Full Disclosure mailing list archives

possible MS03-026 worm?


From: "mobly99" <dhopper () ameritech net>
Date: Sat, 2 Aug 2003 11:58:00 -0500

Seems to be a possible worm based on the RPC/DCOM exploit making the
rounds?

puts these files in %systemdrive%
rpc.exe
rpctest.exe
tftpd.exe
worm.exe
lolx.exe

also in %windir%\system32 
lolx.exe 
dcomx.exe

rpc.exe and dcomx.exe appear in the running tasks. 


I pulled samples of them and submitted to SARC.


-Dave

Attachment: smime.p7s
Description:


Current thread: