| Pages: [1] 2 :: one page |
| Author |
Thread Statistics | Show CCP posts - 0 post(s) |

The Reverend
|
Posted - 2003.08.12 21:07:00 -
[1]
The Blaster Worm virus is one of the most wide spread damaging virus's to hit the world in recent times, estimates indicate that up to 70% of all computers have been effected.
Here are a number of solutions for it. (Some taken from this board)
1. http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
This is a new tool developed to help remove this virus.
2. This is a process that can be followed and also includes the patch needed to close the loop.
There's one thing you can do to stop the virus from crawling all over your computer..
1. START > RUN > REGEDIT
2. go to HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN and if you see msblast.exe at Windows auto update, delete it.
3. Go to the Task Manager, and select msblast.exe and end the process.
4. Get the security patch and do not install it.
WINDOWS 2000 PROFESSIONAL
http://www.microsoft.com/downloads/...&displaylang=en
WINDOWS XP
http://www.microsoft.com/downloads/...&displaylang=en
If a reboot countdown starts during the download, stop it by:
START > RUN > Shutdown -a press enter.
Restart your computer in safe mode.
START > RUN > cmd
del C:\WINNT\msblast.exe (or whatever your system folder)
Now install the security patch.
Restart.
I would advice you use the first process unless you know what you are doing.
(and who said m0o was in to total destruction )
Seriously guys - this thing has crippled all my machines, don't let it do the same for you.
m0ovie links |

Krackken
|
Posted - 2003.08.12 21:11:00 -
[2]
OT Post prolly get locked in a bit...
But - Any idea how you got it? I'd like to steer clear of it
|

drunkenmaster
|
Posted - 2003.08.12 21:13:00 -
[3]
This hit a mates PC the other day. He has XP, and because it closes every option of removing it (very clever. bastards) there is not a great deal you can do.
My friend got hit before it was major news though, so didn't know of these fixes.
He did a system rollback to a few days before. it fixed the problem, and he was able to remove the crap.
But, for the love of Drunk, be careful, people. .
|

Nerhtal Al'Thali
|
Posted - 2003.08.12 21:17:00 -
[4]
cheers for the info and the warning
"Game Experience And Dev Opinions May Change With The Time Of Day During Online Play" Oveur
"First in, last out" Bridgeburner Motto |

The Reverend
|
Posted - 2003.08.12 21:20:00 -
[5]
As a further warning - this thing will attack any computer thats connected to the net and does not have the relevent patch (it got me via my brothers computer upstairs) - it will then spread throughout the network and infect each computer in turn. Anyway - good luck. (Shuts down to try and sort 5 networked computers out )
m0ovie links |

Vegeta
|
Posted - 2003.08.12 21:24:00 -
[6]
ZoneAlarm works wonders, i was on a LAN with a friend who had it.
2005.04.25 16:40:42 combat Your 1400mm Howitzer Artillery II perfectly strikes LawrenceNewton [WARAG], wrecking for 2706.9 damage.
|

Joshua Calvert
|
Posted - 2003.08.12 21:26:00 -
[7]
At least Eve runs smoothly enough for me to keep Agnitum Outpost and McAfee running in the background.
LEEEEERRRRRRRRRRROOOOOOOOOYYYYYYYYYYYYYYY! |

Jarjar
|
Posted - 2003.08.12 21:27:00 -
[8]
1. Patch 2. Get rid of it
If you do it the other way around... 1. Get rid of it 2. Get infected 3. Patch 
|

Doc Brown
|
Posted - 2003.08.12 21:29:00 -
[9]
This contains the same info as The Reverands post but with click-able links for the lazy.
The virus will infect any Windows NT, 2000 and XP machine that does not have the proper patch applied.
Microsoft has some patches for Windows that, if applied, will prevent infection: - Windows NT: Windows NT Patch - Windows 2000: Windows 2000 Patch - Windows XP: Windows XP
(For the technically minded, the security bulletin is located at Microsoft Tech Bulliten MS03-026 )
Also, Symantec has put out a tool for cleaning machines from this virus. The removal tool is located at http://securityresponse.symantec.com/avcenter/FixBlast.exe. To use the tool, all you need to do is download the FixBlast.exe file and double click on to run it. Documentation about the tool is located at Documentation about the FixBlast tool
Finally, Symantic has some information about the worm/virus _________________________________________________
There are no bad ideas, only bad implementations. |

Fenklar
|
Posted - 2003.08.12 21:35:00 -
[10]
Edited by: Fenklar on 12/08/2003 21:35:27
 
Please Sticky this thread..
Good information for all who have been afflicted with this problem. I have just spent the day doing service calls fixing this very problem.
Many people have been infected and have not figured it out yet...
|

nails
|
Posted - 2003.08.12 21:46:00 -
[11]
I belive people that use p2p programs are most vulnerable. The only computer that got infected in this house was my roomates and it spread to his fileserver. The other 9 computers in the house did not contract it, but were patched anyway. The thing sucks up a ton of bandwith, and blocks off most of the internet traffic ports to the rest of your network. Took about 20 mins to fix the infected computers. ------------------
http://ota-corps.otaku.jp -- Anime l33t level
|

Arathmon
|
Posted - 2003.08.12 21:48:00 -
[12]
Is there a known fix for a windows 98 user? I'm on XP, but the computer my dad uses is still on 98... any suggestions? --------------- I used to be in the FA. I like cookies. Eve Radio is teh pwn. |

Ulstan
|
Posted - 2003.08.12 21:49:00 -
[13]
I didn't see a link to a Windows 98 patch.
Does that mean the virus does not affect win98?
|

Jowen Datloran
|
Posted - 2003.08.12 22:01:00 -
[14]
It shouldn't go into Win 95 or any other operatings systems not mentioned already. I think it has something to do with the NTFS file system ---------------- What's a rumor on page one is a fact on page two |

agrizla
|
Posted - 2003.08.12 22:02:00 -
[15]
Can we have a little less hysteria please?
Facts :
1) this worm is an exploit of a vulnerability (RPC/DCOM) that MS fixed a month ago; 2) if you have a firewall protecting ports 0-1024 (TCP/UDP) this will not directly affect you but see 3); 3) as is common with such worms it first scans the /16 subnet and as such will (if introduced) infect all machines on that subnet. If you don't understand this here's the simple version - it'll infect everything on the LAN.
Now (as I'm getting damn tired of this) here is some advice from someone (me) who spent two boring years of my life being paid to break into companies' systems (both remotely and via social engineering):
1) Use decent antivirus programs. ie Kaspersky or Sophos. Yes they cost more but there is a reason for that; 2) Password protect all fileshares; 3) Use a decent password - doesn't have to be hard - eg use your printer name then a date then your monitor type (all one string); 4) Partition your windows machine into C: and D: and never ever allow filesharing on C: 5) Never routinely run your machine with admin privileges (not an option for XP Home users); 6) Use a "gateway-level" firewall - ie a machine (be it a router or otherwise) where all rules are applied; 7) Block all incoming ports from (the internet) 0-1024 - you don't need them and if you do then you damn well should know the risks!
Here endeth a very basic lesson. Anyone who has had problems with this worm has only themselves to blame as MS fixed the buffer overflow before the exploit became public. If your antivirus didn't pick the worm itself up well hey - I have given you advice above.
|

John Zeppe
|
Posted - 2003.08.12 22:03:00 -
[16]
Facts: 1) People don't care about updates before it's too late 2) People don't know everything just because a few (of us ) may do it.
|

Zotigh
|
Posted - 2003.08.12 22:09:00 -
[17]
This worm only affects NT machines, not PC machines.
NT Operating systems are basically:
NT 3.51 NT 4.0 Windows 2000 (NT 5.0) Windows XP Windows 2003
PC Operating systems are basically:
Windows 95 Windows 98 Windows ME
Again...the Blaster worm only affects NT operating systems.
|

MaiLina KaTar
|
Posted - 2003.08.12 22:12:00 -
[18]
*looks at the router in the other room*
*laughs*
See all this is the reason why I always tell my brother to get lost whenever he comes to ask me because he wants ports opened for some damn game 
Mai's Idealog |

Alpha Centauri
|
Posted - 2003.08.12 22:16:00 -
[19]
sorry to be dumb here but if your pc is not prompting a shut down, then your ok ? 
my pc aint doing nothing like that but im worried. :/
|

Zotigh
|
Posted - 2003.08.12 22:20:00 -
[20]
If you are using NT, you should go ahead and patch your Windows. If you are unsure of having the virus, the you could run the 'fix' provided by Symantec first, and then patch. The fix has a link to the Microsoft patch page for that particualr patch. Mind you...at times the downloading is s-l-o-w due to the current load. Here's the link to the removal tool:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html
|

agrizla
|
Posted - 2003.08.12 22:30:00 -
[21]
Quote: Facts: 1) People don't care about updates before it's too late 2) People don't know everything just because a few (of us ) may do it.
Heh - tell me about it. The amount of phone calls I've had tonight from friends who know what I used to do is scary.
I think we need a book called (no offence intended but it's true) :
"Security for gamers/leechers"
I have lost count of how many people/companies I've dealt with where there's either no firewall or someone has opened up ports and installed P2P apps.
Oh and none of you *nix buffs get complacent either - there's actually far more holes in the various daemons/services (whichever you want to call them) than there are in the current version of XP Pro. Sendmail has hundreds of the buggers - since hardly anyone knows "Vogon Poetry" (sendmail.cf) and tends to just leave it alone. 
|

Synapse Archae
|
Posted - 2003.08.12 22:39:00 -
[22]
Correct. Windows 98 is just fine for this one, confirming again why I still run it.
Windows98: because everthing else is overfeatured and underdocumented.*
*everthing else means windows versions, no starting OS wars here.
--------------------------------------------- [/IMG]http://millerfam.org/eve/synapse_logo.jpg[/IMG] Everyone deserves a chance to live. My job is to make sure they get it. |

Mitch Taylor
|
Posted - 2003.08.12 23:02:00 -
[23]
"Bill Gates! You promised win 98 would be faster, easier to use and more bug free!"
"Well it is faster......#BANG!#"
Pretty much sums up how I feel about MS Still use winXP though
|

Nirvy
|
Posted - 2003.08.12 23:03:00 -
[24]
Edited by: Nirvy on 12/08/2003 23:04:28 Thanks Rev, 1st Virus i have ever had..fck knows how i got the damn thing, it took out my gaming PC and Laptop for almost a day :\ Mercenary | The Azath |

annoing
|
Posted - 2003.08.13 00:13:00 -
[25]
I use the Windows update feature and get updates sent through every few days...but i didnt get this one. i havent suffered from this worm as yet but i patched anyway. thx for the heads up on this
>>>>>>>>>>>>>>>>>>>>>>>>>>>>> The Inquisition Long live the Inquisition Long live the Emperor Long live Amarr!
>>>>>>>>>>>>>>>>>>>>>>>>>>>>> |

RAIDAKAOZ
|
Posted - 2003.08.13 00:17:00 -
[26]
here is something that will stop u from getting it . set your windows update on manuel and set it so that it will ask u if it is ok to download. U should be ok then. ------------------
If it looks like a duck, and sounds like a duck, it is probably a chicken that CCP ****ed up. |

Azov
|
Posted - 2003.08.13 00:24:00 -
[27]
Yeah had it on my computer a few days ago, it's annoying as hell.
Patched from microsoft's website and removed it just like it was above.
TO GIVE YOU MORE TIME BEFORE SYSTEM SHUTS DOWN:
in command line type shutdown -a
|

jabb0r
|
Posted - 2003.08.13 00:26:00 -
[28]
moOblast.exe :: pay 10mill or get podded (greets ur bad worm) ----------------------------------------------
this is a signature
winamp-radio-list |

Durandal
|
Posted - 2003.08.13 00:30:00 -
[29]
Thanks all...I got the shutdown timer and RPC interface message twice today, wondered what was going on. However, I have run the FixBlast and it found nothing!! Norton did an autoupdate this afternoon and that 'may' have got rid of it but I am patching anyway just to be sure. Plz make this sticky
"Never let your sense of morals prevent you from doing what is right!"
|

Endureth
|
Posted - 2003.08.13 01:24:00 -
[30]
This is what happens when you download too much ****.
-E
|
| |
|
| Pages: [1] 2 :: one page |
| First page | Previous page | Next page | Last page |