Why not register?


Post new topic Reply to topic  [ 13 posts ] 

All times are UTC [ DST ]

Author Message
PostPosted: Mon Jan 03, 2005 8:37 pm  Post subject: Help with registry
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
This should make you chuckle wargand :oops:
I'm in trouble with my registry. I'v recently done a clean install and while doing a security check on my ports found that one was open port 135. I followed the links to these instuctions


Q1 How do I enable or disable DCOM?

A. The HKEY_LOCAL_MACHINE\Software\Microsoft\OLE registry key has "EnableDCOM" as a named value. By default this value is set to "Y." To disable DCOM, change this value to "N." You can do this in the OLE/COM Object Viewer with the File.System Configuration dialog box. Changing this value requires you to restart your computer.

If EnableDCOM is not set to "Y," then all cross-computer calls are rejected (the caller, typically, receives an RPC_S_SERVER_UNAVAILABLE return code).

Now I foolishly tried :oops:
only I dont think i got it right. My pc came up with a message saying probs with RCP and it restarted :wacky:
HELP anyone know of a good reg fixer :beerchug:


Top
 Profile  
PostPosted: Mon Jan 03, 2005 8:45 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
Just got RegistryFix V1.03 free download :D
Is it any good . It say I got 264 problems (but the bitch aint one) :D
Free my ass only fixed 51 probs need to pay for rest


Top
 Profile  
PostPosted: Mon Jan 03, 2005 11:06 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
anybody got any ideas, i got reg mechanic full ran it, said it fixed all probs :D
hour later system shutdown says
windows is restarting because RCP remote call procedure was terminated unexpectedly :cry:


Top
 Profile  
PostPosted: Tue Jan 04, 2005 2:11 am  Post subject:
Reply with quote
a member of the recently deceased
Offline

a member of the recently deceased
Joined: Mon Jul 28, 2003 8:07 am
Posts: 2564
Location: Hell ___________________________ ------ Horror Dealer ------
Never trust those reg fix progs!!!!!!!!!!!!!!!!!!!!

RCP Remote IS NEEDED to run XP properly.

Just close the services you don't need manually and you should be OK.

You'll need to do some research depending on your setup.


Top
 Profile  
PostPosted: Tue Jan 04, 2005 2:43 am  Post subject:
Reply with quote
User avatar
Offline

Mod of the Living Dead
Joined: Fri Nov 22, 2002 4:30 pm
Posts: 3346
Location: Where dead angels lie
Dr Phibes wrote:
anybody got any ideas, i got reg mechanic full ran it, said it fixed all probs :D
hour later system shutdown says
windows is restarting because RCP remote call procedure was terminated unexpectedly :cry:


This means you got one of these sasser/blaster worms that multiply using open port 135. Any firewall is enough to be protected against those things, you don't need to fix your registry or change anything manually. From my experience - no use trying to close port 135, it simply doesn't work on some machines (tried everything, from dedicated registry tools to manual edit). This, however, does not affect your security as long as you keep your firewall running.

If your machine got infected by sasser, this means yor actions must have left it unprotected.

_________________
"When I was a kid we fuckin' respected our parents, we didn't fuckin' eat them!"


Top
 Profile  
PostPosted: Tue Jan 04, 2005 5:04 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
Yes a friend suggested it might b sasser worm. Thing is i know that what i messed with in the reg was connected with RCP. I have since been into Services and under the properties for the RCP I changed the setting to Take no action instead of restart. The thing about the worm is I have tried three different AV the 1 i normally run Symantec AV client fully updated, I downloaded the Stinger from Mc Cafree and i tried onother recomended (FH) AV all found nothing :-o
I did update the firewall (Sygate pro) whem I did the clean install. Also 2what is new is that i cant stop those f**Kin messenger pop ups unless i run Tweak XP all the time. :wacky:
Begining to wish I hadn't bothered with the install now only did it cus i found a sp2 intg copy . This will make u laugh it was dutch ( fumbled my way thru the format ect thinking i could change the language later :oops:
U CANT DO THAT :lol: :lol:
So im back to square 1 or rather my pc was runnin sweet as a nut now its pi**ing me off :-o :eatthis:
anyway thank 4 ur time
:beerchug:


Top
 Profile  
PostPosted: Tue Jan 04, 2005 10:33 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
Sorted out the pop up prob with win update :oops:
Really dont think its sasser worm as went to here
http://vil.nai.com/vil/content/v_125007.htm
alltho i got the system shutdown warning none of the mentioned files,reg entries are there :wacky:
got the removal kit from microsoft and it didn't find anything
anyway this may be connected. I have something called a "defragfat40.exe" trying to connect to "ciberlinkcommunity.kick-ass.net "
The address doesn't exist and defragfat40.exe returns no results in google :o
anyone know what it is ?


Top
 Profile  
PostPosted: Tue Jan 04, 2005 10:40 pm  Post subject:
Reply with quote
User avatar
Offline

Mod of the Living Dead
Joined: Fri Nov 22, 2002 4:30 pm
Posts: 3346
Location: Where dead angels lie
Removal kit from microsoft doesn't necessarily have to work, I had sasser once or twice and removal tools didn't help. The best way is to try and remove it manually, there should be a description on how to do this on the net.

_________________
"When I was a kid we fuckin' respected our parents, we didn't fuckin' eat them!"


Top
 Profile  
PostPosted: Tue Jan 04, 2005 10:56 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
There is on the link above but I cant see the files or reg entries to do it manually
:? :?


Top
 Profile  
PostPosted: Wed Jan 05, 2005 3:40 am  Post subject:
Reply with quote
a member of the recently deceased
Offline

a member of the recently deceased
Joined: Mon Jul 28, 2003 8:07 am
Posts: 2564
Location: Hell ___________________________ ------ Horror Dealer ------
Boot into safe mode then do it.


Top
 Profile  
PostPosted: Wed Jan 05, 2005 6:36 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
Manual Removal Instructions
To remove this virus "by hand", follow these steps:

1. Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
2. Delete the file AVSERVE.EXE from your WINDOWS directory (typically c:\windows or c:\winnt)
3. Edit the registry
* Delete the "avserve" value from
o HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
4. Reboot the system into Default Mode


There is no avserve.exe there is no reg entry :-o
I really dont think i have this worm
the "defragfat40.exe" is the 1 ive deleted it was running at start up and kept trying to connect so i dumped it. No results from google on this one. PC runnin fine at mo


Top
 Profile  
PostPosted: Wed Jan 05, 2005 6:43 pm  Post subject:
Reply with quote
User avatar
Offline

Mod of the Living Dead
Joined: Fri Nov 22, 2002 4:30 pm
Posts: 3346
Location: Where dead angels lie
AFAIK there are many mutations of this worm, each of them uses a different filename of the executable.

_________________
"When I was a kid we fuckin' respected our parents, we didn't fuckin' eat them!"


Top
 Profile  
PostPosted: Wed Jan 05, 2005 9:10 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Sun Apr 18, 2004 5:54 pm
Posts: 1962
Location: UK
Think I got it .Got update to av ran scan and it found WIN32.IRCBOT
It was in c: recycler, that was where i dumped the defarfat40.exe when i started in safe mode . It was named Dc1.exe,my system runs fine without it and a friend checked his syst 32 and he does not have it on his system. So fingers crossed i got the ba****d :eatthis:


Top
 Profile  
Display posts from previous:  Sort by  

All times are UTC [ DST ]

Post new topic Reply to topic  [ 13 posts ] 


Who is online

Users browsing this forum: No registered users and 2 guests


Moderator: Help Mods

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Frontpage / Forums / Scifi


What's blood for, if not for shedding?