SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


W32/Lovsan.worm Blaster/MSBlaster - Remote Procedure Call - Repeatedly re-booting

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 08-16-2003, 04:50 AM
The Tool's Avatar
The Tool Offline
Mod
 
Join Date: Feb 2002
Location: LaLa Land
Posts: 918
W32/Lovsan.worm Blaster/MSBlaster - Remote Procedure Call - Repeatedly re-booting

W32/Lovsan.worm is a Medium-On-Watch Internet Worm. Also known as "Blaster" or "MSBlaster", Lovsan has quickly infected computers throughout the Internet. The worm takes advantage of a flaw in Windows NT, 2000 and XP operating systems to drop a malicious program on your computer.
Unlike typical computer viruses, which usually arrive as email attachments, Internet worms attack open communication ports on vulnerable systems, often without the operator's knowledge. By taking advantage of a vulnerability in Windows, the worm is able to spread without requiring any action on the part of the user.

How do you know if you've been infected?
Generally, the Lovsan worm causes your system to repeatedly re-boot itself every few minutes. Windows NT 4.0 and Windows 2000 systems may become unresponsive. Also, the file msblast.exe appears in the WINDOWS SYSTEM32 directory.

How do you clean your system if it’s already infected?
Download McAfee Stinger

How do you prevent future attacks?
1. Update Windows
2. Update your anti-virus software. Always ensure your virus definition DAT files are current.
3. Firewall - This secure barrier fortifies your Internet defenses against malicious cyber code and hackers, helping block Internet worms like Lovsan before they invade your system.

More @ Microsoft: http://www.microsoft.com/security/incident/blast.asp
__________________
If you can't convince them, confuse them!

Last edited by The Tool : 08-25-2003 at 04:47 AM.
Reply With Quote

  #2  
Old 08-19-2003, 03:11 PM
Fraz's Avatar
Fraz Offline
Junior Member
 
Join Date: May 2003
Location: England
Posts: 16
asdf

Thanks, nice post.
__________________
Wear the Grudge like a Crown of Negativity...
Reply With Quote

  #3  
Old 08-22-2003, 09:56 AM
baronsaemdi Offline
Junior Member
 
Join Date: Aug 2003
Posts: 1
Good Info

thanks good info keep up the good work
Reply With Quote

  #4  
Old 09-01-2003, 10:20 AM
Firebrand Offline
Junior Member
 
Join Date: Apr 2003
Location: Northern Ireland
Posts: 8
Cheers in abundance!
Reply With Quote

  #5  
Old 09-20-2003, 11:45 PM
jd_surat Offline
Junior Member
 
Join Date: Sep 2003
Location: Melbourne
Posts: 2
Send a message via AIM to jd_surat Send a message via Yahoo to jd_surat
Unhappy Trouble

hi,
I am geting the same trouble you indicated above. But as i m getting througf it i am finding some other viruses. I got this problem when i upgrade my windows XP Home To Windows XP Pro.
I got problem while i connected to inetrnet. First it says that there is a problem in SVCHost.exe. Then A message window pop up. It says that it is from NT AUTHORITY / SYSTEM & i have to shut system in 1 min. Also timer displayed on that window. Also i cant get rid of that window. I (forcibly)have to restart system.
Then i format my Harddisk & install Fresh Windows XP Pro. After that i connected to net first time & same problem presisted.
So, when i searched i found that it is W32.Welchia.Worm. Now This Worm do the above things as per symantec says. Also it tries to remove MSblast virus. But i found W32.WElchia.Worm when i sacnned first time & removed that. Then when i run Virus Scanning (with fully updated Virus Definations) i found MSBlast.
So, the problem is i am not getting rid of this viruses. They are poping up after i remove them.
Please Help me.
Thanks in advance.
Reply With Quote

  #6  
Old 09-21-2003, 02:00 AM
sami Offline
Junior Member
 
Join Date: Sep 2003
Posts: 9
First, virus Velchia can not be removed by scan, u must download a fix tool for that, and for Blaster virus too. Since u say u have blaster, and as we saw in first post the ways he behaves, first thing u should do is to stop the process that starts it. Then execute the fixtool that u can download at www.symantec.com in the section of virus removal tools. Then u can say u have removed them from the computer. As u say that these viruses keep rolling over in your computer, i wonder if u r connected on LAN with other users, because Velchia spreads itself like that too in nonprotected computers.
hope this will help u
__________________
every problem has it's solution
Reply With Quote

  #7  
Old 09-21-2003, 06:30 AM
ESALADUANE's Avatar
ESALADUANE Offline
Senior Member
 
Join Date: Nov 2002
Location: Minneapolis, Minnesota, USA
Posts: 2,003
I does little good to remove the virus if you're still vulnerable to re-infection as soon as you reconnect to the internet. You need a firewall that blocks the relevant ports and you need to download the patch. You must do these things before using the removal tool.



This is from Microsoft:

Step 1: Enable your firewall (the native XP one if you don't have another one).

Step 2: Download the patch from Microsoft (this patch replaces 823980).
http://support.microsoft.com/default.aspx?kbid=824146

Step3: Install or update your anti-virus program

Step 4: Download the worm removal tool for W32.Blaster.Worm
http://securityresponse.symantec.com...oval.tool.html



If you have Windows 2000, which doesn't have a firewall, follow these steps for Step 1.

--Select "Network and Dial-up Connections" in the control panel.
--Right-click the interface you use to access the Internet, and then click "Properties".
--In the "Components checked are used by this connection" box, click "Internet Protocol (TCP/IP)", and then click "Properties".
--In the Internet Protocol (TCP/IP) Properties dialog box, click "Advanced".
--Click the "Options" tab.
--Click "TCP/IP filtering", and then click "Properties".
--Select the "Enable TCP/IP Filtering (All adapters)" check box.
--There are three columns with the following labels:

TCP Ports
UDP Ports
IP Protocols

--In each column, you must select the "Permit Only" option.
--Click OK.
Reply With Quote

  #8  
Old 10-09-2003, 03:46 PM
techsupport's Avatar
techsupport Offline
Junior Member
 
Join Date: Oct 2003
Location: India
Posts: 3
well reinstalling windows XP after formatting the HDD wont be of much help because the virus hits the computer again. All you need to do is that after running fixblast.exe from Microsoft and als there is a security patch that needs to be downloaded. This will resolve the issue. Also have the latest Antivirus installed on your computer which has all the latest security updates.
__________________

"Breaking the thought barrier"


Technical Support
Reply With Quote

  #9  
Old 10-19-2003, 02:14 PM
ZeB's Avatar
ZeB Offline
Junior Member
 
Join Date: Oct 2003
Location: Canada
Posts: 7
DCOM exploit

Everyone should also note that this is a DCOM RPC security exploit, and DCOM should be disabled to prevent further infection.

From Microsoft:

"The Distributed Component Object Model (DCOM) is a protocol that enables software components to communicate directly over a network in a reliable, secure, and efficient manner."

Yeah right!

To diable DCOM, open a RUN dialogue box and type 'dcomcnfg'. Expand 'Component Services', then 'Computers'. Right-click on 'My Computer' and choose 'Properties'. Click on the 'Default Properties' tab, and uncheck the 'Enable Distributed COM on this computer'. Click 'Ok', and then restart your system.

Doing this along with the other steps outlined in this thread will help prevent further infection against all Blaster variations and the Nachi worm as well.

Ciao!
__________________
--
Intel Celeron 950MHz
768MB PC133 RAM (3x256MB Kingston KVR133x64C3)
ASUS P2B-VT (VIA Apollo Pro133)
nVIDIA GeForce2 MX400 4x AGP (32MB)
40GB Maxtor HDD (94098U8 5400rpm ATA-100)
40GB Maxtor HDD (4D040H2 5400rpm ATA-100)
HP CD-Writer Plus! (4x4x24)
Toshiba SD-M1302 DVD-ROM (8x)
Sound Blaster Live! 5.1
Windows XP Pro (SP1)
Reply With Quote

  #10  
Old 11-14-2003, 03:47 AM
ZeuSueZ's Avatar
ZeuSueZ Offline
Junior Member
 
Join Date: Nov 2003
Location: Cph. DEN
Posts: 1
Send a message via ICQ to ZeuSueZ
Arrow

If you are having problems with the RPC showing while working the fix, simpley press the start button -> run -> type : 'shutdown -a' --- without '

This command will terminate the current application trying to shutdown Windows, and you can do it over and over again, until the repair process is completed.

//Z
__________________
Real men don't do backup...
...real men cry ALOT!
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Remote Procedure Call (RPC) Service help ]v[atriX Windows XP 4 10-22-2009 11:36 AM
Remote Procedure Call andriese@wxs.nl Windows XP 2 08-25-2003 04:31 AM
Generic Host Process and Remote Procedures Call ArchEagleJ Windows XP 1 08-13-2003 06:41 AM
Error occured while launching the setup the remote procedure call failed moffa Windows XP 0 01-27-2003 01:56 PM
an error occured while launching the setup the remote procedure call failed M374llic4 Windows XP 1 11-10-2002 01:07 PM



All times are GMT -5. The time now is 03:46 AM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.