blaster worm - VIRUS WARNING URGENT!!!! - TennisForum.com
Reply
 
LinkBack Thread Tools
post #1 of 59 (permalink) Old Aug 12th, 2003, 03:31 PM Thread Starter
country flag M&M
Senior Member
 
Join Date: Oct 2001
Posts: 5,963
                     
Exclamation blaster worm - VIRUS WARNING URGENT!!!!

article on it in german

security patch

ACTIVE YOUR FIREWALL!!!!

Last edited by M&M; Aug 12th, 2003 at 03:39 PM.
M&M is offline  
Sponsored Links
Advertisement
 
post #2 of 59 (permalink) Old Aug 12th, 2003, 03:35 PM
Senior Member
 
Join Date: Jan 2002
Location: b/n 1 & 3
Posts: 3,628
 
I read that activating a firewall might not be enough. Make sure you disable dcom support (don't know how to do that), and apply the patch. It's news like this that make me glad that I dumped MS windows operating system long time ago from my desktop.

More info on how to remove this worm from your computer if it's affected from good people at slashdot: http://slashdot.org/articles/03/08/1...id=190&tid=201

Last edited by eta psi; Aug 12th, 2003 at 03:42 PM.
Hulet is offline  
post #3 of 59 (permalink) Old Aug 12th, 2003, 03:36 PM Thread Starter
country flag M&M
Senior Member
 
Join Date: Oct 2001
Posts: 5,963
                     
well i had problems to start my comp yesterday. after i started a window got opened and told me i have one minute to quit all programms etc. then the comp rebooted (i think 8 or ten times in a row).

i didn't know what to do, and today found out this. download this security patch
i will also post the remove tool soon.

take care of your computers and your privacy!!!
M&M is offline  
post #4 of 59 (permalink) Old Aug 12th, 2003, 03:39 PM Thread Starter
country flag M&M
Senior Member
 
Join Date: Oct 2001
Posts: 5,963
                     
removal tool

well, this tool will look at your comp system and search for the worm. if he will find it, it will be delated.

!!!!FIGHT WITH THE HACKERS!!!!
M&M is offline  
post #5 of 59 (permalink) Old Aug 12th, 2003, 03:59 PM Thread Starter
country flag M&M
Senior Member
 
Join Date: Oct 2001
Posts: 5,963
                     
well i have successfully removed it now!!!

The process "msblast.exe" is viral. It is terminated.

Deleted the value "windows auto update" from the registry key
"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Cur rentVersion\Run".

The tool has deleted the viral file "C:\WINDOWS\system32\msblast.exe".

W32.Blaster.Worm has been successfully removed
from your computer!

Here is the report:

The total number of the scanned files: 39627
The number of deleted files: 1
The number of repaired files: 0
The number of viral processes terminated: 1
The number of registry entries fixed: 1
M&M is offline  
post #6 of 59 (permalink) Old Aug 12th, 2003, 04:00 PM Thread Starter
country flag M&M
Senior Member
 
Join Date: Oct 2001
Posts: 5,963
                     
so if u don't wanna have a long search, here is teh link to the viral file

C:\WINDOWS\system32\msblast.exe
M&M is offline  
post #7 of 59 (permalink) Old Aug 12th, 2003, 04:16 PM
Senior Member
 
Join Date: Mar 2002
Location: Belfast, N.Ireland
Posts: 4,491
                     
I'm on my sister's puter at the mo cos when I connect mine to the net it has a system shutdown after one minute- what am I going to do cos obviously I can't download any of this stuff? Will my normal virus guard be enough to take it out since I only just updated it?

Btw, how does this virus get into your puter? I've hardly been using mine lately but my sister is never off it so is it possible she could have got it from a download or something or through her inbox?

Jen, is it cold out there or are you just pleased to see me?
Luna_Angel_84 is offline  
post #8 of 59 (permalink) Old Aug 12th, 2003, 04:26 PM
Senior Member
 
bis2806's Avatar
 
Join Date: Jul 2002
Location: Charlottesville, VA
Posts: 7,119
                     
OMG!!!! i have the same fucking problem this morning?!??!?!?!?!?!?!? i thought something must be wrong with my computer.. help someone!!! please tell us all the steps on how to delete the virus?!?!??!
bis2806 is offline  
post #9 of 59 (permalink) Old Aug 12th, 2003, 04:31 PM Thread Starter
country flag M&M
Senior Member
 
Join Date: Oct 2001
Posts: 5,963
                     
well u really should try to download the removal tool somehow, for some of us it didn't work first cause so many poeple are downloading it at the same time - the link is in a previous post.

then update your windows system and download the security patch, i t really should work.
M&M is offline  
post #10 of 59 (permalink) Old Aug 12th, 2003, 04:39 PM Thread Starter
country flag M&M
Senior Member
 
Join Date: Oct 2001
Posts: 5,963
                     
Quote:
Originally Posted by bis2806
OMG!!!! i have the same fucking problem this morning?!??!?!?!?!?!?!? i thought something must be wrong with my computer.. help someone!!! please tell us all the steps on how to delete the virus?!?!??!
maybe just make a quickserach in your system for msblast.exe

then u can delate it... but the removal tool should be better.

btw: yes, if u r downloading big files, like movies and many mp3, the possibility to get the worm is much bigger. they eneter your sytem at an open port...
M&M is offline  
post #11 of 59 (permalink) Old Aug 12th, 2003, 04:45 PM
Senior Member
 
gorecki's Avatar
 
Join Date: Nov 2001
Location: Limbo
Posts: 32,947
                     
from symantec website:

W32.Blaster.Worm is a worm that exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. This worm attempts to download and run the Msblast.exe file.

Block access to TCP port 4444 at the firewall level, and then block the following ports, if they do not use the applications listed:


TCP Port 135, "DCOM RPC"
UDP Port 69, "TFTP"

The worm also attempts to perform a Denial of Service (DoS) on Windows Update. This is an attempt to prevent you from applying a patch on your computer against the DCOM RPC vulnerability.

[center]People are Tricky you can't Afford to Show anything Risky..
Seeing is Believing. Feeling is Deceiving. I could be anyone but your friend..
~*~
I'm going out, I'm going to drink myself to death
And in the crowd I see you with someone else
I brace myself 'cause I know it's going to hurt
But I like to think at least things can't get any worse
[center]
gorecki is offline  
post #12 of 59 (permalink) Old Aug 12th, 2003, 04:50 PM
Senior Member
 
Join Date: Mar 2002
Location: Belfast, N.Ireland
Posts: 4,491
                     
Pffffft my puter can't find the file to be deleted so I am well and truly screwed here.

Jen, is it cold out there or are you just pleased to see me?
Luna_Angel_84 is offline  
post #13 of 59 (permalink) Old Aug 12th, 2003, 04:58 PM
country flag YSL
Boozy Woman
 
YSL's Avatar
 
Join Date: Jul 2002
Location: *hic*
Posts: 2,408
                     
luna, if you reboot your machine then go download the patch and then instantly log off as soon as it's downloaded. You should be OK. The RPC shutdown thing only happens when you're online

REMEMBER: Friends don't set fire to each other
YSL is offline  
post #14 of 59 (permalink) Old Aug 12th, 2003, 05:07 PM
Senior Member
 
Join Date: Mar 2002
Location: Belfast, N.Ireland
Posts: 4,491
                     
Can someone tell me how to do this thing to abort shutdown so I have enough time to download this stuff? At that site they say to do this shutdown \a thing or something, but what does that mean? My mum is going to be so mad about this if we can't get it fixed cos our computer is pretty new and she paid for most of it.

Jen, is it cold out there or are you just pleased to see me?
Luna_Angel_84 is offline  
post #15 of 59 (permalink) Old Aug 12th, 2003, 05:10 PM
Senior Member
 
Join Date: Mar 2002
Location: Belfast, N.Ireland
Posts: 4,491
                     
The thing is, the timer thing comes up as soon as I come online. Some people seem to have a gap but my bloody thing starts its 60 second countdown. I mean how long will the patch take to download?

Jen, is it cold out there or are you just pleased to see me?
Luna_Angel_84 is offline  
Reply

Quick Reply
Message:
Options

Register Now



In order to be able to post messages on the TennisForum.com forums, you must first register.
Please enter your desired user name, your email address and other required details in the form below.

User Name:
Password
Please enter a password for your user account. Note that passwords are case-sensitive.

Password:


Confirm Password:
Email Address
Please enter a valid email address for yourself.

Email Address:
OR

Log-in









Human Verification

In order to verify that you are a human and not a spam bot, please enter the answer into the following box below based on the instructions contained in the graphic.



Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page



Posting Rules  
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

 
For the best viewing experience please update your browser to Google Chrome