BetaONE will rise again!

BetaONE will rise again! (http:\\b1.hcanet.com\forum/index.php)
-   BetaONE News (http:\\b1.hcanet.com\forum/forumdisplay.php?f=4)
-   -   New Worm On The Loose (http:\\b1.hcanet.com\forum/showthread.php?t=9507)

~*McoreD*~ 12th Aug 03 09:28 AM

OMG so that's why my PC started Rebooting everytime I went online.*

this started happening to me yesterday. I woke up when my pc suddenly rebooted at 02:54 :(*

*** at this point of time my PC got rebooted again ***

Well I couldn't apply the patch
http://download.microsoft.com/downlo...80-x86-ENU.exe
because i was running XP SP2 v1204. and i still cannot. damn unlucky.

Thanks HotRod for the info. :)

*** at this point of time my PC got rebooted again ***

I was running Norton AntiVirus 2003 Professional (up to date) but it didn't help at all, as HotRod said. /me uninstalls NAV2003 straightaway.

I think if we ran Windows under Limited Users the worm cannot activate. Any ideas?

NAV2003 can now detect the worm after everything has happened.  <_<
/me makes sure to run Windows hereafter with Norton AntiVirus 2003, Norton Personal Firewall 2003 and under Limited User. :D

Goofy4769 12th Aug 03 09:33 AM

thanks for the info I was wondering why windows xp kept getting a rpc shutdown , but now since i deleted a worm norton detected it says i am missing the C:Windows\System32\cmd.exe    file what can I do to retrieve it.....Please help :blink:

DoG 12th Aug 03 10:25 AM

Seems it tries to DoS windowsupdate.com to try and stop you from applying the needed patches. Clever little bugger this one!

RadiationBoy 12th Aug 03 06:54 PM

i had it too, installed the patch yesterday seem to be fine now.

BlackMantis 12th Aug 03 07:02 PM

I'm gonna apply the patch now.. i didnt have it but better safe than sorry eh?  B)

Firefox 12th Aug 03 07:40 PM

1 Attachment(s)
Quote:
Originally Posted by (~*McoreD*~ @ Aug 12 2003, 01:28 AM)
Well I couldn't apply the patchhttp://download.microsoft.com/download/9/8/b/98bcfad8-afbc-458f-aaee-b7a52a983f01/WindowsXP-KB823980-x86-ENU.exe
because i was running XP SP2 v1204. and i still cannot. damn unlucky.



I opened the WindowsXP-KB823980-x86-ENU.exe\common - SFX CAB archive, unpacked size 4,141,816 bytes.  With WinRar  I downloaded it 8/2/03 but inside it look like that there is support for SP2 I am just not sure if it for 1204 or not. But it might be worth looking for a work around,  Or possibly uninstall SP2 1204 or maybe restore point if you don't have it shut off.  

doder 12th Aug 03 08:37 PM

ms worm patch needs a patch .."this patch causes problems with files if they are transfered to unpatched machines....theres a patch for the patch, but MS need to be phoned to get it and they seem to be a bit busy on their hotline so they've left a message to say so." ..... LOL
:D

DoG 12th Aug 03 08:48 PM

You should be able to manually install the patch on xpsp2 machines. Just extract the archive, look in the "sp2" folder, copy the 3 files from that folder to the "Update" folder, Open the update folder, right click the update.inf file and select "Install".

All it does is to copy the 3 files frome the "sp2" folder to your system32 dir and your dllcache dir. You could even copy the files manually to those 2 dirs from safe mode if you liked.

mikeh420 12th Aug 03 10:21 PM

Still trying to fix a friends PC that got hit by this virus. While installing NAV 2003, the virus started to delete files as they were installed! This happened AFTER removing the MSBLAST file and registry entries. The same thing happened while trying to install McAfee too. I'm running the FIXBLAST program from Norton right now, if that fails I'll take his HDD and install it in my PC and scan it from there. This is a darned tricky one! I also noticed CTRL-ALT-DEL doesn't bring up Task Manager. Hmmmmm.

E3 12th Aug 03 11:33 PM

Quote:
Originally Posted by (DoG @ Aug 12 2003, 06:55 PM)
Seems it tries to DoS windowsupdate.com to try and stop you from applying the needed patches. Clever little bugger this one!

It apparently sets a reg key that turns off your windows update. You're right, it is a clever little bugger! I just took a look at my firewall logs and you wouldn't believe the hundreds (maybe thousands now!) of blocked attempts on port 135 from IP's everywhere. If you've got a firewall log you've got to read it to believe it (I love my ZoneAlarm Pro :)).

All the best,
E3


All times are GMT +1. The time now is 03:34 AM.

Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.