For every question, there's an answer -- and you'll find it here!


Printer-friendly copy
Top The PC Q&A Forum The Computer Forum topic #243343
View in linear mode

Subject: "rpc dcom worm out - msblaster/lovesan - please read for..." Previous topic | Next topic
crazyXgermanSun Jul-25-04 07:44 PM
Charter member
5592 posts
Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
"rpc dcom worm out - msblaster/lovesan - please read for..."
Fri Aug-15-03 04:01 PM by crazygerman

  

          

links to descriptions, scanning and removal tools for blaster/lovesan worm:

http://www.eeye.com/html/Research/Advisories/AL20030811.html
http://www.eeye.com/html/Research/Tools/RPCDCOM.html
http://isc.sans.org/diary.html?date=2003-08-11
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
http://support.microsoft.com/?kbid=823980
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
http://www.secadministrator.com/Articles/Index.cfm?ArticleID=39837
http://www.counterpane.com/alert-v20030801-001.html
http://www.iss.net/support/product_utilities/ms03-026rpc.php
http://support.microsoft.com/default.aspx?scid=kb;en-us;823980
http://support.microsoft.com/default.aspx?kbid=826369

additional tidbits:

- if you are experiencing the shutdown problem associated with this issue, open a command prompt window and type shutdown /a. you may be able to abort the shutdown process. this only works on windows xp or win2k w/resource kit.

- you may be able to prevent a failing rpc service from rebooting your machine by changing the service properties. navigate to start / control panel / administrative tools / services / Remote Procedure Call RPC, right-click and select Properties / Recovery. change the failure response to something else than reboot the computer.

==============================================================

there is another piece of malware out there since 8/2 that also takes advantage of the rpc vulnerability and installs an existing backdoor mechanism. this one is a trojan, not a worm, and is a separate threat / NOT related to the blaster/lovesan worm!

http://www.viruslist.com/eng/viruslist.html?id=61506
http://news.com.com/2100%2D1009%2D5059263.html
http://www3.ca.com/virusinfo/virus.aspx?ID=36115
http://www.datafellows.fi/v-descs/rpc.shtml

if your machine has been rooted by use of this backdoor, then the only safe method of recovery is a clean install.


once again, the lesson learned is: visit the windows update site regularly and install all critical updates immediately! alternatively, use the automatic windows update feature to automatically download all critical updates, or at least subscribe to microsoft's security notification service at http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/notify.asp.

if you don't trust the critical updates, get yourself drive imaging software such as acronis true image and make a drive image before installing the critical update. alternatively, windows xp offers the system restore feature in case something goes wrong.

the only reason why worms like this one can propagate is due to user ignorance. properly patched systems are not affected.

  

Alert Printer-friendly copy | | Top

Replies to this topic
Subject Author Message Date ID
RE: rpc dcom worm out
Aug 11th 2003
1
RE: rpc dcom worm out
Aug 11th 2003
2
RE: rpc dcom worm out
Aug 11th 2003
3
      RE: rpc dcom worm out
Aug 11th 2003
4
           RE: rpc dcom worm out
Aug 11th 2003
5
RE: rpc dcom worm out
Aug 12th 2003
6
RE: rpc dcom worm out
Aug 12th 2003
7
      RE: rpc dcom worm out
Aug 12th 2003
8
Internet Traffic Report shows impact of RPC / dcom bug
Aug 12th 2003
9
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 12th 2003
10
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 12th 2003
11
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 12th 2003
12
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 12th 2003
13
RE: rpc dcom worm out - msblaster/lovesan - please read...
Jul 25th 2004
28
      RE: rpc dcom worm out - msblaster/lovesan - please read...
Jul 25th 2004
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 13th 2003
17
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 13th 2003
14
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 13th 2003
15
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 13th 2003
16
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 13th 2003
18
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 13th 2003
19
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 14th 2003
20
      RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 14th 2003
21
           RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 14th 2003
22
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 15th 2003
23
RE: rpc dcom worm out - msblaster/lovesan - please read...
Aug 15th 2003
24
RE: rpc dcom worm out - msblaster/lovesan - please read...
Sep 05th 2003
25
RE: rpc dcom worm out - msblaster/lovesan - please read...
Sep 05th 2003
26
RE: rpc dcom worm out - msblaster/lovesan - please read...
Jul 25th 2004
27

doctormidnightMon Aug-11-03 09:00 PM
Charter member
11300 posts
Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
#1. "RE: rpc dcom worm out"
In response to crazyXgerman (Reply # 0)


  

          

Bumping this up because we've already had a few people with the problem.

  

Alert Printer-friendly copy | | Top

pwrguruMon Aug-11-03 09:03 PM
Member since Feb 18th 2003
532 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#2. "RE: rpc dcom worm out"
In response to crazyXgerman (Reply # 0)
Mon Aug-11-03 09:04 PM by pwrguru

  

          

Mickster just posted a web site to help out those people and i am just passing this along in case they do not read that post... http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp



PWRGURU

  

Alert Printer-friendly copy | | Top

    
micksterMon Aug-11-03 09:08 PM
Charter member
6671 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#3. "RE: rpc dcom worm out"
In response to pwrguru (Reply # 2)


          

The patch is on that page also.

  

Alert Printer-friendly copy | | Top

        
sophie tuckerMon Aug-11-03 09:36 PM
Member since Jan 31st 2002
6544 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#4. "RE: rpc dcom worm out"
In response to mickster (Reply # 3)


          

applied the patch as it sounded less scary.

will keep you all posted.

sophie

  

Alert Printer-friendly copy | | Top

            
sophie tuckerMon Aug-11-03 09:52 PM
Member since Jan 31st 2002
6544 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#5. "RE: rpc dcom worm out"
In response to sophie tucker (Reply # 4)


          

21 minutes and no shut down yet.

this may be it!

  

Alert Printer-friendly copy | | Top

therubeTue Aug-12-03 01:45 AM
Member since Jan 22nd 2003
16604 posts
Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#6. "RE: rpc dcom worm out"
In response to crazyXgerman (Reply # 0)


  

          

Based upon the number of posts today here alone on this subject, seems like for the majority of users out there Shelly has it correct.


<http://www.pcqanda.com/dc/dcboard.php?az=show_topic&forum=2&topic_id=242888>
"You were correct to install the critical updates, all "rules" should be broken under certain circumstances, and security is one good example."


Wonder what the commonality is between the various people who have just gotten this worm is. Ok, a port scanner & lax security?

  

Alert Printer-friendly copy | | Top

    
aewysiwygTue Aug-12-03 02:06 AM
Charter member
291 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
#7. "RE: rpc dcom worm out"
In response to therube (Reply # 6)


          

That's not the same thing as this is it?

http://www.washingtonpost.com/wp-dyn/articles/A46233-2003Aug11.html

because I didn't see any mention of the alias "san" on the sites mentioned above. I also didn't find any support for a virus that goes by "blaster" and "san" on the Symantec website. Any news on this?

  

Alert Printer-friendly copy | | Top

        
TufenufTue Aug-12-03 02:40 AM
Charter member
1417 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#8. "RE: rpc dcom worm out"
In response to aewysiwyg (Reply # 7)


          

Alex's first post has the Symantec Removal Instructions link. Here's the link again.

http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html


Tufenuf

  

Alert Printer-friendly copy | | Top

AllynTue Aug-12-03 04:18 PM
Member since Dec 27th 2001
12072 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#9. "Internet Traffic Report shows impact of RPC / dcom bug"
In response to crazyXgerman (Reply # 0)


          

http://www.internettrafficreport.com/main.htm

  

Alert Printer-friendly copy | | Top

Paul DTue Aug-12-03 07:10 PM
Charter member
10207 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#10. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)


  

          

Am I correct in understanding that this does NOT apply to 98?



Paul D

  

Alert Printer-friendly copy | | Top

    
martiTue Aug-12-03 07:16 PM
Charter member
11338 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#11. "RE: rpc dcom worm out - msblaster/lovesan - please read..."
In response to Paul D (Reply # 10)


  

          

>Am I correct in understanding that
>this does NOT apply to 98?



Correct.

Systems Affected: Windows 2000, Windows XP from this link:

http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

marti

  

Alert Printer-friendly copy | | Top

    
PhilipTue Aug-12-03 07:50 PM
Charter member
134 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#12. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to Paul D (Reply # 10)


          

According to my German providor, T-Online, the worm is a danger for NT4, 2000 and XP.

  

Alert Printer-friendly copy | | Top

    
ShellyTue Aug-12-03 10:21 PM
Charter member
58338 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#13. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to Paul D (Reply # 10)


  

          

All flavors of NT.

Shelly

  

Alert Printer-friendly copy | | Top

        
adirongSun Jul-25-04 07:46 PM
Charter member
1601 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#28. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to Shelly (Reply # 13)


          

Shelly,

I've just downloaded the patch from microsoft for the blaster worm and all seems fine with my computer. Just wondering if it is recommended to download the "removal tool" even thought I don't believe I am infected; to have it just in case so to speak??

Thanks,

Adirondack Girl

  

Alert Printer-friendly copy | | Top

            
crazyXgermanSun Jul-25-04 07:44 PM
Charter member
5592 posts
Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
"RE: rpc dcom worm out - msblaster/lovesan - please read for..."


  

          

it doesn't hurt anything to run it. all it takes is a few minutes computing time. if you want to be safe and have peace of mind, by all means, go ahead.

  

Alert Printer-friendly copy | | Top

    
oldgitWed Aug-13-03 02:46 PM
Member since Jan 26th 2002
1442 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#17. "RE: rpc dcom worm out - msblaster/lovesan - please read..."
In response to Paul D (Reply # 10)


  

          

Paul, I'm sure that this only affects Win NT, 2K and XP. BTW thanks to the Gurus I've succeeded in getting rid of the Worm/Virus whatever. There have been some repercussions however. I did all the good things as per Alex's piece, but there remain some registry entries that keep coming back after reboot. They are in H_KEYUSERS/Software/Microsoft/Searchassistent/ACmru/5603/Defaultreg_SZ......They are as follows Lovsan, Start %s, windowsupdate.com, BILLY, and msblast. I've tried to rename them, but they come back, so I guess they're in the MBR. Any ideas please, apart from a clean install, that my friend is hesitant to do??? AVG puts up a screen that says it's detected the virus, but when you run, it finds nothing. As far as I can tell the system seems to be working OK apart from that. Any ideas please, and thanks in advance !!!
Sincerely,
Richard.
Website http://www.mvessexgirl.com
Athlon XP2600, MSI K7N2 Motherboard with onboard sound, 1x 30Gb 1x 80Gb hdds, , Toshiba DVD,NEC DVD+RW, 1Gb DDR RAM,GeForce 128Mb video card, 450w PSU, OneTouch8600 scanner, Win XP Pro.
“It’s nice to be important, but it’s important to be nice”





http://www.worldcommunitygrid.org/getDynamicImage.do?memberName=oldgit&mnOn=true&stat=1&imageNum=3&rankOn=false&projectsOn=false&special=true" frameborder="0" name="di" scrolling="no" width="125px" height="176px">

  

Alert Printer-friendly copy | | Top

WakkoWed Aug-13-03 01:11 PM
Charter member
5198 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#14. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)


  

          

Microsoft wrote the patch specifically for W2K SP2 and SP3, but because SP4 shipped prior to the patch being released, said it was supported only on the current and N-1 SP (SP3 and SP4). Its taken them 27 days to officially say it will work on a platform they designed it for, SP 2.

Mostly cut and paste from NTBugTraq, but something I've been trying to beat over the head of several coworkers here. It does work for Win2K SP 2.

  

Alert Printer-friendly copy | | Top

CrashnburnWed Aug-13-03 02:01 PM
Charter member
55 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#15. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)


          

Can I just use a system retore point prior to the date of infection and then install the MS patch and update my NAV definitions?

Thanks

  

Alert Printer-friendly copy | | Top

tangomanWed Aug-13-03 02:42 PM
Charter member
378 posts
Click to view this author's profileClick to add this author to your buddy list
#16. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)


          

There are also a few interesting threads on our own Board about all this. Here are a few:

http://www.pcqanda.com/dc/dcboard.php?az=show_topic&forum=2&topic_id=243393&mesg_id=243393&page=2

http://www.pcqanda.com/dc/dcboard.php?az=show_topic&forum=2&topic_id=243373&mesg_id=243373&page=

http://www.pcqanda.com/dc/dcboard.php?az=show_topic&forum=2&topic_id=243379&mesg_id=243379&page=3

  

Alert Printer-friendly copy | | Top

Josh NWed Aug-13-03 04:23 PM
Charter member
1523 posts
Click to send email to this authorClick to view this author's profileClick to add this author to your buddy list
#18. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)


  

          

It shutdown our domain within 30 minutes yesterday afternoon. The servers that I support already had the patch, but majority of the others did not. Not to mention the 10000+ clients that needed patching. You can guess that amount of headaches going on around here today.

  

Alert Printer-friendly copy | | Top

DarrenWed Aug-13-03 10:41 PM
Charter member
9461 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#19. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)


  

          

Direct download for the patch...If you don't already have it.
To check, go to Control Panel Add\Remove Programs, and look for Hotfix KB823980.

http://www.microsoft.com/security/incident/blast.asp




  

Alert Printer-friendly copy | | Top

    
SoccerAceThu Aug-14-03 12:58 AM
Member since Jun 21st 2003
186 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
#20. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to Darren (Reply # 19)


          

My friend got the worm and i figured i could find information on this site. PC Q and A rules!
Soccerace

512MB DDR 333 RAM
AMD 1.6 Ghz processor
128 R-9000 graphics card
60gig harddrive
Windows 98se

  

Alert Printer-friendly copy | | Top

        
JoeBunThu Aug-14-03 02:30 PM
Member since Aug 28th 2002
22 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#21. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to SoccerAce (Reply # 20)


          

Hi, I'm still having trouble with my computer after deleting the blaster worm. I used the symantec exe to get rid of the worm, but I'm still having internet connectivity issues: I can log on thorugh my dsl modem but I can't load any pages or ftp or anything. Plus, my virus scanner (McAfee) still crashes out unless I'm in safe mode. Anybody have any suggestions?

AMD 1900
Win2000

  

Alert Printer-friendly copy | | Top

            
Bob HThu Aug-14-03 03:53 PM
Charter member
10682 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#22. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to JoeBun (Reply # 21)


  

          

Don't know what the Symantec fix might have done to your McAfee virus, unless it decided to delete it, too. Makes sense, in a way. I'd suggest going to McAfee site and get the instructions for deleting it and then install a good AV, or reinstall McAfee. (Affectionately known as McCrappy. )



  

Alert Printer-friendly copy | | Top

hal9000Fri Aug-15-03 01:11 AM
Member since Jan 21st 2002
3876 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#23. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)
Fri Aug-15-03 04:06 AM by hal9000

          



Thanks..

  

Alert Printer-friendly copy | | Top

HETTATLONGUNFri Aug-15-03 06:09 AM
Member since Feb 09th 2002
1032 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
#24. "RE: rpc dcom worm out - msblaster/lovesan - please read..."
In response to crazyXgerman (Reply # 0)


          

Latest Microsoft information and fix: What You Should Know About the Blaster Worm.

AMD Athlon64 3000+, MSI K8T Neo-FSR, Corsair CMX512-PC3200C2, Windows XP Pro, High-Speed AOL Plus!

  

Alert Printer-friendly copy | | Top

BarbFri Sep-05-03 12:24 AM
Charter member
413 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#25. "RE: rpc dcom worm out - msblaster/lovesan - please read..."
In response to crazyXgerman (Reply # 0)


          

Looks like this might be what hit me today, but it's not checking out that way.

When I first came home, had black screen saying that it couldn't find a boot file, install disk and hit any key.

After checking out bios my primary hard drive was not showing, and I couldn't make it show. Went into Fdisk and it wasn't there either.

I changed out the cable and it booted and I say hooray and walked out of the room. Came back five minutes later to see it boot again. Uh oh...

I went into safe mode to see what I could see.

I'm on a home network with a router, WinXP Home, AOL broadband which I'm told works as a VPN. I have all XP updates as of two days ago, and Norton AV 2003 updated as of yesterday with a full system scan.

Right now I'm using the blast tool, but Norton already said I didn't have any virus problems.

I followed Alex's direction and went into processes and changed it from rebooting, but I've not finished with the tool yet.

If it's not Blaster what else can I try? thanks

  

Alert Printer-friendly copy | | Top

    
BarbFri Sep-05-03 04:42 AM
Charter member
413 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#26. "RE: rpc dcom worm out - msblaster/lovesan - please read..."
In response to Barb (Reply # 25)


          

After much playing, I was able to get it to boot up and stay booted. But all my personal preferences are gone - email, etc. I can see my name in documents and settings, but there is another me in there also.

But there is only one name as user so I'm very confused. It's late and I'm wiped..I'll start another thread tomorrow.

I'm not convinced that this was caused by a virus/worm.

  

Alert Printer-friendly copy | | Top

crazyXgermanSun Jul-25-04 07:44 PM
Charter member
5592 posts
Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#27. "RE: rpc dcom worm out - msblaster/lovesan - please read for..."
In response to crazyXgerman (Reply # 0)


  

          

"A flaw in Windows Update caused some organisations - including the US Army - to wrongly believe they were protected from MSBlast, according to a researcher.

A flaw in Windows Update -- Microsoft's online tool that lets customers update their operating system with patches and fixes -- enabled the MSBlast worm to infect computers that apeared to have already been patched, according to a security expert."

http://news.zdnet.co.uk/0,39020330,39115732,00.htm

  

Alert Printer-friendly copy | | Top

Top The PC Q&A Forum The Computer Forum topic #243343 Previous topic | Next topic
Powered by DCForum+ Version 1.27
Copyright 1997-2003 DCScripts.com
Home
Links
About PCQandA
Link To Us
Support PCQandA
Privacy Policy
In Memoriam
Acceptable Use Policy

Have a question or problem regarding this forum? Check here for the answer.