Endpoint Protection

 View Only
Expand all | Collapse all

[SID 23179] MSRPC Server Service BO detected

Migration User

Migration UserMar 24, 2009 04:00 PM

Migration User

Migration UserApr 17, 2009 03:08 AM

Migration User

Migration UserApr 22, 2009 01:56 PM

Migration User

Migration UserDec 15, 2009 02:55 AM

  • 1.  [SID 23179] MSRPC Server Service BO detected

    Posted Mar 23, 2009 08:24 PM
    I keep getting an alert from Endpoint saying that traffic from ip address .... is blocked

    [SID 23179] MSRPC Server Service BO detected

    I was just wondering what this means and how I can fix it.  It is always the same address and has been occuring more often the past week.


  • 2.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 23, 2009 09:44 PM
    Can you post some event logs, or run diagnostic tool from symantec on the PC then post it here? We need to identify this..


  • 3.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 24, 2009 03:50 PM

    When I run a virus scan, even in safe mode, nothing is found.  I just continue to get the alert from the icon in the lower right hand cornor.  What should I run on my computer?



  • 4.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 24, 2009 03:55 PM
    Did you inspect the machine that had been backtracked and run a full scan on it?


  • 5.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 24, 2009 04:00 PM

    how would i do this?



  • 6.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 24, 2009 04:14 PM
    The IP address that is being detected, Is that in your domain?

    If it is, Narrow down on to where the machine physically is located. Take it off the network. Run a full scan on it.


  • 7.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 24, 2009 04:14 PM
    The IP address that is being detected, Is that in your domain?

    If it is, Narrow down on to where the machine physically is located. Take it off the network. Run a full scan on it.


  • 8.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 24, 2009 09:59 PM
    As what Sandeep said, locate it from the network. This could be a misleading application infection.


  • 9.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Mar 26, 2009 11:58 PM
    One machine on the network is infected and is trying to spread. (Whoc IP is shown on other machines)

    Remove infected machine.

    Tejas


  • 10.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 02, 2009 02:28 AM
    I also getting alert like this and I found w32.downadup.B try to spreads in my network system.


  • 11.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 15, 2009 11:59 AM
    Run the downadup removal tool on all workstations...


  • 12.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 17, 2009 12:15 AM
    i am using Symantec endpoint MR3 for my 500 client ...... I did all the steps which you guys are discussing..... i think Symantec is just useless product ......

    Symantec unable to remove W32.downadup.b......



  • 13.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 17, 2009 12:20 AM
    hi Dhayal,

    I would suggest you Run a manual scan on all of your machine from SEPM.


    RightClick on your Group> Scan the computers.

    Make sure all you rmachines are having latest definition and MS08-067 vulnerabitility is been patched.

    Temporary disable ADMIN$ share in your network. Ask user to disable OPen shares in there machines and change password every 45 days. the password must be tough and not simple dictionary words.

    I know its little bit lenghty procedure, but you need to follow to remove the same.

    Rgrds,
    SAM


  • 14.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 17, 2009 03:08 AM
    Hi Sc,

    Can you please share the security logs here?


  • 15.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 17, 2009 03:15 AM



    thanks SAM ..... but i already did these steps .....what next ???... i have very wide range network ..


  • 16.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 17, 2009 04:46 AM
    Hi,

    Pls Log a case with Symantec team,. They will provide you with the Loadpoints. Run the Loadpoint and submit the same. They will further ask you to send the suspicious files to SEcuroty Response team.

    I think it is a NEW VARIANT.

    Rgrds,
    SAM


  • 17.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 20, 2009 11:18 PM
    When I run a virus scan, even in safe mode, nothing is found. I just continue to get the alert from the icon in the lower right hand cornor.


  • 18.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 21, 2009 12:14 AM
    this is the logs which i found very time on windows server 2003 ... its very time attacking on server 2003 only ....

    Risk,Filename,Original Location,Status,Date
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 5:16 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 6:21 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 6:21 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 6:34 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 7:48 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 9:01 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 10:17 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/20/2009 11:31 PM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 12:48 AM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 1:58 AM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 3:13 AM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 4:29 AM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 5:44 AM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 6:59 AM
    W32.Downadup.B,xqcasvu.qqt,C:\WINDOWS\system32\,Infected,4/21/2009 8:16 AM



  • 19.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 21, 2009 12:26 AM
    The system with that IP address must be in your domain.
    Physically locate them.Remove their network connection.Check that virus defination is updated or not. Then run full scan on system to be on safer side. 


  • 20.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 21, 2009 01:01 AM
    Downadup uses this vulnerability in windows.Mke sure all your computers are patched with patch KB 958644
    Check the security logs and Isolate the computer fro which you are getting these attacks.
    Make sure these computers have all the features installed with updates definitions and windows security patches.


  • 21.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 22, 2009 12:40 PM
    Try to findout the infected computer by its IP address and clean it. For downadup please download the removal tool, disable the system resoter point, detach the computer from network, log on to safe mode and then run the tool.


  • 22.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 22, 2009 01:45 PM
    some time it is showing external ip & some time internal ip


  • 23.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Apr 22, 2009 01:56 PM
    Have you tried it? What is the update?


  • 24.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Aug 13, 2009 07:32 AM
    I am having this same problem with my PC. I have run scans and it keeps popping up. The IP address's that are being blocked are from multiple PC's. Where is the removal tool to download that you spoke of?

    Jackie


  • 25.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Aug 14, 2009 11:12 AM
    Whats the confusion?
    What I do is export my NTP logs with it filtered to show only Intrustion Prevention.
    An remote hosts mentioned in lines with [SID 23179] MSRPC Server Service BO detected are surely infected with Downadup. There are no cases of false alarms.


    You need to get hold of the remote host

    1) Check that all members of the Administrators group have a PROPER password. If you are skipping this step you are wasting your time.

    2) Ensure System Restore is turned off if its a desktop OS

    3) clean it up using the removal tool
    http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/D.exe

    4) Put the MS Patch refer to KB958644 for that OS. Also ensure that SEP client is running or needs to be reinstalled.

    5) Educate all IT staff if its a remote location that when they rebuild PCs for any reason, they need to ensure all the above is done.




  • 26.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Sep 10, 2009 09:14 PM

    To add MSRPC 23179 exception.

    1.Go to Policies --> Intrusion Prevention Policies
    2.Right Click Edit --> On the Exceptions tab
    3.Click Add --> Look for the ID 23179
    4.click Next
    5. On the Signature Action select "Allow" and click OK.

    If you want to disable the notification on your system tray..

    1. Go to Clients, then the client group you want to remove this ability from.
    2. Click the Policies tab on the right, then expand 'Location-specific Settings'.
    3. Click on 'Server Control', then Customize.
    4. In the Intrusion Prevention Notifications Uncheck the "Display Intrusion Prevention notifications."



  • 27.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Dec 15, 2009 02:19 AM
     keep getting an alert from Endpoint saying that traffic from ip address .... is blocked

    [SID 23179] MSRPC Server Service BO detected

    I was just wondering what this means and how I can fix it.  It is always the same address and has been occuring more often the past week.



  • 28.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Dec 15, 2009 02:55 AM
    porn site automatically open in pc any one help me


  • 29.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Dec 15, 2009 10:25 PM


  • 30.  RE: [SID 23179] MSRPC Server Service BO detected

    Posted Feb 27, 2010 08:33 AM
      |   view attached
    How to Remove risk log?

    I am using Symantec Endpoing Protection. In symantec Endpoint Protection, in the view menu  antivirus and antispyware protection in the view log in risk log, when i try to delete file the follwing message arrive.  Please any one help about this problem.

    Symantec end point protection cannot perform this action of 1 of the files you selected.

    possible causes:
     
     - The file have been moved or deleted.
    - you are tryting to clean file located in e-mail messages.
    - you are tryung to clean a compressed file in a container.
     
    i am attached herewith risk log file.

    Please help me. 

    Attachment(s)

    xls
    fdfd.xls   26 KB 1 version