Re: RPC Failure accross the domain

From: Yaron Bental (Yaron_Bental_at_gmaccm.com)
Date: 08/14/03


Date: Thu, 14 Aug 2003 10:35:36 -0700


yep it was the worm. it just have different behaviour when
you use terminal servers.

Thanks for you help.

>-----Original Message-----
>Did you patch all servers and workstations with the MS03-
026 patch?
>
>Yaron Bental wrote:
>> Hi,
>>
>> We have seen a failure of RPC service at exactly the
same
>> time almost across all servers one of our domains. In
fact
>> all the servers that failed were on the same subnet.
Some
>> machines on the DMZ Were NOT affected.
>>
>> We are seeing in the event log massage:
>>
>> The Remote Procedure Call (RPC) service terminated
>> unexpectedly. It has done this 1 time(s). The
following
>> corrective action will be taken in 0 milliseconds: No
>> action.
>>
>> Giving the latest msblaster spread out we thought it
could
>> be it. However we are not seeing any other signs of
>> msblaster. We have tried to use the tools provided from
>> Symantec to verify if the worm was on there and it
didn't
>> find it.
>>
>> Is anyone else experiencing the same problem?
>>
>> Any idea would be greatly appreciated.
>>
>> Thanks very much.
>
>
>.
>



Relevant Pages

  • Nimda Worm Alert - What Ive done so far.
    ... Download/Install URL Scan for www servers. ... A new worm named W32/Nimda-A (known aliases are Nimda, Minda, Concept ... Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability ...
    (Focus-Microsoft)
  • Re: ** Sobig.F attack expected 3:00pm to 6:00pm EST today [Friday 22]
    ... computers that are currently infected with the Sobig.F worm ... > infected device possibly involving the "master servers," the others opened ... > This press release comes from F-Secure. ... > has been added to our lists without your consent, ...
    (microsoft.public.security)
  • Re: ** Sobig.F attack expected 3:00pm to 6:00pm EST today [Friday 22]
    ... computers that are currently infected with the Sobig.F worm ... > infected device possibly involving the "master servers," the others opened ... > This press release comes from F-Secure. ... > has been added to our lists without your consent, ...
    (microsoft.public.inetserver.iis.security)
  • Re: ** Sobig.F attack expected 3:00pm to 6:00pm EST today [Friday 22]
    ... computers that are currently infected with the Sobig.F worm ... > infected device possibly involving the "master servers," the others opened ... > This press release comes from F-Secure. ... > has been added to our lists without your consent, ...
    (microsoft.public.windowsxp.security_admin)
  • RE: New "concept" virus/worm?
    ... The W32.Nimda.A@mm worm infects IIS servers by exploiting the 'MS IIS/PWS ... opening the attachment will infect the machine. ... The virus comes at a time of heightened sensitivity to Internet attack. ...
    (Incidents)

Quantcast