but does anyone have any idea what function " dcomx.exe " performs.

thanks in advance

rob

darrow
08-12-2003, 03:19 PM
Originally posted by Rob.J:
Sorry to come back to this but does anyone have any idea what function " dcomx.exe " performs.

thanks in advance

rob assuming you do mean dcomx.exe and not dcom.exe, dcomx.exe is what is called the backdoor component of a trojan horse virus. It's presence means you have been infected by a virus/been the victim of an attack.

Here's some of the things it can do...

Using ICQ to send a notification message when the backdoor is started
Downloading and executing files
Ending running processes
Dynamically updating the installed Trojan
Performing Denial of Service (DoS) attacks
Stealing CD keys
"Securing" the machine by removing network shares
Logging keystrokes
Attacking other systems using various exploits

(I took these from Symantec.com)

jnr
08-12-2003, 03:33 PM
there is a hidden message in this virus:


"The worm contains the following text, which is never displayed:

I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ? Stop making money and fix your software!!"


who the hell is SAN? graemlins/conf44.gif

C hristian
08-12-2003, 04:47 PM
for me, it was a remote attack, i beleive.
i tried to do a virus scan, but all my norton stuff was knocked out by it.

so i downloaded zone alarm, (and every little patch and fix it norton utility and Spyware search and destroy) and used it, and i feel so secure now! smile.gif ..until the next time graemlins/cool_shades.gif :(

C hristian
08-12-2003, 04:48 PM
i decided that my unprotected group sex /virus joke isn't funny, so i edited it out.

[ August 12, 2003, 05:50 PM: Message edited by: C hristian ]

der geile hund
08-13-2003, 09:33 AM
Hey all, if I'm using a pirated version of XP, can I still download Service Packs and shit from MS, or do they check that shit now? Aren't there supposedly new and fancy ways Bill G. could bust me?

Rob.J
08-13-2003, 12:52 PM
PC is now officially f**ked, all seemed to be working fine then i rebooted and the display has gone to hell and getting a .DLL error.

Tried to alter the display settings the only option is 8bit colour

Reinstall grahpics card ?
System restore ?

I am running XP pro by the way

rob :(

flypitcher
08-13-2003, 01:03 PM
I posted the solution in a previous post under
g-man a new virus hitting..............

GROOVE VICTIM
08-13-2003, 01:32 PM
Well I spent the day updating service packs and installing patches on all of our laptops running 2000 Professional and XP Professional. Everything is running smoothly.

If anyone encounters any problems with Windows 9x operating systems, please let me know. All of our workstations are still running 95 and 98 with the exception of a few office personnel PCs. I'd rather be safe than sorry.

Peace