Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: Secure.dcom.exe
.

  • To: "Lee Evans" <[EMAIL PROTECTED]>
  • Subject: Re: Secure.dcom.exe
  • From: Sorin Victor DUDEA <[EMAIL PROTECTED]>
  • Date: Fri, 8 Aug 2003 09:25:26 +0300
  • Cc: [EMAIL PROTECTED]
  • In-reply-to: <[EMAIL PROTECTED]>
  • Organization: SC Softwin S.R.L.
  • References: <[EMAIL PROTECTED]>
  • Reply-to: Sorin Victor DUDEA <[EMAIL PROTECTED]>
.
 
Hello Lee,

      That file is not malware. It is a DCOM disabler.
      It sets the key EnableDCOM from
      HKLM\Software\Microsoft\Ole\ to 'N'. By this the computer is
      immune to the RPC/DCOM exploit.

Wednesday, August 6, 2003, 1:50:13 PM, you wrote:

LE> Hi All,

LE> I have found an executable called secure.dcom.exe when looking around a
LE> customers server. They hadnt patched the server above SP4 and I assume it
LE> has been exploited using the RPC DCOM vulnerability. A serv-u ftp server has
LE> been installed, but im still looking into it to see if I can spot anything
LE> else. Netstat shows a bunch of outgoing connections to 6667 -
LE> irc.homelien.no. Unfortunately there are no IDS or other systems on this
LE> network segment I can use, so im looking for someway to capture this traffic
LE> and hopefully track down some more details on the irc traffic - if anyone
LE> can recommend a good (preferably free) traffic sniffer I can quickly install
LE> on the host locally (win2k sp4) to decode the IRC traffic I would be
LE> grateful.

LE> The exe is available from http://www.leeevans.org/secure.dcom.exe - if
LE> anyone wants a look. I'd be interested to know more about it, if anyone has
LE> come across it before or can find out.

LE> Regards
LE> Lee



-- 
Best regards,
     Sorin Victor Dudea
     BitDefender Head of Antivirus Research
     E-mail: [EMAIL PROTECTED], [EMAIL PROTECTED]

     www.bitdefender.com
     www.softwin.ro


---------------------------------------------------------------------------
----------------------------------------------------------------------------


 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.