North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Possible New RPC vulnerability and Worm?????

  • From: tad pedley
  • Date: Thu Jan 29 20:00:42 2004

Just found this on the Symantec site, this seems a little rushed after reading it. Anyone have any thoughts?

http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.anig.html

tad pedley <[email protected]> wrote:
Has anyone heard of a new Microsoft RPC vulnerability today? I'm hearing conflicting reports of a new worm that is exploiting this new vulnerability. We have seen the following process created on our XP workstations:
 
It apparently creats the following process "NTOSA32.EXE" with a dependancy for RPC. It is also running as the distributed file controller. There also seems to be a link to this file: "NTBKH32.DLL".
 
Please forgive siplisity of the post, but that is all the info we are seeing right now. Our AV is looking at it and so far has said little other than it is a new worm. Just trying to see if anyone has seen or heard this.
 
Thanks,
T


Do you Yahoo!?
Yahoo! SiteBuilder - Free web site building tool. Try it!


Do you Yahoo!?
Yahoo! SiteBuilder - Free web site building tool. Try it!