Page 1 of 2
Virus Alert
Posted: Tue Aug 12, 2003 8:07 pm
by riverbravo
There is a nasty virus called the "worm blaster".
I picked it up.There is a patch and a removal tool.
The bug attacks windows and causes the system to shutdown in 1 min.You cant stop it from shuttimng down,you can only watch the time tick down as you try to stop it.
I got it last night.I got the fix it patch and it still didnt root out the foul abomination.So I had to pull out the big guns and get the removal too from symatec.
symatec
It will also cause you to not log on for a bit after removal,at least it did me,maybe it attacked my ISP?
GOOD lUCK I hope you guys are in the clear.
better check out youre systems just in case.
Posted: Tue Aug 12, 2003 11:33 pm
by Blunderbuss
Do you know where you picked this virus up from?
Posted: Tue Aug 12, 2003 11:46 pm
by Marc von Martial
Posted: Tue Aug 12, 2003 11:48 pm
by Marc von Martial
better check out youre systems just in case.
No, start spending that 20$ on Norton Antivirus or McAffee

. I never had a virus struck me in 2 years now.
Posted: Tue Aug 12, 2003 11:51 pm
by Mr.Frag
This virus is all over the place. It attacks based on the RPC endpoint mapper so pretty much every single machine running Windows can get hit by it.
Part of the virus actually does Denial of Service attacks on Microsoft to try and prevent you from being able to download the service packs and fixes required.
Take this one seriously, it has probably hit about a 1/4 of the PC's on the planet so far and is spreading like wildfire now.
Information:
http://www.symantec.com/avcenter/venc/d ... .worm.html
There is a removal tool located there, but simply removing it does not fix the problem as you can be re-infected.
Microsoft Patch:
http://www.microsoft.com/technet/treevi ... 03-026.asp
(hey Marc, quit typing faster then me!)
Posted: Tue Aug 12, 2003 11:59 pm
by Fallschirmjager
Best protection is just to be careful
I have all cookies blocked except those I allow
I dont open ppl from e-mail I do not know
Is someone sends me a e-mail and I know them..but I they did not tell me they are putting an attachment with it...I will not open it
I never let webpages auto-download software
I always format disks and cds before using them
A little common sense will go a long way
Posted: Wed Aug 13, 2003 12:24 am
by Marc von Martial
Originally posted by Mr.Frag
This virus is all over the place. It attacks based on the RPC endpoint mapper so pretty much every single machine running Windows can get hit by it.
Part of the virus actually does Denial of Service attacks on Microsoft to try and prevent you from being able to download the service packs and fixes required.
Take this one seriously, it has probably hit about a 1/4 of the PC's on the planet so far and is spreading like wildfire now.
Sounds like a "Terminator 3" advertising gag, LOL
Posted: Wed Aug 13, 2003 12:25 am
by Mr.Frag
Hey Fall, unless you are specifically running some port blocking protection, you are wide open to this particular exploit.
Open up a command prompt and type:
netstat -an | more
You will see on the very first page:
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
Thats the attack port. Unless you are blocking port 135 from the Internet, you can be hit.
Any of the many Personal Stealth Firewalls can protect you, but really, I agree with Marc, anyone not running some form of virus protection these days is simply playing with loaded dice. It is just a matter of time.
This actual issue and it's fix was released on the 17th last month, yet today, people are still getting creamed by it because they always think they are safe. :rolleyes:
Posted: Wed Aug 13, 2003 12:27 am
by Les_the_Sarge_9_1
Hear hear Fallschirmjager
I have my anti virus set
anti social mode generally speaking, but I surf at will and have not had troubles.
The main reason is I DO NOT open email I don't recognise ever.
I have found that careless thinking with email goes the farthest with doing damage.
In aaaaaaaall the years online, I have only been effected by viruses twice (that's since 1990 in my case). And in both cases I had downloaded an infected file.
Posted: Wed Aug 13, 2003 12:28 am
by Fallschirmjager
I only have one port open
and unlike my dumbass friends...I turn my broadband off when not in use
added protection..and its courteous to other users
Posted: Wed Aug 13, 2003 12:33 am
by Marc von Martial
I only have one port open
And that is ?
Posted: Wed Aug 13, 2003 12:40 am
by Marc von Martial
Seriously youhave way more open, that´s for sure.
Posted: Wed Aug 13, 2003 1:01 am
by Procrustes
This one takes advantage of specific holes in Windows. If you do the "windows update" you can't get hit. But you should still run an antivirus and a firewall if you can. (I finally got my McAfee firewall configured right - been amazed at the number of intrusive pings and queries that get stopped. Last week even had a couple of people searching for open ports on my home computer.)
Posted: Wed Aug 13, 2003 1:44 am
by Marc von Martial
been amazed at the number of intrusive pings and queries that get stopped.
Oh yes, I have some 50 security warning per day beeing blocked by my software firewall, and that´s the stuff that get through the Linksys router hardware firewall
Port Scans are a piece of cake, anybody can do them.
Posted: Wed Aug 13, 2003 1:53 am
by Bobthehatchit
I work for an IT firm, and it been doing nuts all day lots of people got stung by this and lots more will tomorrow.
Its gona be another crappy day tomorrow, who ever produced this little gem need kneecapping.

Posted: Wed Aug 13, 2003 1:55 am
by Pawlock
Hmm, I picked that little Motherf*cker up last week and it drove me bonkers I can tell you.
It shuts down your pc after 1 min and timed for 1 min. Well it was a nighmare to saty online long enought to d/load the nessecary file to eradicate it.
Posted: Wed Aug 13, 2003 1:59 am
by Bobthehatchit
Originally posted by Pawlock
Hmm, I picked that little Motherf*cker up last week and it drove me bonkers I can tell you.
It shuts down your pc after 1 min and timed for 1 min. Well it was a nighmare to saty online long enought to d/load the nessecary file to eradicate it.
You can stop the shut down process by going:
Click Start/Run/ type "shutdown /a" without the "" and run this
Posted: Wed Aug 13, 2003 2:18 am
by Marc von Martial
Originally posted by Bobthehatchit
I work for an IT firm, and it been doing nuts all day lots of people got stung by this and lots more will tomorrow.
Its gona be another crappy day tomorrow, who ever produced this little gem need kneecapping.
But then again these guys secure jobs, LOL

.
Posted: Wed Aug 13, 2003 2:36 am
by Bobthehatchit
Originally posted by Marc Schwanebeck
But then again these guys secure jobs, LOL
.
I can live without that kind of help!
Althought the company did shift every copy of av software in the place! And quite a few copies that we don't have as of yet..... althought the customers don't need to know that!:D
Posted: Wed Aug 13, 2003 3:34 am
by Marc von Martial
I can live without that kind of help!
Yeah, I hear you. I did this kind of "support" in the company Iworked before

. Erasing viruses and stuff on a weekly basis, and that with every single machine "secured"
