Results 1 to 16 of 16

Thread: I Think I Might Have a Virus. Any Ideas on what it is?

  1. #1

    Thread Starter
    Hyperactive Member VBD's Avatar
    Join Date
    Apr 2001
    Location
    The Place Above The Place Below Heavin
    Posts
    278

    I Think I Might Have a Virus. Any Ideas on what it is?

    Well, I was viewing the website "Computer Stupidities", and suddenly a little box came up that said: "The RPC Service has exited. your machine will reboot in 60 seconds", Then the seconds part counts down and restarts my computer at zero. So, the second time, and third time i'm viewing this website, it does that. I know the reboot part is part of Windows XP, but the RPC Service Exiting could be a virus. Next, After about 3 of these reboots, and I stop using that website. The reboots stop. Then, on start up, it says: "Windows does not know what program to load TFTP98 with". I never installed anything new, so I have no idea how that even got there. I disable it with MSConfig, reboot, and when the computer starts up again, TFTP98 tries to load again. This time, I try to run msconfig. As sxoon as msconfig comes up, it dissapears as if somethihng is trying to shut it down. The same with Ctrl+Alt+Delete, or any other file that controls proccesses. I tried Avast 32(my virus scanner) and it didn't pick up anything. Does anybody have any idea what could be wrong and how to fix it?
    Hello

  2. #2
    So Unbanned DiGiTaIErRoR's Avatar
    Join Date
    Apr 1999
    Location
    /dev/null
    Posts
    4,111
    There was a bug in IE and RPC that let a malicious webpage or even a remote user get Admin privleges on your box.

    I'd go get the windows updates.

    Then scan your start-ups for trojans.

  3. #3
    So Unbanned DiGiTaIErRoR's Avatar
    Join Date
    Apr 1999
    Location
    /dev/null
    Posts
    4,111
    Check out this thread:

    http://www.vbforums.com/showthread.p...hreadid=255977

    Another user had a similar problem.

    Near the bottom is a list of start-up locations.

  4. #4

    Thread Starter
    Hyperactive Member VBD's Avatar
    Join Date
    Apr 2001
    Location
    The Place Above The Place Below Heavin
    Posts
    278

    Thanx

    I'll check it out.
    Hello

  5. #5

    Thread Starter
    Hyperactive Member VBD's Avatar
    Join Date
    Apr 2001
    Location
    The Place Above The Place Below Heavin
    Posts
    278

    Closes Regedit.exe when I try to run that too./

    I'm gonna test out safe mode...
    Hello

  6. #6
    KrisSiegel.com Kasracer's Avatar
    Join Date
    Jul 2003
    Location
    USA, Maryland
    Posts
    4,985
    Originally posted by DiGiTaIErRoR
    There was a bug in IE and RPC that let a malicious webpage or even a remote user get Admin privleges on your box.

    I'd go get the windows updates.

    Then scan your start-ups for trojans.
    There is NO BUG in IE that allows this to be done, it is a bug in the RPC service itself.

  7. #7
    So Unbanned DiGiTaIErRoR's Avatar
    Join Date
    Apr 1999
    Location
    /dev/null
    Posts
    4,111
    Originally posted by kasracer
    There is NO BUG in IE that allows this to be done, it is a bug in the RPC service itself.
    There was a bug, which a patch fixes, which would allow a malicious website to execute code on your machine. There is also an exploit to make you download a file, which then can be executed.

  8. #8
    KING BODWAD XXI BodwadUK's Avatar
    Join Date
    Aug 2002
    Location
    Nottingham
    Posts
    2,176
    You can download a fix from antivirus places
    If you dribble then you are as mad as me

    Lost World Creations Website (XBOX Indie games)
    Lene Marlin

  9. #9
    Monday Morning Lunatic parksie's Avatar
    Join Date
    Mar 2000
    Location
    Mashin' on the motorway
    Posts
    8,169
    The RPC bug is remotely exploitable.
    I refuse to tie my hands behind my back and hear somebody say "Bend Over, Boy, Because You Have It Coming To You".
    -- Linus Torvalds

  10. #10
    KrisSiegel.com Kasracer's Avatar
    Join Date
    Jul 2003
    Location
    USA, Maryland
    Posts
    4,985
    Originally posted by DiGiTaIErRoR
    There was a bug, which a patch fixes, which would allow a malicious website to execute code on your machine. There is also an exploit to make you download a file, which then can be executed.
    The RPC exploit and anything with IE are NOT related.

  11. #11
    Hyperactive Member Radames's Avatar
    Join Date
    Feb 2001
    Location
    Tech Tropics
    Posts
    360
    Sounds like you have the blaster worm friend. Go to
    http://www.microsoft.com/technet/tre.../msblaster.asp

  12. #12

    Thread Starter
    Hyperactive Member VBD's Avatar
    Join Date
    Apr 2001
    Location
    The Place Above The Place Below Heavin
    Posts
    278
    Yup thats exactly what it was.
    Hello

  13. #13
    ^:^...ANGEL...^:^ wrack's Avatar
    Join Date
    Mar 2002
    Location
    Melbourne, AUSTRALIA
    Posts
    2,695
    If you have a good antivirus and firewall then this would have never happened.

  14. #14
    Monday Morning Lunatic parksie's Avatar
    Join Date
    Mar 2000
    Location
    Mashin' on the motorway
    Posts
    8,169
    Even without them, just patching with the patch that was released at least a week in advance would have saved you.
    I refuse to tie my hands behind my back and hear somebody say "Bend Over, Boy, Because You Have It Coming To You".
    -- Linus Torvalds

  15. #15

    Thread Starter
    Hyperactive Member VBD's Avatar
    Join Date
    Apr 2001
    Location
    The Place Above The Place Below Heavin
    Posts
    278

    Bad Luck

    I'd just formatted my PC cause I hadn't since 2001 when I bought it. I got it before I had time to downlaod all the updates. I probably should have download the Virus patches before SP1...
    Hello

  16. #16
    KrisSiegel.com Kasracer's Avatar
    Join Date
    Jul 2003
    Location
    USA, Maryland
    Posts
    4,985
    Originally posted by parksie
    Even without them, just patching with the patch that was released at least a week in advance would have saved you.
    That makes me laugh. A week in advanced? Try 2 months ago. The patch for the RPC exploit was released over 2 months ago

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width