1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

New Virus "Blaster Worm" - Beware!

Discussion in 'BBS Hangout' started by Sonny, Aug 12, 2003.

  1. Sonny

    Sonny Member

    Joined:
    Mar 20, 2001
    Messages:
    5,436
    Likes Received:
    8
    Cert.Org Link

    This worm is very dangerous and is spreading fast, patch your machines.

    Symantec Link


    save the apple/linux BS.... :p
     
  2. LonghornFan

    LonghornFan Member

    Joined:
    Sep 16, 2002
    Messages:
    15,718
    Likes Received:
    2,628
    Is your computer giving you 60 seconds to shut down? Here's some Blaster patches.

    Looks like we got another worm on the loose. I was infected this weekend.

    If you are running WinNT, Win2000, or WinXP I hope you got your latest security patch. There is a nasty virus that is exploiting a security hole and causing the computer to shutdown after an internet connection is established. My friend works for a major isp in the webhosting department and he says they have been getting slammed with calls about this all day. He says he has never seen a virus hit so many people so fast.

    The older Microsoft operating systems can be infected but they they do not have the "feature" that the virus is using to cause a shutdown.

    Here are the links to the Microsoft security patches for you folks with the fancy operating systems.

    WInXP Patch

    Win2000 Patch

    WinNT4.0 Patch

    Running a fire wall and closing port 135 works well too (along with every other port you don't need).

    Click this link to check if it's open...
    https://grc.com/x/portprobe=135

    It is not a virus, it is a worm. It does not come from email, it comes straight through port 135 from other infected machines.

    This worm exploits an open vulnerability in Windows and you do not have to do anything but be on the Internet unprotected for it to affect you.

    Read more:

    http://www.cert.org/advisories/CA-2003-20.html

    EVERYONE should look into getting a personal firewall for their PC. ZoneAlarms, Tiny, Norton - there are a ton of them out there. Antivirus alone is no longer enough - by the time you need antivirus it is too late!

    This looks like a very informative site too:

    http://www.firewallguide.com/

    Also, www.downloads.com offers Sygate for free. Very good firewall in my opinion, but complicated when figuring out how to block certain ports.
     
    #2 LonghornFan, Aug 12, 2003
    Last edited: Aug 12, 2003
  3. mr_gootan

    mr_gootan Member

    Joined:
    May 23, 2001
    Messages:
    1,616
    Likes Received:
    121
    Yeah, I just got hit last night.(Windows XP home)

    Obviously you're going to have a hard time downloading stuff with this problem. Here's some steps to get to the point of actually being able to download. (or you could dowload the patch from an uninfected machine)

     
  4. Mulder

    Mulder Member

    Joined:
    Nov 20, 1999
    Messages:
    7,118
    Likes Received:
    81
    Damn no fair! :D





    apple rules...
     
  5. A-Train

    A-Train Member

    Joined:
    Jan 1, 2000
    Messages:
    15,997
    Likes Received:
    39
    "Blaster Worm"....that sounds like a pretty bad ass video game title...
     
  6. moestavern19

    moestavern19 Member

    Joined:
    Dec 8, 1999
    Messages:
    39,003
    Likes Received:
    3,641
    does anybody know how the remove this thing? My parents computer was infected last night and It shuts the computer down before I could download a Remover.
     
  7. FlyerFanatic

    FlyerFanatic YOU BOYS LIKE MEXICO!?! YEEEHAAWW
    Supporting Member

    Joined:
    Mar 25, 2002
    Messages:
    7,457
    Likes Received:
    189
    What if u have win98? can the worm work? if so what patch should i d-load?
     
  8. Apollo Creed

    Apollo Creed Contributing Member

    Joined:
    Aug 25, 2001
    Messages:
    4,449
    Likes Received:
    3
    This worm has made me it's b**** for a couple days now, but I think I've got it figured out...

    First of all, the shutdown thing is weird. Even if you can stop that from happening, the worm is still repeatedly infecting the system. Something odd about it though is that not only is there an msblast.exe infecting, but there are these two odd, out of place folders in the Windows folder on your drive.

    Run a search for the file svchost.exe...

    While that's a normal file, some other long strange file names will come up along with it. Something like a svchost.exe.dmpp or so. Open the source folder (there are two of them) and you'll see that there are little notepad files, and if you open them up and read them, you'll see a bunch of code, and the exact text that comes up when your computer is shutting down. Delete both of those files and the folders that contain them.

    Now, open up your Windows task manager and shutdown msblast.exe

    Head into Windows, then System32 and find msblast.exe and delete it. Then go to run, regedit, then go to:

    HKEY_LOCAL_MACHINE/SOFTWARE/MICROSOFT/WINDOWS/RUN

    And find the file called 'windows auto update' or msblast.exe and delete it.

    Now download that patch!

    Hope this was somewhat helpful to you.
     
  9. LonghornFan

    LonghornFan Member

    Joined:
    Sep 16, 2002
    Messages:
    15,718
    Likes Received:
    2,628
    Ugh, I know I'm having a massive brainfart, but how do I find/get into the Windows folder on my hardrive?

    Thanks for that information, too. Big help! :) I've had this worm since Friday night, and there's no telling how many others my modem has helped infect.
     
  10. Pole

    Pole Houston Rockets--Tilman Fertitta's latest mess.

    Joined:
    Feb 15, 1999
    Messages:
    8,568
    Likes Received:
    2,735
    Apollo....it hasn't hit me yet, but I've got a bunch of people asking me about it. The people who are complaining about it to me tell me their machines are shutting down within a few seconds of logging on. Are you doing this through safe mode? How did you get your machine to stop shutting down. From your instructions, you obviously are working IN windows, so how did you get to the point where you can do that?
     
  11. ima_drummer2k

    ima_drummer2k Member

    Joined:
    Oct 18, 2002
    Messages:
    36,414
    Likes Received:
    9,359
    Or the name of a male porno star....and his "worm".
     
  12. Baqui99

    Baqui99 Member

    Joined:
    Jul 11, 2000
    Messages:
    11,495
    Likes Received:
    1,231
    Oh no. I'd better get tested. I was online unprotected for about 30 minutes last night. :)
     
  13. LonghornFan

    LonghornFan Member

    Joined:
    Sep 16, 2002
    Messages:
    15,718
    Likes Received:
    2,628
    My IT guy fixed his PC last night by logging on, but not connecting through his modem until he ran the 'msconfig' and deleted the program from loading during startup.

    I knew as soon as I hit submit I threw a hanging curve that someone would jack out of the park. :D
     
  14. Apollo Creed

    Apollo Creed Contributing Member

    Joined:
    Aug 25, 2001
    Messages:
    4,449
    Likes Received:
    3
    Well, maybe I'm one of the lucky ones, but I got about five minutes on my computer each time before it would initate the shutdown...

    And LonghornFan, to get to your windows folder, go through my computer, drive c, then windows....
     
  15. Kam

    Kam Member

    Joined:
    Jan 16, 2002
    Messages:
    30,476
    Likes Received:
    1,322
    I just downloaded the xp patch.
    Then my compuer tells me i am low on space.
     
  16. Sonny

    Sonny Member

    Joined:
    Mar 20, 2001
    Messages:
    5,436
    Likes Received:
    8
    Start - All Programs - Accessories - System Tools - Disk Cleanup


    We haven't been hit by the worm yet, several of our other offices have though. Actually one of our users come in from home and had it on his laptop but his ant-virus got updated and stopped it.
     
  17. Dr of Dunk

    Dr of Dunk Clutch Crew

    Joined:
    Aug 27, 1999
    Messages:
    46,633
    Likes Received:
    33,635
    I emailed our network admin about this awhile ago. He apparently patched everyone's machine weeks ago. Keep up-to-date with those patches people... it's not difficult. A few clicks and all this can be avoided.
     
  18. countingcrow

    countingcrow Member

    Joined:
    May 7, 2000
    Messages:
    2,582
    Likes Received:
    25
    Quick question: Should there be a programe running called "msblast.exe" when I open my task manager?
     
  19. Sonny

    Sonny Member

    Joined:
    Mar 20, 2001
    Messages:
    5,436
    Likes Received:
    8
    No! You've been infected.

    Check the links to remove it.
     
  20. countingcrow

    countingcrow Member

    Joined:
    May 7, 2000
    Messages:
    2,582
    Likes Received:
    25
    I'm still infected, even though I have already successfully installed the patch? I installed the patch yesterday with no problems and haven't encountered any problems since then.
     

Share This Page

  • About ClutchFans

    Since 1996, ClutchFans has been loud and proud covering the Houston Rockets, helping set an industry standard for team fan sites. The forums have been a home for Houston sports fans as well as basketball fanatics around the globe.

  • Support ClutchFans!

    If you find that ClutchFans is a valuable resource for you, please consider becoming a Supporting Member. Supporting Members can upload photos and attachments directly to their posts, customize their user title and more. Gold Supporters see zero ads!


    Upgrade Now