Poll: Have you been been hit with the RPC worm?

hopeless879

Senior member
Mar 4, 2002
900
0
0
Just wondering how many of you people have gotten infected with this.

My computer didn't, but my families computer did.
 

arod

Diamond Member
Sep 26, 2000
4,236
0
76
Havent been hit but I know almost everybody I know has.... but IMO this is good... it will scare the "end" users into running updates more frequently. The only reason this is so widespread is laziness of people.
 

Skyclad1uhm1

Lifer
Aug 10, 2001
11,383
87
91
Nope, virusscanner/firewall combo seems to have done its job.

A colleague of mine just walked in a minute ago asking me whether I knew what the problem could be with his home system suddenly shutting down :p
 

isaacmacdonald

Platinum Member
Jun 7, 2002
2,820
0
0
I don't know if I should be concerened. I haven't applied the patch, but I'm behind two different firewalls/nat devices-
 

Viper GTS

Lifer
Oct 13, 1999
38,107
433
136
ffmcobalt had a hell of a time with his system yesterday, he re-installed windows four times before calling me. If it weren't for the sticky in OT I wouldn't have known the answer.

All the systems I use are heavily firewalled, I don't get hit by much of anything.

Viper GTS
 

Mr N8

Diamond Member
Dec 3, 2001
8,793
0
76
1 of 2 computers at home got hit. The one with Nav Corp 8.1 was fine, the one with AVG got nailed.
 

iamme

Lifer
Jul 21, 2001
21,058
3
0
my PCs weren't affected.

a friend's PC was. i helped him patch it and then blamed him for downloading too much porn ;)
 

Czar

Lifer
Oct 9, 1999
28,510
0
0
voted for nobody, but I know of one person at work who has it at home, will fix it tomorrow
 

hopeless879

Senior member
Mar 4, 2002
900
0
0
Originally posted by: jjsole
those who got it how are you getting rid of it?

So far what I've done is when I boot up I quickly go into the Services menu and change the action that happens when RPC fails to start from Shutdown system, to restart service. This stops your comp from shutting down, but it doesnt fix anything. Then I downloaded the patch from the MS site, look through some of the threads, you'll find a link. Then ran adaware. Then went to sleep for awhile because I was tired. Today when I get home from work I'm going to scan for virii and install a new firewall.
 

MrBond

Diamond Member
Feb 5, 2000
9,911
0
76
Originally posted by: Viper GTS
ffmcobalt had a hell of a time with his system yesterday, he re-installed windows four times before calling me. If it weren't for the sticky in OT I wouldn't have known the answer.
People have been getting hit lightly with this since last week. There's been a bunch of threads both in OT and Software about it. Only yesterday did it really go widespread. I don't think the things people were noticing last week were this worm, but they were definatly system exploits.

I don't understand why the virus companies/white hat hackers don't write a worm to fix this. How hard would it be to have the worm download and execute the RPC patch. Then just spread the worm around and it self propagates, fixing systems without people even knowing.

I guess the virus companies wouldn't sell as many copies of their programs then.

 

Lonyo

Lifer
Aug 10, 2002
21,938
6
81
I haven't been hit by it, somehow.
No virus scanner, no firewall.
Had hits coming in on 135 in the 10 mins since I DID install a Firewall, so I'm guessing that I was getting hit, but Windows updates did their job :eek:
 

KingNothing

Diamond Member
Apr 6, 2002
7,141
1
0
Originally posted by: hopeless879
Originally posted by: jjsole
those who got it how are you getting rid of it?

So far what I've done is when I boot up I quickly go into the Services menu and change the action that happens when RPC fails to start from Shutdown system, to restart service. This stops your comp from shutting down, but it doesnt fix anything. Then I downloaded the patch from the MS site, look through some of the threads, you'll find a link. Then ran adaware. Then went to sleep for awhile because I was tired. Today when I get home from work I'm going to scan for virii and install a new firewall.

I just checked the RPC entries (Win2K SP3) and they're set to "Take No Action". Maybe the updates did that, I don't know. I've been getting several hits on port 135 as well.
 

slag

Lifer
Dec 14, 2000
10,473
81
101
I haven't and frankly, I dont see how others have.

Anyone , either SA or home user, who is worth a sh|t should be checking for patches on a weekly basis and updating their virus scanners weekly as well.

"Emergencies" like this bother me since they shouldnt even be happening in the first place.
 

stonecold3169

Platinum Member
Jan 30, 2001
2,060
0
76
I got hit by it, and really don't know how. Well, rather, I know how, just not, you know, how. My roomate and I are sharing a cable connection with a linksys router, and he always has dmz enabled on his side of things (dumb, dumb dumb, I know). So he got it, and then I got it through him I would guess (Everything would go to his comp because of the DMZ, not mine, right?).

However, I have zone alarm running as well on my comp, and I definitely never got a prompt telling me there was a breech, and I didn't have anything but IE, Opera, AIM, bnet set to send or receive automatically... kinda creeps me out, but all better now.
 

FoBoT

No Lifer
Apr 30, 2001
63,084
15
81
fobot.com
the MS windows update site is getting HAMMERED, i have never seen it this slow, billions of people must be downloading years worth of patches/service packs

funny how so many complain about MS security, but don't bother to take advantage of the patches they supply

hmmmm.....