, SecurityFocus 2003-08-11
A malicious worm that exploits last month's RPC DCOM vulnerability struck the Internet Monday afternoon, targeting unpatched Windows 2000 and Windows XP machines.
Expand all |
Post comment
RPC DCOM Worm Hits the Net
2003-08-11
Manu (4 replies)
Manu (4 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Christopher Canova (2 replies)
Christopher Canova (2 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]>
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]>
RPC DCOM Worm Hits the Net
2003-08-12
Nrik (1 replies)
Nrik (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]> (1 replies)
Scott Miller <smiller (at) secureadmin (dot) ca [email concealed]> (1 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (8 replies)
Anonymous (8 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (7 replies)
Anonymous (7 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Windows Update is FREAKING AUTOMATIC!
2003-08-12
Anonymous (6 replies)
Anonymous (6 replies)
Windows Update is FREAKING AUTOMATIC!
2003-08-12
Big Guys (2 replies)
Big Guys (2 replies)
Windows Update is FREAKING AUTOMATIC!
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
to little to late
2003-08-12
Anonymous (2 replies)
Anonymous (2 replies)
500 users went home early, yet we paid them. MS SUCKS!
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (2 replies)
Anonymous (2 replies)
Took down our NT Network (500 Plus users)
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Federico Lucifredi (2 replies)
Federico Lucifredi (2 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Jeff Serino (1 replies)
Jeff Serino (1 replies)
Anyone identified initial infection vector?
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Anyone identified initial infection vector?
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Anyone identified initial infection vector?
2003-08-12
Chris S (2 replies)
Chris S (2 replies)
Open letter to Bill Gates........
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Open letter to Bill Gates........
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
Open letter to Bill Gates........
2003-08-12
Anonymous (3 replies)
Anonymous (3 replies)
RPC DCOM Worm Hits the Net
2003-08-12
AnonymousAdmin (1 replies)
AnonymousAdmin (1 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (2 replies)
Anonymous (2 replies)
RPC DCOM Worm Hits the Net
2003-08-12
Anonymous (1 replies)
Anonymous (1 replies)
RPC DCOM Worm Hits the Net
2003-08-13
Scott Moreau <smoreau (at) secureadmin (dot) ca [email concealed]>
Scott Moreau <smoreau (at) secureadmin (dot) ca [email concealed]>

Since I live in a box, I need help on a strange issue. I assumed a firewall (ZoneAlarm) would protect me from the worm.
I got a DSL connection which is always up, directly connected (no router) to my PC (I've only got one). win2k I also used NAV.
My computer have been acting like I got the worm:
1. svchost.exe failure
2. unexpected reboots
3. cut function in MS Word locks up system
etc etc
But I don't have the f****** worm.exe, cause
1. ZoneAlarm stopped the tftp from connecting to the outside.
2. I don't have any not know .services running under taskman
3. There is no msblast.exe when I look in the registy under ..current\run
4. No files on the hd contains the string "billy why do you make this possible...."
Help me please, is it possible that I got hit on port 135 while the zonealarm was loading during the startup, so it wasn't active?
My computer is still acting strange, I think it's gonna reboot in a little whil.....
cheers
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/6689/21440#21440