Forums: Dcom Worm Killer 2.0 - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Dcom Worm Killer 2.0 killing the dcom worm

#1 User is offline   Kenny 

  • Commander In Chief
  • Icon
  • Group: Admin
  • Posts: 6,447
  • Joined: 18-August 06

Posted 17 August 2003 - 05:12 PM

excellent illwill ...thanks mate B)
Kenny aka ComSec

Please read the Forum Rules !!!

Blog

" http://kaltech.blogspot.com/ "

______________________
0

#2 User is offline   illwill 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 540
  • Joined: 28-July 03

Posted 15 August 2003 - 06:25 PM

http://illmob.org/rp...aners/dcom2.zip

kills and removes the blaster worm and the b and c variants of it. all in a pretty little package of 1.62kb (gotta love assembly)

Coded in MASM by:
illwill
xillwillx@yahoo.com
www.illmob.org


DCOM worm killer (W32.Blaster.Worm)
Aliases: W32/Lovsan.worm [McAfee], Win32.Poza [CA], Lovsan [F-Secure]
WORM_MSBLAST.A [Trend], W32/Blaster-A [Sophos], W32/Blaster [Panda]
WORM_MSBLAST.B [Trend], Win32.Poza.C [CA], W32/Lovsan.worm.c [McAfee], Worm.Win32.Lovesan [KAV]
etc..... blablablabla keep changing it (filtered)s we'll still find yer ass :)


This program is a tool to remove the malicious worm(s)
that spread through exploiting the DCOM RPC vulnerability using TCP port 135.
This worm attempts to download the msblast.exe file to the %WinDir%\system32 directory and execute it.
Once executed it creates a hidden Cmd.exe remote shell that will listen on TCP port 4444,
allowing an attacker to issue remote commands on the infected system.
This tool was made to Automate the process of removing the worm from memory and all files related to it.

-------------------------------------------------------------------------
Directions:
1. Execute the file called DCOM2.exe
a. Deletes the registry values that have been added.
b. Terminates the W32.Blaster.Worm, W32.Blaster.B.Worm, and W32.Blaster.C.Worm viral processes.
c. Deletes the W32.Blaster.Worm, W32.Blaster.B.Worm and W32.Blaster.C.Worm files.
d. Deletes the dropped files.

-------------------------------------------------------------------------
Tech Info:
Startup registry keys-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"windows auto update"="msblast.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"windows auto update"="penis32.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Microsoft Inet Xp.."="teekids.exe"

Dropped files-
Windows system directory (c:\windows\system32 c:\winnt\system32)
'msblast.exe' 'penis32.exe' 'teekids.exe' 'root32.exe' 'index.exe'

Source:
http://illmob.org/sources/DCOM2.html
http://illmob.org/sources/DCOM2.asm
0

#3 User is offline   virus 

  • Specialist
  • Icon
  • Group: Members
  • Posts: 506
  • Joined: 05-July 03

Posted 15 August 2003 - 08:01 PM

Now this is a quality post illwill. Thanks for sharing it ;)
0

#4 User is offline   woutiir 

  • Corporal
  • Icon
  • Group: Specialist
  • Posts: 161
  • Joined: 31-July 03

Posted 16 August 2003 - 07:39 AM

Hey illwill,
nice to see ya here. And thnx for the post, i already saw it. Should help alot of ppl out.

nice ASM code btw.

Cheers,
woutiir
0

#5 User is offline   SLiM577 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 83
  • Joined: 30-November 03

Posted 06 December 2003 - 11:25 AM

that site is down mate.
0

#6 User is offline   KoStIsTR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 28
  • Joined: 01-December 03

Posted 07 December 2003 - 01:16 AM

I think removing msblast from your pc it too easy so you can do it manually :)
As the article says the vers of msblast are quiet few...but the way of disinfection is always the same :P . The only thing you have to do is to shut the worm from the proccess then open regedit and delete the keys that article says :

Quote

Startup registry keys-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"windows auto update"="msblast.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"windows auto update"="penis32.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Microsoft Inet Xp.."="teekids.exe"
after this make a search at your system32 folder for this names :

Quote

Dropped files-
Windows system directory (c:\windows\system32 c:\winnt\system32)
'msblast.exe' 'penis32.exe' 'teekids.exe' 'root32.exe' 'index.exe'

and delete them.
Simple heh? :)
0

#7 Guest_biboupoki_*

  • Group: Guests

Posted 07 December 2003 - 06:44 PM

thanx for the information
0

#8 User is offline   ST. 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 94
  • Joined: 29-December 03

Posted 30 December 2003 - 01:53 PM

link is down
0

#9 User is offline   as0l0 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 248
  • Joined: 14-September 03

Posted 30 December 2003 - 04:32 PM

can / will this work remotely?

in other words can I set it against a remote machine or a number of remote machines to clean blaster remotely?
0

#10 Guest_headbanger_*

  • Group: Guests

Posted 01 January 2004 - 10:38 AM

very nice tool illwill!
0

#11 Guest_polax_*

  • Group: Guests

Posted 09 January 2004 - 04:42 PM

thanx for the info
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting