Author Topic: Persistent DCOM Attacks  (Read 7221 times)

0 Members and 1 Guest are viewing this topic.

ver CO

  • Guest
Persistent DCOM Attacks
« on: July 18, 2010, 06:19:44 PM »
Good day! Newbie here and I totally need your help please.

Last week, I've had a rash of DCOM attacks. Good thing is, avast! is blocking those instances; I didn't really take note of the IP addresses though. I did some research and learned that these attacks are usually stopped by the firewall, and that I can close my DCOM ports.

I installed ZoneAlarm and used it in lieu of the Windows firewall. I also ran a boot time scan, installed Spybot and had HijackThis check my notebook. Result was: notebook is clean.

The thing is, even with what I've done, I'm still getting attacked! Like at least once a day. Did I miss or overlook anything?

Thanks in advance!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Persistent DCOM Attacks
« Reply #1 on: July 18, 2010, 07:11:02 PM »
Have you tried a forum search ?   " DCOM "   it may give you the info you want !

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Persistent DCOM Attacks
« Reply #2 on: July 18, 2010, 08:18:18 PM »
DCOM Attacks are speculative, not targeted and tries to exploit a vulnerability in out of date OS, if your OS is up to date then you aren't vulnerable to the exploit. That doesn't stop them (usually someone from the same ISP with an infected computer) trying to see if it can infect others.
 
Your firewall should be the first line of defence in this, but avast also monitors common attack ports using the Network Shield, ideally the firewall should block it and avast wouldn't know about it, but for whatever reason avast is first in line over your firewall.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Persistent DCOM Attacks
« Reply #3 on: July 18, 2010, 08:26:41 PM »
Messages like:
Network Shield: blocked "DCOM Exploit" - attack from 81.178.115.162:135/tcp
are due to the RPC/DCOM exploit, which is a vulnerability that allows an attacker to gain access to the destination machine by sending a malformed packet to the DCOM service. It uses the RPC TCP port 135.

Which firewall do you use?
And, most important, is your operational system updated?

You could get this free program from Steve Gibson's site.  This small program will test your PC to see if it's vulnerable.  The link below also explains what DCOM is all about.

Microsoft's DCOM security patch leaves DCOM running...
http://www.grc.com/freeware/dcom.htm
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Persistent DCOM Attacks
« Reply #4 on: July 18, 2010, 09:06:33 PM »
The attacks aren't due to any exploit as they are speculative in the hope that a users system is vulnerable and not because of it.

The OP reported ZA as his firewall.

Using DCOMbobulator won't stop the speculative attacks just attempt to close the port and that doesn't stop them trying the fact that it won't get through won't stop the attempts.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

ver CO

  • Guest
Re: Persistent DCOM Attacks
« Reply #5 on: July 19, 2010, 12:22:36 PM »
Thanks DavidR!

I have tried disabling DCOM using regedit and dcomcnfg.exe; still getting notices from avast! net shield. I didn't use the DCOMbobulator because I didn't think it'll help; thanks for confirming!

Neither the Windows 7 fw nor ZA are of any help. I have installed all the updates as they come (save those for IE because I don't use it.)

I just installed and ran a scan using MBAM and it says nothing is infected.

Is there anything else I can do?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Persistent DCOM Attacks
« Reply #6 on: July 19, 2010, 01:15:17 PM »
1. I just installed and ran a scan using MBAM and it says nothing is infected.
2. Is there anything else I can do?

1. Because you are not infected, that's an attack from the outside to your machine.
2. If you know the IP of the attacker, report it to the refering ISP.
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

ver CO

  • Guest
Re: Persistent DCOM Attacks
« Reply #7 on: July 19, 2010, 02:36:52 PM »
Thanks, asyn!

I still don't understand though why it's avast! blocking it and not my firewall. Can anyone please enlighten me on this matter?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Persistent DCOM Attacks
« Reply #8 on: July 19, 2010, 02:40:31 PM »
Maybe some problem in Zone Alarm?
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Persistent DCOM Attacks
« Reply #9 on: July 19, 2010, 05:13:26 PM »
Thanks DavidR!

I have tried disabling DCOM using regedit and dcomcnfg.exe; still getting notices from avast! net shield. I didn't use the DCOMbobulator because I didn't think it'll help; thanks for confirming!

Neither the Windows 7 fw nor ZA are of any help. I have installed all the updates as they come (save those for IE because I don't use it.)

I just installed and ran a scan using MBAM and it says nothing is infected.

Is there anything else I can do?

I said it wouldn't make any difference as applying a local solution to try and prevent an external attack attempt won't work. The external attacks will continue as the external source doesn't give a stuff what is on your system the random (as in your IP address is randomly assigned by the ISP), speculative (in that they hope your system isn't up to date and vulnerable), exploit attempts will continue. Given they are random they should after a while subside or stop, but they could be back or continue.

We don't know why avast's network shield is getting in first, that isn't something that I would expect with a third party firewall installed. Normally the firewall would be first and block it silently, but if the network shield sees it then it would have to assume it has bypassed your firewall and alert.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Persistent DCOM Attacks
« Reply #10 on: July 20, 2010, 09:11:19 AM »
Thanks, asyn!

1. I still don't understand though why it's avast! blocking it and not my firewall.
2. Can anyone please enlighten me on this matter?

You're welcome..!
1. Me neither, as your FW should block it. ;)
2. Not really. A solution would be to use another free FW. (Comodo, PCTools, etc...)
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

ver CO

  • Guest
Re: Persistent DCOM Attacks
« Reply #11 on: July 21, 2010, 11:33:02 AM »
Thanks DavidR and asyn! :)

Last question please: should I then keep both Spybot and MBAM,or uninstall one of them?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Persistent DCOM Attacks
« Reply #12 on: July 21, 2010, 12:42:23 PM »
Last question please: should I then keep both Spybot and MBAM,or uninstall one of them?
Spybot does not worth the effort anymore.
Keep only MBAM.
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Persistent DCOM Attacks
« Reply #13 on: July 21, 2010, 03:22:42 PM »
Thanks DavidR and asyn! :)

Last question please: should I then keep both Spybot and MBAM,or uninstall one of them?

You're welcome.

I too feel that spybot hasn't kept pace (but it does still have a reasonable detection), but allied to that there have been a few posts in the forums were it looks like spybot had been causing some issues with avast.

If you feel that having another anti-spyware I would suggest SUPERantispyware (SAS). On-Demand only in free version.
Don't worry about reported tracking cookies they are a minor issue and not one of security, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie. One of the useful features in SAS is that it has a number of Repair functions to recover from some common registry problems.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Persistent DCOM Attacks
« Reply #14 on: July 22, 2010, 07:47:07 AM »
Thanks DavidR and asyn! :)

Last question please: should I then keep both Spybot and MBAM,or uninstall one of them?

You're welcome..!
Drop Spybot and keep Mbam...
asyn

W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0