This is a read-only archive. No new posts or registrations. Privacy Page
Software

Want to disable DCOM protocol

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The Distributed Component Object Model (DCOM) is a protocol that enables software components to communicate directly over a network.
How to disable DCOM support in Windows

Reason 1
Frequent System Error
DCOM got error "%1068" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}.
Upnphost service is for hosting UPnP devices. Universal Plug and Play (UPnP) is an architecture in Windows XP that supports peer-to-peer Plug and Play functionality for network devices. Have desktop PC without network devices connection.

Reason 2
DCOM Security
DCOM enables programmatic calls from an application to COM objects on remote devices. This technology has potential security risks when deployed to run over a public network, such as the Internet.
PC is protected by a firewall from the public network and Microsoft issued hotfixes, but…
Symantec: … A buffer overrun vulnerability has been reported in Microsoft Windows that can be exploited remotely via a DCOM RPC interface that listens on TCP/UDP port 135 … For maximum security, 3rd generation full application inspection technology intelligently blocks tunneling of DCOM traffic over HTTP channels thus providing an extra layer of protection not readily available on most common network filtering firewalls…

Please opinion.

arTech
That is pretty old, last updated October 11, 2007. I would expect an update has been released since then to close that particular security hole. Why are you asking?
In chime of my slogan: prevent rather than cure - I want to disable DCOM protocol on my XP PCs by reason of security (DCOM works with both Java applets and ActiveX components and uses Port 135 open) and perhaps avoid system error ("%1068") which frequent occur? DCOM uses a little bit of resources.
I am Home user and haven't devices connected via network and I'm not connected to remote servers.
I'm not sure.

arTech
I would not do it. From the same link you porvided: Warning If you disable DCOM, you may lose operating system functionality. After you disable support for DCOM, the following may result: * Any COM objects that can be started remotely may not function correctly. * The local COM+ snap-in will not be able to connect to remote servers to enumerate their COM+ catalog. * Certificate auto-enrollment may not function correctly. * Windows Management Instrumentation (WMI) queries against remote servers may not function correctly. There are potentially many built-in components and 3rd party applications that will be affected if you disable DCOM. Microsoft does not recommend that you disable DCOM in your environment until you have tested to discover what applications are affected. Disabling DCOM may not be workable in all environments. But in the spirit of adventure and exploration, try it and let us know how you make out. :D
Done. DCOM is disabled. Now I will watch for system functionality. Once again DCOM runs over TCP port 135. Firewall is scanning and blocking this port. Where is the problem? Firewall can be confused, wrong configured, asleep (specially at booting time), accidentally switched off, … Microsoft's RPC (Remote Procedure Call) implementation runs over TCP port 135. RPC is used by several higher level protocols, such as by DCOM. Hacker tools are able to identify immediately every DCOM-related service running on the computer and the services it gives access to. Anyway I’m not pleased. My port 135 is still open by the rpcrt4.dll (RPC API, used by Windows applications for network and Internet communication). Next: Closing port 135 arTech
I just checked my WIn 7 Pro X64 system at grc.com and there are no visible ports. I'll give my XP system a try and see what it shows.

XP system also clean though I just noticed I'm running a very old Kerio Personal Firewall there. Also tested it with Kerio off and the XP Firewall off and it's still invisible.

Sounds to me like there is no need to block port 135 unless something you are running has explicitly opened it to WAN (Internet) traffic. What test are you using to check for open ports?
CurrPorts runs on your computer and looks at outbound ports. It doesn't check for open ports that are visible to the internet, which are the only ones I'm concerned about. For instance, on my XP box, netstat -a -n shows: Proto Local Address Foreign Address State TCP 0.0.0.0:135 0.0.0.0:0 LISTENING TCP 0.0.0.0:445 0.0.0.0:0 LISTENING TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING TCP 127.0.0.1:1025 127.0.0.1:3389 ESTABLISHED TCP 127.0.0.1:1029 0.0.0.0:0 LISTENING TCP 127.0.0.1:3389 127.0.0.1:1025 ESTABLISHED TCP 127.0.0.1:5152 0.0.0.0:0 LISTENING TCP 192.168.131.65:139 0.0.0.0:0 LISTENING As you can see, there are 8 ports open looking outward, but none are visible from the internet, they all have to be established from my computer.
CurrPorts and cmd netstat -a -n show the same results on my PC, but they show only part of secret world of stealth data transfer which are the only ones I'm concerned about.

If you use any seriously sniff program you will find many ports with active background inbound and outbound network traffic which are not on netstat list. After only few minutes of sniffing I found (for instance) ports with WTT remote address, host and location right in Dallas, or ports with uninvited partner.googleadservices.com, google-analytics.com, edge.quantserve.com, … although use Firefox NoScript. More sniffing more surprise.

OK nothing horridly, but generally want to reduce data leaking (more important problem than virus attack).

How?

Close and disable all needlessly, monitor, analyze and keep informed. Firewall must be the best.

arTech

PS: Your netstat list is temporary. An port can be closed unless something you are running has explicitly opened it for a short time.
At the beginning I didn’t quite understand theory of port activity, security practice and tactics of malicious hackers.

This may be simple explanation.

Open port means a TCP/IP channel that is configured to accept data packets via certain protocol from server and vice versa. However open port is not enough to establish communication. There must be an service (application) listening on that port to accept and process the incoming packets. If there is no service listening on a port, incoming packets will be rejected by the OS. Malicious hacker usually uses remote port scanning software to find which ports are reachable, and is there an actual service is listening on that port.

Here is the key. Common security practice is to disable all unnecessary services which might be running on the PC without the user's knowledge (also disabling some services can increase processor speed).

Now simple explanation of netstat report (port 135):

TCP 0.0.0.0 (local IP address) : 135 (port) 0.0.0.0:0 (remote or foreign address) LISTENING (state).

LISTENING shows there are services which are listening a open port 135 for inbound connections. DCOM application could be one (this is not DCOM Server Process Launcher) see Post #1.
Addresses 0.0.0.0 means the port is listening on all network interfaces and will accept any incoming connection on that port number! This is classic security hole.

List of known trojans and malware which use port 135: Femot, W32.Blaster.Worm, W32.HLLW.Gaobot, W32.Yaha, W32.Francette.Worm, W32.Cissi, W32.Welchia, W32.HLLW.Polybot, W32.Kibuv.Worm, W32.Explet, W32.Lovgate, W32.Spybot, W32.Maslan, W32.Mytob, W32.Kassbot, W32.Reatle, Secefa, W32.Kiman.

After 4 days without DCOM health of my PC is very well, and Event Viewer is clean now.

arTech

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI