Exploits : MS03-026
Exploit in Microsoft Windows NT 4.0, Microsoft Windows 2000, Microsoft Windows XP,
Microsoft Windows Server 2003
On the 16th of July, Microsoft released a security bulletin detailing an exploit found in
Microsoft Windows. This and related articles can be found below:
The exploit is known to attempt to run a program which will allow an attacker to gain access
privileges to the affected system. The attacker would then be able to "take any action on the
system, including installing programs, viewing changing or deleting data, or creating new
accounts with full privileges" (Microsoft Security Bulletin MS03-026).
Due to the security risks involved, Microsoft have assigned this with a "Critical" rating.
It is highly recommended that users of Microsoft Windows NT 4.0, Microsoft Windows 2000,
Microsoft Windows XP or Microsoft Windows Server 2003 install the most recent security patches
available for their version of Windows to ensure that it is secured.
Important Note:
If you are unsure of whether your system is safe, then it will be best to
run Windows Update to ensure you have the most
recent patches for your version of Windows.
Q: Which version am I using?
To check which version of Windows you are using
- Click on the Start button
- Click on Run
- Type in "winver" without the quotes
- Click on OK or Run
If you cannot find the Run menu but have a Windows key on your keyboard (it will have the
Microsoft Windows logo on it):
- Hold down the Windows key
- Press the Pause/Break key (usually towards the top right of your keyboard)
- A System Information window will appear and the version you use will be indicated at the top right
Virus Removal Instructions
Step 1: Stop Remote Procedure Call from rebooting
- Click on Start
- Click on Run
- Type in "services.msc" without the quotes
- Click on OK or Run
- In the list on the right, double-click on the first "Remote Procedure Call
(RPC)"
NOT the one called "Remote Procedure Call (RPC) Locator"
- Select the Recovery tab at the top
- Change all Failure from "Restart the Computer" to "Take No Action"
- Click on OK
- Click on Start, Shutdown then Restart to restart the computer
Step 2: Apply the virus removal and security patches
- Download the virus removal patch from Symantec here.
- Download the Microsoft Security Patch for:
Windows XP
Windows 2000
Other versions of Windows please see here
- Run the virus removal patch and the Microsoft Security patch to apply the fix
- When complete, click on Start, Shutdown then Restart to
restart the computer
The virus should now be removed.
Related Links
- Instructions to download the security patch are available here
Click here to return to the Internet Security index
|