Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11EternalRocks was a self-replicating network worm reported in May 2017. Its seven named components were not all exploits: two performed reconnaissance, four were exploitation tools, and DoublePulsar acted as a backdoor. Cisco Talos described one observed chain that used EternalBlue and DoublePulsar for access, then waited 24 hours before downloading a further payload. That account describes reported behavior, not a sequence proven for every sample.
What was EternalRocks?
Researcher Miroslav Stampar described EternalRocks, also called MicroBotMassiveNet, as a self-replicating network worm. His repository lists May 3, 2017, as the date of the oldest known sample and says the worm emerged in the first half of that month. SecurityWeek’s May 22, 2017 report also cited a May 3 sample and credited Stampar with its discovery. Stampar’s EternalRocks repository and SecurityWeek’s contemporary report document those early findings.
The name “seven NSA hacking tools” can be misleading: the reported set mixed scanning utilities, exploit code, and a backdoor. The Shadow Brokers publicly released the relevant exploit material on April 14, 2017, according to Check Point; Microsoft had already issued its MS17-010 security update in March for some of the vulnerabilities involved. Check Point’s analysis places the worm in that context: leaked attack tools could still threaten systems that had not been updated.
What were the seven tools, and what did they do?
Check Point grouped the components by function rather than treating all seven as interchangeable exploits:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
| Role | Components | Reported function |
|---|---|---|
| Reconnaissance | SMBTouch and ArchiTouch | SMBTouch scanned targets before an attack and attached a detailed target report, according to Check Point. Check Point grouped ArchiTouch with reconnaissance tools. |
| Exploitation | EternalBlue, EternalChampion, EternalSynergy, and EternalRomance | Exploit tools used to target vulnerable systems. Check Point grouped these four Eternal-named components in the exploitation stage. |
| Backdoor | DoublePulsar | A backdoor component. In Cisco Talos’s account of observed EternalRocks behavior, it helped maintain access and enable delivery of further malicious software. |
The seven names are also listed in Stampar’s repository and SecurityWeek’s reporting. The categories above follow Check Point’s analysis; the behavior attributed to Talos is described in Cisco Talos’s report.
How did EternalRocks spread, according to contemporary reports?
Cisco Talos reported that EternalRocks used EternalBlue and DoublePulsar to gain access, then used that access as a backdoor for installing other malicious software. Talos highlighted a 24-hour delay before the worm downloaded a final payload that included additional exploits from the Shadow Brokers’ release. This is Talos’s description of behavior it observed; it does not establish that every version or sample followed the same sequence.
SecurityWeek reported that the malware appeared to install DoublePulsar and relayed a researcher’s view that, at the time, it seemed more like a research project than an active malicious tool. That was a time-bound assessment in May 2017, not evidence of the worm’s present status. The accounts do not describe EternalRocks as ransomware. Cisco Talos and SecurityWeek provide the contemporary descriptions.
Why did SMBv1 matter?
Microsoft’s MS17-010 bulletin covered Windows SMBv1 vulnerabilities, including remote-code-execution flaws CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148, as well as the information-disclosure flaw CVE-2017-0147. Microsoft stated: “To exploit the vulnerability, in most situations, an unauthenticated attacker could send a specially crafted packet to a targeted SMBv1 server.” See Microsoft’s MS17-010 bulletin for the affected vulnerabilities and its historical mitigation guidance.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →How should administrators harden Windows SMB systems?
Microsoft’s guidance points to two core actions: apply the appropriate security update and disable SMBv1 where it is not needed. These controls address different parts of the risk: patching fixes the applicable vulnerabilities, while disabling the older protocol removes exposure through SMBv1. Cisco Talos also recommended installing the update associated with MS17-010.
- Apply the appropriate security update. Follow the MS17-010 bulletin and the update guidance for the Windows version in use; do not assume that a generic security product or antivirus replaces operating-system patching.
- Review SMBv1 dependencies before disabling or removing it. Microsoft’s current Windows SMB guidance strongly discourages SMBv1 because it has significant security vulnerabilities, but warns that older computers or software may depend on it. Check the applicable Windows guidance and test legacy dependencies before changing a production network.
- Use monitoring as a complement, not a substitute. Network and endpoint detection can help identify suspicious activity, but neither a detection tool nor a single network control replaces patching and deliberate SMB configuration.
Microsoft’s current recommendation and compatibility warning are in its Windows SMB1 guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is known about EternalRocks today?
The cited contemporary reporting establishes historical samples and behavior from 2017; it does not establish current prevalence or a reliable infection total. The sample date of May 3, 2017, and the April 14, 2017 Shadow Brokers release date are event dates, not counts of infected systems. The evidence here therefore supports a historical account and a continuing defensive lesson about patching and SMBv1, not a claim that EternalRocks is currently widespread or active.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

