India Broadband

Forum

 

Avast: DCOM Exploit- Blocked

This is a discussion on Avast: DCOM Exploit- Blocked within the BSNL broadband forums, part of the DSL Broadband Service Providers category; Today I got a warning from Avast about a "DCOM Exploit". I got the same warning message 5-6 times already. ...


Go Back   India Broadband Forum > Indian Broadband Forums > DSL Broadband Service Providers > BSNL broadband

Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

 

LinkBack Thread Tools Display Modes
Old 21-11-2008, 08:33 AM   #1
Apprentice Hunter
 
Archer's Avatar
 
Join Date: Aug 2008
Posts: 2,645
Rep Power: 3 Archer is on a distinguished road
Exclamation Avast: DCOM Exploit- Blocked

Today I got a warning from Avast about a "DCOM Exploit". I got the same warning message 5-6 times already. I wasn't using internet but was active when I got this warning messages. I have Zone Alarm firewall installed but was disabled when this happened. I have also got the similar messages from Zone Alarm before.
What should I do ?

This is the warning message I got in Avast.

025.gif
__________________

Archer is online now   Reply With Quote
Old 21-11-2008, 08:59 AM   #2
Alligator
 
itsmemad's Avatar
 
Join Date: Sep 2008
Location: Patna, Pune
Posts: 2,637
Rep Power: 3 itsmemad will become famous soon enough
Send a message via MSN to itsmemad
Default

Read it... attacts from dcom exploit continue - CNET Computer help Forums
itsmemad is offline   Reply With Quote
Old 21-11-2008, 05:55 PM   #3
Bronze Member
 
Join Date: Sep 2008
Location: Bangalore
Posts: 156
Rep Power: 1 internet_guy is on a distinguished road
Default

hey i got same type of message 1 month back.from avast

30.10.2008 0208 DCOM Exploit attack
from 59.92.112.212:135
30.10.2008 0222 DCOM Exploit attack
from 59.92.78.28:135
30.10.2008 0206 DCOM Exploit attack
from 59.92.78.28:135

i trace the ip adress and its another bsnl broadband user in chennai

i dont know why he was trying to get in to my system ?

my speed during night unlimitedis very low,is this anything to do with it,is that user hacked my speeds or something considering the fact that this happen during 2am -3am ?
internet_guy is offline   Reply With Quote
Old 21-11-2008, 10:38 PM   #4
Platinum Member
 
Join Date: Feb 2008
Posts: 1,555
Rep Power: 2 superprash2003 is on a distinguished road
Default

its probably not him.. its probably a virus in his pc that is trying to spread virus and hack your pc.. this is through open ports.. so having a firewall is necessary..
superprash2003 is offline   Reply With Quote
Old 22-11-2008, 02:26 AM   #5
Bronze Member
 
Join Date: Sep 2008
Location: Bangalore
Posts: 156
Rep Power: 1 internet_guy is on a distinguished road
Default

Quote:
Originally Posted by superprash2003 View Post
its probably not him.. its probably a virus in his pc that is trying to spread virus and hack your pc.. this is through open ports.. so having a firewall is necessary..
then how the virus got hold of my ip address,

my port 135 is stealth i ran some online firewall checks ,
internet_guy is offline   Reply With Quote
Old 22-11-2008, 02:28 AM   #6
Apprentice Hunter
 
Archer's Avatar
 
Join Date: Aug 2008
Posts: 2,645
Rep Power: 3 Archer is on a distinguished road
Default

PORT 135 is commonly used for Microsoft Remote Procedure Call (RPC) service. I wonder whether there is any relations between this.
Archer is online now   Reply With Quote
Old 22-11-2008, 02:46 AM   #7
Bronze Member
 
Join Date: Sep 2008
Location: Bangalore
Posts: 156
Rep Power: 1 internet_guy is on a distinguished road
Default

Quote:
Originally Posted by Archer View Post
PORT 135 is commonly used for Microsoft Remote Procedure Call (RPC) service. I wonder whether there is any relations between this.
see my second post,some dude from Chennai is accessing my port 135 during 2:50 am

i was not on torrents nor i know him

i assume he or the virus is trying to do some nasty sh*t with my rpc

i was just wondering how he or the virus got my ip
internet_guy is offline   Reply With Quote
Old 22-11-2008, 02:49 AM   #8
Apprentice Hunter
 
Archer's Avatar
 
Join Date: Aug 2008
Posts: 2,645
Rep Power: 3 Archer is on a distinguished road
Default

Same with my case. The IP is from a local place, but I don't even know who that is.
Archer is online now   Reply With Quote
Old 22-11-2008, 04:01 AM   #9
Junior Member
 
cableguy's Avatar
 
Join Date: Sep 2008
Posts: 100
Rep Power: 1 cableguy is on a distinguished road
Default

Some viruses/worms are designed to automatically search for Windows systems to infect using port 135. If you have a firewall just set it to block any connections to port 135.
__________________
cableguy is offline   Reply With Quote
Old 22-11-2008, 02:48 PM   #10
Platinum Member
 
Join Date: Feb 2008
Posts: 1,555
Rep Power: 2 superprash2003 is on a distinguished road
Default

just a random ip.. he wasnt intending to attack YOU particularly.. just any target.. you just happened to be the lucky one :-). try it out yourself.. try some random ip within the bsnl range .. try pinging it, you would get a successful ping..
superprash2003 is offline   Reply With Quote
Reply

Bookmarks

Tags
avast dcom exploit, blocked, dcom, dcom exploit, dcom exploit blocked


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
Avast Anti-Virus professional Review ShAdOwCoN Software News, Previews and Reviews 2 13-11-2008 09:36 AM
Ports blocked!! help!!! ReBeLLioN Airtel Broadband 7 19-09-2008 07:58 PM
Torrent Blocked abhilashca BSNL broadband 8 02-07-2008 03:29 PM
IS port 25 blocked by airtel mehul87 Airtel Broadband 5 30-06-2008 01:15 PM
How to access blocked pages? xwhyz Computer hardware and software tips and tricks 1 17-04-2008 03:17 AM


All times are GMT +5.5. The time now is 11:41 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
India Broadband Forum