|
[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]
Re: Secure.dcom.exe |  |
- To: "Lee Evans" <[EMAIL PROTECTED]>
- Subject: Re: Secure.dcom.exe
- From: Sorin Victor DUDEA <[EMAIL PROTECTED]>
- Date: Fri, 8 Aug 2003 09:25:26 +0300
- Cc: [EMAIL PROTECTED]
- In-reply-to: <[EMAIL PROTECTED]>
- Organization: SC Softwin S.R.L.
- References: <[EMAIL PROTECTED]>
- Reply-to: Sorin Victor DUDEA <[EMAIL PROTECTED]>
 |
| |
Hello Lee,
That file is not malware. It is a DCOM disabler.
It sets the key EnableDCOM from
HKLM\Software\Microsoft\Ole\ to 'N'. By this the computer is
immune to the RPC/DCOM exploit.
Wednesday, August 6, 2003, 1:50:13 PM, you wrote:
LE> Hi All,
LE> I have found an executable called secure.dcom.exe when looking around a
LE> customers server. They hadnt patched the server above SP4 and I assume it
LE> has been exploited using the RPC DCOM vulnerability. A serv-u ftp server has
LE> been installed, but im still looking into it to see if I can spot anything
LE> else. Netstat shows a bunch of outgoing connections to 6667 -
LE> irc.homelien.no. Unfortunately there are no IDS or other systems on this
LE> network segment I can use, so im looking for someway to capture this traffic
LE> and hopefully track down some more details on the irc traffic - if anyone
LE> can recommend a good (preferably free) traffic sniffer I can quickly install
LE> on the host locally (win2k sp4) to decode the IRC traffic I would be
LE> grateful.
LE> The exe is available from http://www.leeevans.org/secure.dcom.exe - if
LE> anyone wants a look. I'd be interested to know more about it, if anyone has
LE> come across it before or can find out.
LE> Regards
LE> Lee
--
Best regards,
Sorin Victor Dudea
BitDefender Head of Antivirus Research
E-mail: [EMAIL PROTECTED], [EMAIL PROTECTED]
www.bitdefender.com
www.softwin.ro
---------------------------------------------------------------------------
----------------------------------------------------------------------------
| |