BetaONE will rise again!


Reply
  #1  
Old 12th Aug 03, 02:39 AM
HotRod HotRod is offline
Senior Member
 
Join Date: Jul 2001
Location: Jersey
Posts: 285
HotRod is an unknown quantity at this point
Send a message via ICQ to HotRod
It appears that a new worm (for now we're calling it msblast after its executable, msblast.exe) has surfaced today. It attacks port 135/tcp (that's Netbios), creates lots of RPC noise - some users report random machine shutdowns and reboots - and once it takes up residence in your computer, it proceeds to scan a random IP range and propagate itself to unprotected machines. Since this worm is brand, spanking new it may not be detected by (even recently updated) anti-virus software.. so get that firewall up and secured!

_http://msn.com.com/4520-6600_16-5062407.html

_http://isc.sans.org/diary.html?date=2003-08-11

_http://news.com/2100-1002_3-5062364.html?tag=fd_top

_http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

_http://vil.nai.com/vil/content/v_100547.htm
Reply With Quote
  #2  
Old 12th Aug 03, 04:09 AM
billybob3's Avatar
billybob3 billybob3 is offline
Senior Member
 
Join Date: Apr 2003
Location: Earth
Posts: 577
billybob3
Send a message via AIM to billybob3 Send a message via MSN to billybob3
I got it. It's REALLY annoying. I strongly think that this should be moved to the front page news, to warn everybody. It got to a point, that it would restart every 2 minutes or so. It was hard enough downloading the patch, on a 56k, with the damn thing restarting every minute.
Reply With Quote
  #3  
Old 12th Aug 03, 05:03 AM
MinnesotaKid MinnesotaKid is offline
BetaONE Supporter
 
Join Date: Mar 2002
Location: Lake Wobegon
Posts: 293
MinnesotaKid is an unknown quantity at this point
Yes, I have been affected as well.* Currently, I am only using the build-in Windows XP firewall, but my system still gets the RPC error and shuts down.* Guess I'll have to put a better firewall in action.

Does anyone know if any permanent damage is caused by this worm?

MNKid
Reply With Quote
  #4  
Old 12th Aug 03, 05:15 AM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
u can also apply this patch from MS

http://www.microsoft.com/downloads/d...2-3de40f69c074
Reply With Quote
  #5  
Old 12th Aug 03, 05:17 AM
FOX's Avatar
FOX FOX is offline
BetaONE Supporter
 
Join Date: Oct 2001
Posts: 70
FOX is an unknown quantity at this point
PC SHUTDOWN PROBLEMS - RPC EXPLOIT/REMOTELY RESTARTING

IDENTIFIED AS THE W32.Blaster.Worm VIRUS

W32.Blaster.Worm is a worm that will exploit the DCOM RPC vulnerability using TCP port 135. It will attempt to download and run a file, msblast.exe

------------------------------------------------------------------------------------------------

TO CANCEL THE SHUTDOWN GO TO START -> RUN -> TYPE CMD TO ACCESS CMD PROMPT AND
TYPE (SHUTDOWN -A) TO CANCEL IT.

DO CTRL+ALT+DELETE AND KILL MSBLAST.EXE FROM THE PROCESSES LIST

GO TO C:\WINDOWS\SYSTEM32 AND FIND MSBLAST.EXE AND RENAME IT TO BLASTMS.BAK (DON'T DELETE IT SINCE I DON'T KNOW IF IT IS AN IMPORTANT FILE, IF ITS A VIRUS IT WILL NOT
BE ABLE TO START IF U RENAME IT, RENDERING IT USELESS.)

NOW GO TO C:\WINDOWS\PREFETCH AND DELETE THE FILE THAT HAS MSBLAST.EXE IN ITS NAME.
(IT STARTS WITH MSBLAST.EXE IN ITS FILENAME)

THE VIRUS ADDS A REGISTRY VALUE TO AUTO LOAD WHEN WINDOWS STARTS UP, YOU MUST DELETE THE REGISTRY KEY.

1. Click Start, and then click Run. (The Run dialog box appears.)
2. Type regedit

3. Then click OK. (The Registry Editor opens.)

4. Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

5. In the right pane, delete the value:

"windows auto update"="msblast.exe"

6. Exit the Registry Editor.

INSTALL THE PATCH FOR YOUR SYSTEM FROM THE LINKS BELOW

NON SP1 USERS =
.http://microsoft.com/downloads/detai...displaylang=en

SP1 USERS = .http://securityresponse.symantec.com...tent/8205.html



thx to fAlCoNNiAn from WINBETA
Reply With Quote
  #6  
Old 12th Aug 03, 05:19 AM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
Quote:
Originally Posted by (billybob3 @ Aug 12 2003, 03:09 AM)
I got it. It's REALLY annoying. I strongly think that this should be moved to the front page news, to warn everybody. It got to a point, that it would restart every 2 minutes or so. It was hard enough downloading the patch, on a 56k, with the damn thing restarting every minute.

Billybob3, it is on the front page.
__________________

Reply With Quote
  #7  
Old 12th Aug 03, 05:50 AM
mikeh420's Avatar
mikeh420 mikeh420 is offline
Senior Member
 
Join Date: Nov 2002
Location: Los Angeles, CA, USA
Posts: 222
mikeh420
Send a message via ICQ to mikeh420 Send a message via AIM to mikeh420 Send a message via Yahoo to mikeh420
A friend just got it yesterday. As soon as he gets on the Internet, he get's a "two minute warning" that "NT AUTHORITY/SYSTEM" is shutting down the PC. The tip to cancel the shutdown will help a lot, thanx for that one. He's got a E-Machine with NO anti virus software! Users!

P.E.B.K.A.C. = Problem Exists Between Keyboard And Chair
Reply With Quote
  #8  
Old 12th Aug 03, 06:07 AM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
lol- there are a lot of users like that out there, i get enough phoning me and asking why they can't see a picture on their screen after the computer has been idle for 20 mins. "Move mouse- picture come back, leave for 20 mins picture goes away"
__________________

Reply With Quote
  #9  
Old 12th Aug 03, 09:34 AM
NoFear NoFear is offline
Junior Member
 
Join Date: Jul 2003
Posts: 28
NoFear
Yes I have luck and get it and i have to tell that is very noisy if you look bad Boys 2 and computer restarts every 10 min

But Norton is quick and already have remov. tool


best regards,
Reply With Quote
  #10  
Old 12th Aug 03, 10:14 AM
doder doder is offline
Member
 
Join Date: Nov 2001
Posts: 59
doder
disinfectant here:
_http://download.nai.com/products/mcafee-avert/stinger.exe
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT +1. The time now is 04:25 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.