Why not register?
|
Page 1 of 1
|
[ 13 posts ] |
|
Author |
Message |
Dr Phibes
|
Posted: Mon Jan 03, 2005 8:37 pm Post subject: Help with registry |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
This should make you chuckle wargand
I'm in trouble with my registry. I'v recently done a clean install and while doing a security check on my ports found that one was open port 135. I followed the links to these instuctions
Q1 How do I enable or disable DCOM?
A. The HKEY_LOCAL_MACHINE\Software\Microsoft\OLE registry key has "EnableDCOM" as a named value. By default this value is set to "Y." To disable DCOM, change this value to "N." You can do this in the OLE/COM Object Viewer with the File.System Configuration dialog box. Changing this value requires you to restart your computer.
If EnableDCOM is not set to "Y," then all cross-computer calls are rejected (the caller, typically, receives an RPC_S_SERVER_UNAVAILABLE return code).
Now I foolishly tried
only I dont think i got it right. My pc came up with a message saying probs with RCP and it restarted
HELP anyone know of a good reg fixer 
|
|
Top |
|
 |
Dr Phibes
|
Posted: Mon Jan 03, 2005 8:45 pm Post subject: |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
Just got RegistryFix V1.03 free download
Is it any good . It say I got 264 problems (but the bitch aint one)
Free my ass only fixed 51 probs need to pay for rest
|
|
Top |
|
 |
Dr Phibes
|
Posted: Mon Jan 03, 2005 11:06 pm Post subject: |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
anybody got any ideas, i got reg mechanic full ran it, said it fixed all probs
hour later system shutdown says
windows is restarting because RCP remote call procedure was terminated unexpectedly 
|
|
Top |
|
 |
satan
|
Posted: Tue Jan 04, 2005 2:11 am Post subject: |
|
a member of the recently deceased Joined: Mon Jul 28, 2003 8:07 am Posts: 2564 Location: Hell ___________________________ ------ Horror Dealer ------
|
Never trust those reg fix progs!!!!!!!!!!!!!!!!!!!!
RCP Remote IS NEEDED to run XP properly.
Just close the services you don't need manually and you should be OK.
You'll need to do some research depending on your setup.
|
|
Top |
|
 |
Polityk
|
Posted: Tue Jan 04, 2005 2:43 am Post subject: |
|
Mod of the Living Dead Joined: Fri Nov 22, 2002 4:30 pm Posts: 3346 Location: Where dead angels lie
|
Dr Phibes wrote: | anybody got any ideas, i got reg mechanic full ran it, said it fixed all probs hour later system shutdown says windows is restarting because RCP remote call procedure was terminated unexpectedly  |
This means you got one of these sasser/blaster worms that multiply using open port 135. Any firewall is enough to be protected against those things, you don't need to fix your registry or change anything manually. From my experience - no use trying to close port 135, it simply doesn't work on some machines (tried everything, from dedicated registry tools to manual edit). This, however, does not affect your security as long as you keep your firewall running.
If your machine got infected by sasser, this means yor actions must have left it unprotected.
_________________ "When I was a kid we fuckin' respected our parents, we didn't fuckin' eat them!"
|
|
Top |
|
 |
Dr Phibes
|
Posted: Tue Jan 04, 2005 5:04 pm Post subject: |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
Yes a friend suggested it might b sasser worm. Thing is i know that what i messed with in the reg was connected with RCP. I have since been into Services and under the properties for the RCP I changed the setting to Take no action instead of restart. The thing about the worm is I have tried three different AV the 1 i normally run Symantec AV client fully updated, I downloaded the Stinger from Mc Cafree and i tried onother recomended (FH) AV all found nothing :-o
I did update the firewall (Sygate pro) whem I did the clean install. Also 2what is new is that i cant stop those f**Kin messenger pop ups unless i run Tweak XP all the time.
Begining to wish I hadn't bothered with the install now only did it cus i found a sp2 intg copy . This will make u laugh it was dutch ( fumbled my way thru the format ect thinking i could change the language later
U CANT DO THAT
So im back to square 1 or rather my pc was runnin sweet as a nut now its pi**ing me off :-o
anyway thank 4 ur time

|
|
Top |
|
 |
Dr Phibes
|
Posted: Tue Jan 04, 2005 10:33 pm Post subject: |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
Sorted out the pop up prob with win update
Really dont think its sasser worm as went to here
http://vil.nai.com/vil/content/v_125007.htm
alltho i got the system shutdown warning none of the mentioned files,reg entries are there
got the removal kit from microsoft and it didn't find anything
anyway this may be connected. I have something called a "defragfat40.exe" trying to connect to "ciberlinkcommunity.kick-ass.net "
The address doesn't exist and defragfat40.exe returns no results in google
anyone know what it is ?
|
|
Top |
|
 |
Polityk
|
Posted: Tue Jan 04, 2005 10:40 pm Post subject: |
|
Mod of the Living Dead Joined: Fri Nov 22, 2002 4:30 pm Posts: 3346 Location: Where dead angels lie
|
Removal kit from microsoft doesn't necessarily have to work, I had sasser once or twice and removal tools didn't help. The best way is to try and remove it manually, there should be a description on how to do this on the net.
_________________ "When I was a kid we fuckin' respected our parents, we didn't fuckin' eat them!"
|
|
Top |
|
 |
Dr Phibes
|
Posted: Tue Jan 04, 2005 10:56 pm Post subject: |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
There is on the link above but I cant see the files or reg entries to do it manually

|
|
Top |
|
 |
satan
|
Posted: Wed Jan 05, 2005 3:40 am Post subject: |
|
a member of the recently deceased Joined: Mon Jul 28, 2003 8:07 am Posts: 2564 Location: Hell ___________________________ ------ Horror Dealer ------
|
Boot into safe mode then do it.
|
|
Top |
|
 |
Dr Phibes
|
Posted: Wed Jan 05, 2005 6:36 pm Post subject: |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
Manual Removal Instructions
To remove this virus "by hand", follow these steps:
1. Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
2. Delete the file AVSERVE.EXE from your WINDOWS directory (typically c:\windows or c:\winnt)
3. Edit the registry
* Delete the "avserve" value from
o HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
4. Reboot the system into Default Mode
There is no avserve.exe there is no reg entry :-o
I really dont think i have this worm
the "defragfat40.exe" is the 1 ive deleted it was running at start up and kept trying to connect so i dumped it. No results from google on this one. PC runnin fine at mo
|
|
Top |
|
 |
Polityk
|
Posted: Wed Jan 05, 2005 6:43 pm Post subject: |
|
Mod of the Living Dead Joined: Fri Nov 22, 2002 4:30 pm Posts: 3346 Location: Where dead angels lie
|
AFAIK there are many mutations of this worm, each of them uses a different filename of the executable.
_________________ "When I was a kid we fuckin' respected our parents, we didn't fuckin' eat them!"
|
|
Top |
|
 |
Dr Phibes
|
Posted: Wed Jan 05, 2005 9:10 pm Post subject: |
|
The Devil, Probably Joined: Sun Apr 18, 2004 5:54 pm Posts: 1962 Location: UK
|
Think I got it .Got update to av ran scan and it found WIN32.IRCBOT
It was in c: recycler, that was where i dumped the defarfat40.exe when i started in safe mode . It was named Dc1.exe,my system runs fine without it and a friend checked his syst 32 and he does not have it on his system. So fingers crossed i got the ba****d 
|
|
Top |
|
 |
 |
Page 1 of 1
|
[ 13 posts ] |
|
Who is online |
Users browsing this forum: No registered users and 2 guests |
Moderator: Help Mods
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|