Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Abigail Adams; AIC; airborne; AirForceBrat23; Alamo-Girl; ALOHA RONNIE; angelsonmyside; AnnaZ; ...

Can anyone tell me what this report by my virus software means?

Risk name: MSRPC Malicious LSASS DS Request BO (1)

Attacking Computer: 76.160.255.111,3288
Attacking Computer: 76.53.10.103,16924


2,064 posted on 10/23/2007 4:56:42 PM PDT by patriciaruth (http://www.freerepublic.com/focus/f-news/1562436/posts)
[ Post Reply | Private Reply | To 2063 | View Replies ]


To: patriciaruth

Hi Patty! Hubby suggests that you google the text after the “risk name” and see if there is any info out there about it.

My goodness, I forgot to post about the 3 boxes of candy I sent to Bagram last Friday! Yikes! I will try to remember to do it tomorrow.


2,065 posted on 10/23/2007 5:05:15 PM PDT by Abigail Adams
[ Post Reply | Private Reply | To 2064 | View Replies ]

To: patriciaruth

I did a quick security search and found these:

FORENSIC LOG:

Infection Source:
76.160.255.111
Executables Delivered:
ftpupd.exe
txyqlyt.exe
Listen Ports Opened:
1031
1031
891
Processes Created:
MSMSGS.EXE
txyqlyt.exe
Registry Entries Modified or Created:
HKEY_LOCAL_MACHINE@...Microsoft\Wireless

It’s the IP addresses of the computers that the bug is launching from. It looks like the bug is trying to exploit MS Messenger.

More...
“The Windows Messenger from Microsoft provides Online Chat and Instant Messaging.
If you don’t use Windows Messenger, you can disable it as follows: Start -> Programs -> Windows Messenger -> Tools -> Options -> Preferences. Uncheck “Run this program when Windows Starts”.

Note: The msmsgs.exe file is located in the folder C:\Program Files\Messenger. In other cases, msmsgs.exe is a virus, spyware, trojan or worm! Check this with Security Task Manager.”


2,066 posted on 10/23/2007 5:14:21 PM PDT by Old Sarge (This tagline in memory of FReeper 68-69TonkinGulfYachtClub)
[ Post Reply | Private Reply | To 2064 | View Replies ]

To: patriciaruth

I don’t know. This page from google’s cache might give you some info. http://72.14.209.104/search?q=cache:A9D-ZrYsPHwJ:www.cybertechhelp.com/forums/archive/index.php/t-147714.html+Risk+name:+MSRPC+Malicious+LSASS+DS+Request+BO+(1)&hl=en&ct=clnk&cd=3&gl=us .

Here’s the search I did. Search: Risk name: MSRPC Malicious LSASS DS Request BO (1). http://www.google.com/search?hl=en&q=Risk+name%3A+MSRPC+Malicious+LSASS+DS+Request+BO+%281%29&btnG=Google+Search .


2,067 posted on 10/23/2007 6:14:51 PM PDT by BykrBayb (In memory of my Friend T'wit, who taught me much. ~ Þ)
[ Post Reply | Private Reply | To 2064 | View Replies ]

To: patriciaruth
Looks serious. Download free AVG software and you'll be protected. That's advice from a computer repairman.

Download the software and it will scan everything including that message you posted.

2,068 posted on 10/23/2007 8:41:52 PM PDT by floriduh voter (Terri Ping List: 8mmmauser & I'm 4 DUNCAN HUNTER & ?????????)
[ Post Reply | Private Reply | To 2064 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson