Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

[SID 23179] MSRPC Server Service BO detected

Updated: 27 Aug 2010 | 29 comments
sc345908's picture
0 0 Votes
Login to vote

I keep getting an alert from Endpoint saying that traffic from ip address .... is blocked

[SID 23179] MSRPC Server Service BO detected

I was just wondering what this means and how I can fix it.  It is always the same address and has been occuring more often the past week.

Comments

Paul Mapacpac's picture
23
Mar
2009
0 Votes 0
Login to vote

Re;

Can you post some event logs, or run diagnostic tool from symantec on the PC then post it here? We need to identify this..

sc345908's picture
24
Mar
2009
0 Votes 0
Login to vote

When I run a virus scan, even

When I run a virus scan, even in safe mode, nothing is found.  I just continue to get the alert from the icon in the lower right hand cornor.  What should I run on my computer?

Sandeep Cheema's picture
24
Mar
2009
0 Votes 0
Login to vote

Did you inspect the machine

Did you inspect the machine that had been backtracked and run a full scan on it?

De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey!  I found a virus!  Look at me!  I'm soooo goooood!"

sc345908's picture
24
Mar
2009
0 Votes 0
Login to vote

how would i do this?

how would i do this?

Sandeep Cheema's picture
24
Mar
2009
0 Votes 0
Login to vote

The IP address that is being

The IP address that is being detected, Is that in your domain?

If it is, Narrow down on to where the machine physically is located. Take it off the network. Run a full scan on it.

De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey!  I found a virus!  Look at me!  I'm soooo goooood!"

Sandeep Cheema's picture
24
Mar
2009
0 Votes 0
Login to vote

The IP address that is being

The IP address that is being detected, Is that in your domain?

If it is, Narrow down on to where the machine physically is located. Take it off the network. Run a full scan on it.

De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey!  I found a virus!  Look at me!  I'm soooo goooood!"

Paul Mapacpac's picture
24
Mar
2009
0 Votes 0
Login to vote

Re;

As what Sandeep said, locate it from the network. This could be a misleading application infection.

Tejas Shah's picture
26
Mar
2009
0 Votes 0
Login to vote

One machine on the network is

One machine on the network is infected and is trying to spread. (Whoc IP is shown on other machines)

Remove infected machine.

Tejas

Sadis's picture
01
Apr
2009
0 Votes 0
Login to vote

Re;

I also getting alert like this and I found w32.downadup.B try to spreads in my network system.

Paul Mapacpac's picture
15
Apr
2009
0 Votes 0
Login to vote

Hi,

Run the downadup removal tool on all workstations...

dhayal's picture
16
Apr
2009
0 Votes 0
Login to vote

i am using Symantec endpoint

i am using Symantec endpoint MR3 for my 500 client ...... I did all the steps which you guys are discussing..... i think Symantec is just useless product ......

Symantec unable to remove W32.downadup.b......

SAM_SHAIKH's picture
16
Apr
2009
0 Votes 0
Login to vote

hi Dhayal, I would suggest

hi Dhayal,

I would suggest you Run a manual scan on all of your machine from SEPM.

RightClick on your Group> Scan the computers.

Make sure all you rmachines are having latest definition and MS08-067 vulnerabitility is been patched.

Temporary disable ADMIN$ share in your network. Ask user to disable OPen shares in there machines and change password every 45 days. the password must be tough and not simple dictionary words.

I know its little bit lenghty procedure, but you need to follow to remove the same.

Rgrds,
SAM

Symantec World's picture
16
Apr
2009
0 Votes 0
Login to vote

Re

Hi Sc,

Can you please share the security logs here?

Regards, M.R

dhayal's picture
16
Apr
2009
0 Votes 0
Login to vote

thanks SAM ..... but i


thanks SAM ..... but i already did these steps .....what next ???... i have very wide range network ..

SAM_SHAIKH's picture
17
Apr
2009
0 Votes 0
Login to vote

Hi, Pls Log a case with

Hi,

Pls Log a case with Symantec team,. They will provide you with the Loadpoints. Run the Loadpoint and submit the same. They will further ask you to send the suspicious files to SEcuroty Response team.

I think it is a NEW VARIANT.

Rgrds,
SAM

Tejas Shah's picture
20
Apr
2009
0 Votes 0
Login to vote

When I run a virus scan

When I run a virus scan, even in safe mode, nothing is found. I just continue to get the alert from the icon in the lower right hand cornor.

dhayal's picture
20
Apr
2009
0 Votes 0
Login to vote

logs

this is the logs which i found very time on windows server 2003 ... its very time attacking on server 2003 only ....

Risk,Filename,Original Location,Status,Date
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 5:16 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 6:21 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 6:21 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 6:34 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 7:48 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 9:01 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 10:17 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 11:31 PM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 12:48 AM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 1:58 AM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 3:13 AM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 4:29 AM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 5:44 AM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 6:59 AM
W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 8:16 AM

Peter_007's picture
20
Apr
2009
0 Votes 0
Login to vote

The system with that IP

The system with that IP address must be in your domain.
Physically locate them.Remove their network connection.Check that virus defination is updated or not. Then run full scan on system to be on safer side. 

Vikram Kumar-SAV to SEP's picture
20
Apr
2009
0 Votes 0
Login to vote

[SID 23179] MSRPC Server Service BO detected

Downadup uses this vulnerability in windows.Mke sure all your computers are patched with patch KB 958644
Check the security logs and Isolate the computer fro which you are getting these attacks.
Make sure these computers have all the features installed with updates definitions and windows security patches.

binayak's picture
22
Apr
2009
0 Votes 0
Login to vote

Try to findout the infected

Try to findout the infected computer by its IP address and clean it. For downadup please download the removal tool, disable the system resoter point, detach the computer from network, log on to safe mode and then run the tool.

M Samir0n's picture
22
Apr
2009
0 Votes 0
Login to vote

some time it is showing

some time it is showing external ip & some time internal ip

binayak's picture
22
Apr
2009
0 Votes 0
Login to vote

Have you tried it? What is

Have you tried it? What is the update?

ladybucaneer's picture
13
Aug
2009
0 Votes 0
Login to vote

MSRPC server started

I am having this same problem with my PC. I have run scans and it keeps popping up. The IP address's that are being blocked are from multiple PC's. Where is the removal tool to download that you spoke of?

Jackie

cable mite's picture
14
Aug
2009
0 Votes 0
Login to vote

[SID 23179] MSRPC Server Service BO detected

Whats the confusion?
What I do is export my NTP logs with it filtered to show only Intrustion Prevention.
An remote hosts mentioned in lines with [SID 23179] MSRPC Server Service BO detected are surely infected with Downadup. There are no cases of false alarms.

You need to get hold of the remote host

1) Check that all members of the Administrators group have a PROPER password. If you are skipping this step you are wasting your time.

2) Ensure System Restore is turned off if its a desktop OS

3) clean it up using the removal tool
http://www.symantec.com/content/en/us/global/remov...

4) Put the MS Patch refer to KB958644 for that OS. Also ensure that SEP client is running or needs to be reinstalled.

5) Educate all IT staff if its a remote location that when they rebuild PCs for any reason, they need to ensure all the above is done.

------------------------------------------------------------
MR99 will fix it all.

Optimus Prime's picture
10
Sep
2009
2 Votes -2
Login to vote

To add MSRPC 23179

To add MSRPC 23179 exception.

1.Go to Policies --> Intrusion Prevention Policies
2.Right Click Edit --> On the Exceptions tab
3.Click Add --> Look for the ID 23179
4.click Next
5. On the Signature Action select "Allow" and click OK.

If you want to disable the notification on your system tray..

1. Go to Clients, then the client group you want to remove this ability from.
2. Click the Policies tab on the right, then expand 'Location-specific Settings'.
3. Click on 'Server Control', then Customize.
4. In the Intrusion Prevention Notifications Uncheck the "Display Intrusion Prevention notifications."

;-)

yvrjzala@yahoo.co.in's picture
14
Dec
2009
0 Votes 0
Login to vote

SID 23179 msrpc server service bo detected

 keep getting an alert from Endpoint saying that traffic from ip address .... is blocked

[SID 23179] MSRPC Server Service BO detected

I was just wondering what this means and how I can fix it.  It is always the same address and has been occuring more often the past week.

yvrjzala@yahoo.co.in's picture
14
Dec
2009
0 Votes 0
Login to vote

porn site automatically open

porn site automatically open in pc any one help me

Paul Mapacpac's picture
15
Dec
2009
0 Votes 0
Login to vote

Re

Hi yvrjzala@yahoo.co.in, please see my post at https://www-secure.symantec.com/connect/forums/vir...

it could be the same problem..

yvrjzala@yahoo.co.in's picture
27
Feb
2010
0 Votes 0
Login to vote

how to remove risk log in symantec endpoint protection

How to Remove risk log?

I am using Symantec Endpoing Protection. In symantec Endpoint Protection, in the view menu  antivirus and antispyware protection in the view log in risk log, when i try to delete file the follwing message arrive.  Please any one help about this problem.

Symantec end point protection cannot perform this action of 1 of the files you selected.

possible causes:
 
 - The file have been moved or deleted.
- you are tryting to clean file located in e-mail messages.
- you are tryung to clean a compressed file in a container.
 
i am attached herewith risk log file.

Please help me. 

AttachmentSize
fdfd.xls 26 KB