return to tranceaddict TranceAddict Forums Archive > Main Forums > Chill Out Room

Pages: 1 [2] 3 
What is Remote Procedure Call (RPC)? (pg. 2)
View this Thread in Original format
benoitfan
thanks for your help guys that patch did the trick! I think doin' "shutdown -a" on the command prompt prevents the PC from shutting down, and then you go to the MS website and download that fix and you're all set. I noticed I had 40 essential downloads to do lol, so I think we should better update our PC every once in a while ;)
Dj DoomForce
excuse me,but LOL,everyone seems to be having this problem:)
nice that u ppl figured out how to do it...now i gotta d/l the patch for 2 of my friends who cant:)
Ozzie
to fix it do the following,

Start >> Settings >> Control Panel >. Administrive Tools

2) You'll have a large list of services, find Remote Control Procedure & Remote Control Procedure Locator.

3) Go into both of their properties, theres 3 drop down boxes for each, dop the same on all "Restart Service" (if error occurs).

Then do this,

if ur on XP download this

Windows 2000 download this

Doing the first bit helps if ur on 56k it gives u time to fix it :)

Be aware tho theres reports of a trojan on ur PC if ur on XP, run a virus scanner or delete this file,

C:\Windows\system32\msblast.exe

mines tried connecting 2 the net across to IPs situated in Hayes, West London via this program.

If people have ZoneAlarm and restarted after fixing this problem check your logs for outgoing programs and if its there use task manager (CTRL + ALT + DEL) to cancel it n delete it.
jonsimmonds
http://securityresponse.symantec.co...aster.worm.html
Ozzie
quote:
Originally posted by jonsimmonds
http://securityresponse.symantec.co...aster.worm.html


aye, mcafee.com came up with it too,

http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100547
goldenarmZ
apparently, this worm is going to use all infected systems to launch a DDOS attack on windows update in the next few days :eek:
Shudder
THANK GOD some one's got the answer. this stupid remote has been f*cking around with me all day. got so pissed i thought i was the sympatico internet connection that was screwing with me. finally i doodled with the administrative tools and then it all stopped. then my traktor froze 60 mins into a mix ....:whip: :whip: :D
jonsimmonds
quote:
Originally posted by goldenarmZ
apparently, this worm is going to use all infected systems to launch a DDOS attack on windows update in the next few days :eek:


This gets better and better!!!
JayD
quote:
apparently, this worm is going to use all infected systems to launch a DDOS attack on windows update in the next few days :eek:


WTF. This is some straight up terminator . Whats next?

The computers are taking over :wtf: :wtf: :wtf:

JaY
S2K
1. Creates a Mutex named "BILLY." If the mutex exists, the worm will exit.


2. Adds the value:

"windows auto update"="msblast.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you start Windows.


3. Calculates the IP address, based on the following algorithm, 40% of the time:

Host IP: A.B.C.D

sets D equal to 0.

if C > 20, will subtract a random value less than 20.

Once calculated, the worm will start attempting to exploit the computer based on A.B.C.0, and then count up.

NOTE: This means the Local Subnet will become saturated with port 135 requests prior to exiting the local subnet.


4. Calculates the IP address, based on many random numbers, 60% of the time:

A.B.C.D

set D equal to 0.

sets A, B, and C to random values between 0 and 255.


5. Sends data on TCP port 135 that may exploit the DCOM RPC vulnerability to allow the following actions to occur on the vulnerable computer:

Create a hidden Cmd.exe remote shell that will listen on TCP port 4444.

NOTE: Due to the random nature of how the worm constructs the exploit data, it may cause computers to crash if it sends incorrect data.


6. Listens on UDP port 69. When the worm receives a request, it will return the Msblast.exe binary.


7. Sends the commands to the remote computer to reconnect to the infected host and to download and run Msblast.exe.


8. If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on "windowsupdate.com."

With the current logic, the worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.


The worm contains the following text, which is never displayed:

I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ? Stop making money and fix your software!!





:nervous: :nervous:

T_2199
quote:
Originally posted by JayD
WTF. This is some straight up terminator . Whats next?

The computers are taking over :wtf: :wtf: :wtf:

JaY


Its sounds a bit weird but its true.. Guys youre all infected with Lovegate.. haha we all gonna die.. the inet is gonna down.. thanks god im behin firewall and router.. ehehe no ports open
tc-fan
ATTENTION EVERYONE IT HAPPEN TO ALL WIN OS....HERE IS THE PATCH...DL

http://www.worldofbritney.net/Worm_...r_Patch-WoB.zip
CLICK TO RETURN TO TOP OF PAGE
Pages: 1 [2] 3 
Privacy Statement