WinXP/RPCSS exploit disaster

SlimPickens

Junior Member
Apr 21, 2003
15
0
0
Greetings. Although I've maintained all M$ patches/updates, their flawed RPC service has left a door open on my system and I have a svchost process (RPCSS) running wild and burning up 99% of my cpu cycles. I've repatched to no avail. Is patching supposed to plug all the holes and effectively "fix" the PC? I'm trying to to isolate and kill the intruder (is there one?) but anti-trojan software will take days to run. I can always resort to dropping the bomb on the drive and re-installing but that's my LAST resort. Any of you OS maniacs/hackers have any other options I can try before I employ the "last resort"? Any help/input is appreciated. Regards.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Symantec (I think) sent out a fix for one of the RPC things. Take a look to see if you can find it. The instructions said that you should run it after patching (or before, I forget) because the patch does not get rid of something on your system.
 

SlimPickens

Junior Member
Apr 21, 2003
15
0
0
Hello, All. Thanks for your input. Just to wrap this thread up: I couldn't discover/kill/or otherwise stop the bandit that stole my RPCSS service. So I re-formatted, re-installed and patched the OS (WinXPpro). I wanted to find out what was really going on but my need for the system took precidence over my curiosity. Thanks again for your responses. Til next time. Regards, Slim
 

NogginBoink

Diamond Member
Feb 17, 2002
5,322
0
0
Gee, it might have been a buggy RPC app that you installed on the machine and had nothing to do with malicious code....

...but you can jump to any conclusion you'd like.

(In your defense, it's tough to determine what's going on inside those services without hooking up a debugger.)
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |