VIRUS ALERT!!!!
Moderator: Moderators
VIRUS ALERT!!!
Posted by 2eX Jubei @ 21:43 GMT, 11 Aug 2003 - iMsg*, Reply (Major News: HW)
--------------------------------------------------------------------------------
There was a worm set loose on the internet early yesterday evening called w32.blaster.worm. This basically causes ur computer to restart after 50 seconds with the following message:
'Windows must now restart because the remote procedure call (RPC) service terminated unexpectedly'
Some more information on the virus can be found here:
http://www.microsoft.com/security/secur ... 03-026.asp
http://securityresponse.symantec.com/av ... .worm.html
Take the following steps to get rid of this menace:
U can stop the computer restarting so that can deal with the problem by doing the following:
Click on start > run > type ‘services.msc’ > scroll down to the top remote procedure call (rpc) > right click on this and select properties > click on the recovery tab > change all 3 failure boxes to take no action instead of restart > click on apply and then ok > close services.msc.
Now that u can stay online, take urself off to:
http://windowsupdate.microsoft.com
Grab the security updates from microsoft to close off the ports that the worm uses on ur system.
Tool for removing the virus has been released by symantec here:
http://securityresponse.symantec.com/av ... .tool.html
Job done =]
*TAKEN FROM ESREALITY.COM*
Posted by 2eX Jubei @ 21:43 GMT, 11 Aug 2003 - iMsg*, Reply (Major News: HW)
--------------------------------------------------------------------------------
There was a worm set loose on the internet early yesterday evening called w32.blaster.worm. This basically causes ur computer to restart after 50 seconds with the following message:
'Windows must now restart because the remote procedure call (RPC) service terminated unexpectedly'
Some more information on the virus can be found here:
http://www.microsoft.com/security/secur ... 03-026.asp
http://securityresponse.symantec.com/av ... .worm.html
Take the following steps to get rid of this menace:
U can stop the computer restarting so that can deal with the problem by doing the following:
Click on start > run > type ‘services.msc’ > scroll down to the top remote procedure call (rpc) > right click on this and select properties > click on the recovery tab > change all 3 failure boxes to take no action instead of restart > click on apply and then ok > close services.msc.
Now that u can stay online, take urself off to:
http://windowsupdate.microsoft.com
Grab the security updates from microsoft to close off the ports that the worm uses on ur system.
Tool for removing the virus has been released by symantec here:
http://securityresponse.symantec.com/av ... .tool.html
Job done =]
*TAKEN FROM ESREALITY.COM*
The other links wouldn't work for me (includes "..."). Here are some fixed ones.
http://securityresponse.symantec.com/av ... .worm.html
http://securityresponse.symantec.com/av ... .tool.html
http://securityresponse.symantec.com/av ... .worm.html
http://securityresponse.symantec.com/av ... .tool.html
LOL.From symantec's description wrote:The worm contains the following text, which is never displayed:
I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ? Stop making money and fix your software!!
Hehe.
https://grc.com/x/portprobe=135 to check to see if the port it attacks you on is open or closed... Mine is in stealth mode... but i've got a hardware firewall protecting it..
No fancy protection need...
.. just a simple SOFTWARE firewall will make you port stealth for the first thing. The later is that if you just update your windows this will not affect unless you consider the fact that the net will be downsized in capacity.
Laters report say that a new "transformation" is spreading which probably will make most anti virus software useless.. use firewall and caustion instead. The program handling it all is TFTP which is a common program in windows.. this makes in possible for the mask to get in a mess your system up.
Laters report say that a new "transformation" is spreading which probably will make most anti virus software useless.. use firewall and caustion instead. The program handling it all is TFTP which is a common program in windows.. this makes in possible for the mask to get in a mess your system up.
People on 9x have enuf troubles without needing an extra one, and the people with blaster obviously ignored all the security warning posts, which were going round for at least a week or two before blaster came out.mai9 wrote:I was told that people using win9x can't get that blaster. Maybe it's time to 'upgrade'?
I actually wasn't sure which thread to put this under, the fallout one or this one, but oh well, whatever.
http://www.wired.com/news/infostructure ... 81,00.html "Are You a Good or a Bad Worm?"
http://securityresponse.symantec.com/av ... .worm.html
I don't know what to beleive anymore...
http://www.wired.com/news/infostructure ... 81,00.html "Are You a Good or a Bad Worm?"
http://securityresponse.symantec.com/av ... .worm.html
What a nice little worm... thank you Mr. Worm!Symantec wrote:W32.Welchia.Worm does the following:
Attempts to download the DCOM RPC patch from Microsoft's Windows Update Web site, install it, and then reboot the computer.
Checks for active machines to infect by sending an ICMP echo request, or PING, which will result in increased ICMP traffic.
Attempts to remove W32.Blaster.Worm.
I don't know what to beleive anymore...