BetaONE will rise again!


Reply
  #21  
Old 13th Aug 03, 12:39 AM
micha's Avatar
micha micha is offline
Junior Member
 
Join Date: Sep 2001
Posts: 22
micha
... hm, any of you with infections run zonealarm or another firewall that would stealth your ports? As far as I understand the worm doesn't enter by mail but by a process similliar to portscans?

greetz, micha
Reply With Quote
  #22  
Old 13th Aug 03, 12:57 AM
Firefox's Avatar
Firefox Firefox is offline
Administrator
 
Join Date: Jun 2003
Location: State of Shock
Posts: 682
Firefox has disabled reputation
Quote:
Originally Posted by (E3 @ Aug 12 2003, 03:33 PM)
It apparently sets a reg key that turns off your windows update. You're right, it is a clever little bugger! I just took a look at my firewall logs and you wouldn't believe the hundreds (maybe thousands now!) of blocked attempts on port 135 from IP's everywhere. If you've got a firewall log you've got to read it to believe it (I love my ZoneAlarm Pro ).

All the best,
E3


Have you installed the Patch yet? I am curious if that is why your log is so full.  I am using ZA as well, but my logs are normal. 
Reply With Quote
  #23  
Old 13th Aug 03, 01:03 AM
HotRod HotRod is offline
Senior Member
 
Join Date: Jul 2001
Location: Jersey
Posts: 285
HotRod is an unknown quantity at this point
Send a message via ICQ to HotRod
I didn't get this, Luckily, Even though I was patched I had tons of probes on 135 and 445 until about 8:30 last night.  Looks like Comcast is filtering those ports right now from what I have read at other places.  Kind of nice not having a log full of 135 & 445 probes.
Reply With Quote
  #24  
Old 13th Aug 03, 02:30 AM
PcDad's Avatar
PcDad PcDad is offline
Senior Member
 
Join Date: Jul 2001
Location: Upstate NY
Posts: 134
PcDad is an unknown quantity at this point
Send a message via AIM to PcDad Send a message via MSN to PcDad Send a message via Yahoo to PcDad
For anyone who hasn't done this yet (or can't)....The fix and the patch...

Near as I can tell, you should run the patch first, then the fix...
Reply With Quote
  #25  
Old 13th Aug 03, 02:41 AM
mikeh420's Avatar
mikeh420 mikeh420 is offline
Senior Member
 
Join Date: Nov 2002
Location: Los Angeles, CA, USA
Posts: 222
mikeh420
Send a message via ICQ to mikeh420 Send a message via AIM to mikeh420 Send a message via Yahoo to mikeh420
I ran the FixBlast on a friends PC that was hit, and 5 hours later it's still hasn't found anything. First time, I let it go for an hour with nothing. Don't they test these things before they release them?

P.S. Stinger from Mc Afee worked just fine, found a few other viruses too. The PC is back to normal.
Reply With Quote
  #26  
Old 13th Aug 03, 04:36 AM
Sephiroth Sephiroth is offline
BetaONE Supporter
 
Join Date: Jul 2001
Posts: 1,979
Sephiroth is an unknown quantity at this point
Send a message via MSN to Sephiroth
i didn't get this either, though my mom did, i just got back from fixing hers

if anybody else gets this and they have a problem with it shutting down so quick, when you get the shutdown message, quickly open a command prompt and type shutdown -a , that'll abort the shutdown and let you work
Reply With Quote
  #27  
Old 13th Aug 03, 01:47 PM
E3 E3 is offline
Senior Member
 
Join Date: Jul 2001
Posts: 254
E3
Quote:
Originally Posted by (Phogphire @ Aug 13 2003, 08:27 AM)
Quote:
Originally Posted by (E3 @ Aug 12 2003, 03:33 PM)
It apparently sets a reg key that turns off your windows update. You're right, it is a clever little bugger! I just took a look at my firewall logs and you wouldn't believe the hundreds (maybe thousands now!) of blocked attempts on port 135 from IP's everywhere. If you've got a firewall log you've got to read it to believe it (I love my ZoneAlarm Pro ).

All the best,
E3


Have you installed the Patch yet? I am curious if that is why your log is so full.* I am using ZA as well, but my logs are normal.*


Yep... installed KB823980 about two days after it came out. ZAP has everything running in stealth per Shields Up at grc.com too. Just to give you some real numbers I looked at my latest logs... View is set to show last 500 entries, and that only spans about the last two hours now... With about 10 exceptions they're all attempts on 135/137. Most of the source's are IP's with the same first or second octet range as mine (Australia). Looks like lots of peeps down here neglected to update . Maybe that's why it's quieter up there 'North of the 45th Parallel' .

All the best,
E3
Reply With Quote
  #28  
Old 13th Aug 03, 06:27 PM
BlackMantis BlackMantis is offline
Senior Member
 
Join Date: Jul 2003
Posts: 111
BlackMantis
Thanks for the fixblast pcdad... ran it on my cousin's computer and it worked like charm.. 
Reply With Quote
  #29  
Old 13th Aug 03, 10:33 PM
darklord's Avatar
darklord darklord is offline
BetaONE Supporter
 
Join Date: Sep 2001
Location: uk
Posts: 122
darklord is an unknown quantity at this point
how does this virus work as soon as i logged on to isp trend found this virus on my pc being auto downloaded from ??

this happens everty time i log on
Reply With Quote
  #30  
Old 13th Aug 03, 10:56 PM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
It's auto starting when you boot up. You need to check all your startup items and remove the altered ones. Try running the repair tool posted in this thread
__________________

Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT +1. The time now is 04:25 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.