PDA

View Full Version : W32.Blaster.Worm


JStephenson
2003-08-12, 10:12 PM
If any of you have even watched the news today you have heard about this virus. I recommend anyone using Windows 2000 and XP to do this as soon as possible. Follow the instructions and download the removal tool from the attched link and after you run the tool it will direct you to download the patch. This virus started through Windows updates so you did not even have to open any attachments to have infected your PC. I work a Help Desk and today I have been slammed. It affects your TCP settings so I would suggest if you have not done it do it soon.

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

Sunflowergrl
2003-08-12, 10:25 PM
Dude......while I was at work all the computers kept shutting down cause of that damn virus

...it sucked sooooo hard...we had to shut our computers down for like half of the day

J*C*M
2003-08-12, 10:31 PM
Sounds like fun, where can i get a copy
J/K
Times like this i'm glad that i don't use my own computer

JStephenson
2003-08-12, 10:40 PM
Yeah well I had to go to the MVA this am, and it shut down because of this virus. I should have known my day was going to be crap when I got to work!

retail
2003-08-12, 10:52 PM
hoooray for macs! :woowoo:

:neener:

Sunflowergrl
2003-08-12, 10:54 PM
:whack:............mac's suck!!

hehe :D

retail
2003-08-12, 10:59 PM
:booty:

Sunflowergrl
2003-08-12, 11:07 PM
:wedgie:

retail
2003-08-12, 11:08 PM
:whoa::weazel:

Sunflowergrl
2003-08-12, 11:15 PM
:afterbuzz:.....akk :yikes:



:vipbathroom:

maynard
2003-08-12, 11:25 PM
My computer sucks ass, I would definitely classify it as "vulnerable"... yet, no problems.

:shrug:

xdragonflyx
2003-08-12, 11:28 PM
I somehow managed to get this new virus (i think they are refering to it as blaster) on my computer. it affects windows. Every time I connect to the internet it shuts my computer down. I have tried a few different remedies and it doesnt seem to be working. I am testing out a new one now. Maybe this one will work. I hope so. If anyone knows of anything that is working let me know because this really sucks.

maynard
2003-08-12, 11:29 PM
http://www.buzzlife.com/mssg_brd/showthread.php?s=&threadid=19917

badkitty3804
2003-08-12, 11:39 PM
My mom works at UMBC...they got their asses kicked by the virus...whole campus

Anti-DieselKitty
2003-08-12, 11:47 PM
I think this is funny ONLY because at work I have such an old ass, slow computer... And apparently the worm doesn't affect Windows 98...so for once I caught a break with that retarded slow computer! Yay!



Damn, I just realized, this computer isn't protected by old software. Crap.

A.J.
2003-08-13, 12:15 AM
:hmm:

This is no good, i really need to stop using windows.

A.J. Inx
2003-08-13, 12:19 AM
:D

Actually, it was pretty damn funny when I went to the MVA today and it was CLOSED. I'm hoping it whiped the entire system dry... my brother and I both could use a clean start on our driving. In MY opinion, Glen Burn-out got it's just desserts...

Sorry to all you nice folks out there that don't deserve it, though. Well... some of you.

A.J.
2003-08-14, 12:15 AM
This virus hit my work today, we had to run all around the buildings cleaning it up.

FunkTribe
2003-08-14, 01:55 PM
That worm has been all up my company's asshole these last few days. :no:

n-root
2003-08-14, 02:35 PM
Originally posted by JStephenson
If any of you have even watched the news today you have heard about this virus. I recommend anyone using Windows 2000 and XP to do this as soon as possible. Follow the instructions and download the removal tool from the attched link and after you run the tool it will direct you to download the patch. This virus started through Windows updates so you did not even have to open any attachments to have infected your PC. I work a Help Desk and today I have been slammed. It affects your TCP settings so I would suggest if you have not done it do it soon.

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

:affection: :lessthanthree: :atpc: :ANden: :ANden:

n-root
2003-08-14, 02:38 PM
its all about proactive measures babyyyyyyyyyy

its all about proactive measures babyyyyyyyyyyyyyy

Teh patch has been out for longer than Laaatelyyyyyyy

you gotts to be proactive babyyyyyyyyyyyyy

*/end song*

DNAgirl
2003-08-14, 02:41 PM
All I have to say about this worm is: :redfu:

n-root
2003-08-14, 02:42 PM
blame your admins :shrug:

empath
2003-08-14, 02:43 PM
btw, if you keep getting the 'shutting down' error message, you can go the c prompt and type "shutdown /a" (without the quotes) to stop it.. then you can get rid of the worm..

DNAgirl
2003-08-14, 02:47 PM
Originally posted by n-root
blame your admins :shrug:

Acctually I have to blame myself for not updating my system :sadblue:

n-root
2003-08-14, 02:48 PM
Originally posted by DNAgirl


Acctually I have to blame myself for not updating my system :sadblue:
:-\

zartan
2003-08-14, 02:54 PM
This worm *SUCKS*. I was screwed for 2 days travelling on business, unable to download the patch b/c it kept restarting the computer before it could come thru the dialup. Serious productivity problem!!!

I now support the death penalty for computer virus authors...

DNAgirl
2003-08-14, 02:56 PM
I want to know the difference between a computer worm vs a virus?

n-root
2003-08-14, 02:58 PM
Originally posted by DNAgirl
I want to know the difference between a computer worm vs a virus?


a worm can propagate without assistance over a network without human intervention

the sex molesters
2003-08-14, 03:03 PM
if anyone can program a virus that affects mac os x v. 10.2, AND get it onto my computer, i will give you MAD props. hehehe. cuz i don't think anyone here could do it.

n-root
2003-08-14, 03:07 PM
Originally posted by djinergy
if anyone can program a virus that affects mac os x v. 10.2, AND get it onto my computer, i will give you MAD props. hehehe. cuz i don't think anyone here could do it.

Im sure it runs ELF binaries which by their very nature are ezasy to exploit through dynamic library trojaning and ld cache poisoning. Its not that its SUPER HARD its that no one wants to. After the Great Worm almost took down the internet and Robert Morris went to fucking prison for writing it people started thinking twice about writine unix worms. But dont even fool yourself into thinking its not doable dude. Those machines run fucking sendmail and apache for god sakes

the sex molesters
2003-08-14, 03:13 PM
while it is true that the virus or worm itself would not be too hard to program, i doubt anyone's ability to actually get it to my computer.

n-root
2003-08-14, 03:16 PM
Originally posted by djinergy
while it is true that the virus or worm itself would not be too hard to program, i doubt anyone's ability to actually get it to my computer.


you steal files with p2p sofware dont you? ........ thats at least one open port......

DNAgirl
2003-08-14, 03:17 PM
DO IT ROMAN,....DO IT :D

the sex molesters
2003-08-14, 03:21 PM
you can port scan me, i'm sure... why don't you tell me how you would go about it?

n-root
2003-08-14, 03:21 PM
Originally posted by DNAgirl
DO IT ROMAN,....DO IT :D


not me :)

n-root
2003-08-14, 03:26 PM
Originally posted by djinergy
you can port scan me, i'm sure... why don't you tell me how you would go about it?

Id scan your IP then run a nessus battery on it. take the nmap output and telnet in to check versions. and then move from there... any after that would depend on whats available. and if nothing was available and I wanted to 0wn that box seriously then I wouls monitor apple update for vulnerabilities and then try to catch them in the minutes (or however long) between your computer starting and those updates being installed and the machine restarted. with a simple low level objective of creating a local inconspicous user account so that I could take my time and use your computer cycles to play around with stuff. then I would gain root localy cuz its easier that way :)

IF IF IF IF IF I cared which I dont and never have cared for breaking into people shit

the sex molesters
2003-08-14, 03:28 PM
yeah but your approach requires me to have updates automatically run and installed, which they are not.

n-root
2003-08-14, 03:29 PM
Originally posted by djinergy
yeah but your approach requires me to have updates automatically run and installed, which they are not.


soo that means I have EVEN MORE TIME TO ACT!!!!! The updates are the FIXES to the vulns

the sex molesters
2003-08-14, 03:32 PM
"Security Update 2003-07-14 addresses a potential vulnerability when a password is required upon waking from the Screen Effects feature, which could allow an unauthorized user access to the desktop of the logged in user."


that's the only security update on there now. i don't use that feature.

n-root
2003-08-14, 03:35 PM
Originally posted by djinergy
"Security Update 2003-07-14 addresses a potential vulnerability when a password is required upon waking from the Screen Effects feature, which could allow an unauthorized user access to the desktop of the logged in user."


that's the only security update on there now. i don't use that feature.

ummm Im not taking this conversation any further :inergy:

the sex molesters
2003-08-14, 03:35 PM
ok whatever. yeah it is pointless. i'm bored, what can i say?

n-root
2003-08-14, 03:36 PM
Originally posted by djinergy
"Security Update 2003-07-14 addresses a potential vulnerability when a password is required upon waking from the Screen Effects feature, which could allow an unauthorized user access to the desktop of the logged in user."


that's the only security update on there now. i don't use that feature.

you dont use a screensaver with a password? well then I guess that makes you SUPERSECURE :FUBAR:

the sex molesters
2003-08-14, 03:38 PM
i close my laptop (put it to sleep) when i am not physically using it. that makes it so secure it won't even run background programs while closed. heh.

empath
2003-08-14, 03:46 PM
There's 3 kinds of malware, usually:

A virus can't propogate on its own. It attaches itself to other files, and copies itself when they are copied.

A worm is active. It doesn't need other programs to work, and it active seeks to send itself to new computers on the network, through email or other network protocols.

A trojan horse doesn't really propogate. It's just a program that hides within another program. It's usually used to enable hacking-- it'll log keystrokes, steal passwords, or open a backdoor into the network.

rajdeep
2003-08-14, 07:20 PM
Speaking of which:

Roman, John et al - could you guys recommend some free anti-virus and firewall software for both Win 2000 and Linux? :shrug:

n-root
2003-08-14, 07:22 PM
Originally posted by rajdeep
Speaking of which:

Roman, John et al - could you guys recommend some free anti-virus and firewall software for both Win 2000 and Linux? :shrug:

in the Windows AV world you get what you pay for ..........


for linux though ...

I would use tripwire and tar

n-root
2003-08-14, 07:24 PM
the linux solution isnt based so much on definititions as much as alerting you to what has changed in general making it acceptable for use in MANY MANY situations only one of which would be fixing a virus outbreak

divapb
2003-08-14, 08:37 PM
This shit is on my computer!!!!!!! I can not get it the FFFFF off....ARGHHHHHHHHHHHHHH...:wtf:

n-root
2003-08-14, 08:45 PM
Originally posted by divapb
This shit is on my computer!!!!!!! I can not get it the FFFFF off....ARGHHHHHHHHHHHHHH...:wtf:

put the fix at the root of the C drive

reboot the machine and as it boots the windows kernel hit 'F8' (I think) then at the prompt boot into 'Safe Mode'

then as "Administrator" run the fix

Anti-DieselKitty
2003-08-14, 08:54 PM
OR....let it mess up your computer, and then get a new one!

n-root
2003-08-14, 09:15 PM
Originally posted by Anti-DieselKitty
OR....let it mess up your computer, and then get a new one!


:traviswork: when god struck struck down his hammer while he was forging my soul a piece flew off into the darkest part of heaven.... where catie grew and grew till she knew she could come to the earth and contradict EVERYTHING i've ever believed in :wink: :jk: Catie You know I got mad :affection: for you !!!

rajdeep
2003-08-15, 12:56 PM
:tarvis:

Anti-DieselKitty
2003-08-15, 01:15 PM
:shrug: :affection:

rajdeep
2003-08-15, 04:16 PM
Interestingly the intention of the worm is to launch a denial-of-service attack tonight at midnight on the Microsoft Update server.

The primary payload of the MSBlast worm, which began infecting systems Monday, is a denial-of-service attack against the service from which most Windows users get their updates. If successful, the maneuver would frustrate efforts to patch the Windows vulnerability the worm exploits. The strategy is also a way of simply harassing the Redmond, Wash.-based software giant; the worm's code contains a message for the company's founder: "billy gates why do you make this possible? Stop making money and fix your software!!"

Computers infected with the worm will start sending connection requests to the Windows Update service at midnight Friday, according to the clock on a given user's computer.


More here:
http://news.com.com/2009-1002_3-5063226.html?tag=fd_lede1_hed

technoticau
2003-08-15, 04:22 PM
You know what I always say:

FORMAT FORMAT FORMAT FORMAT.... nihohohohohohaoaaaahahaaaa

formating ur HD is like changing ur oil. Get used to formating. But if you get a boot-virus and dont realize it then u r proper fucked.
nihohoahahahaohaaaaaa

rajdeep
2003-08-15, 04:22 PM
:confused:

Article One
2004-05-03, 03:55 PM
About as ugly as Blaster.worm....

jerkoffs proudly present:

W32/Sasser.worm.a

basically will spread to and thru your system, and cause system shut downs, loss of info, all that good stuff.

here is the full info on it:

http://vil.nai.com/vil/content/v_125007.htm


and here is a link to NAI's FREE "Stinger" program, updated to include this particular virus. Its a great quick scan that will auto-fix alot of infected files....some of the most dangerous and hi-risk viruses will be detected/cleaned/removed by this program.

http://vil.nai.com/vil/stinger/



just a heads up. this virus could get ugly real quick. :thumbsup:

Mitaic
2004-05-03, 04:47 PM
About as ugly as Blaster.worm....

jerkoffs proudly present:

W32/Sasser.worm.a

basically will spread to and thru your system, and cause system shut downs, loss of info, all that good stuff.

here is the full info on it:

http://vil.nai.com/vil/content/v_125007.htm


and here is a link to NAI's FREE "Stinger" program, updated to include this particular virus. Its a great quick scan that will auto-fix alot of infected files....some of the most dangerous and hi-risk viruses will be detected/cleaned/removed by this program.

http://vil.nai.com/vil/stinger/


just a heads up. this virus could get ugly real quick. :thumbsup:



DO IT! My boss' computer got affected and he wasted the entire morning fixing it. In addition, apply the patches, too!

There is a new worm, Sasser
(http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.b.worm.html)
that is in the wild and is in wide distribution within JHU/JHMI.
Symantec has classified this worm as Category 4, meaning its distribution
is widespread and the damage caused is high. This worm exploits the
vulnerability referenced in Microsoft Security Bulletin MS04-11 and
Microsoft KnowledgeBase article 835732.

If you have not patched your system you are vulnerable to this exploit and
your computer may be compromised. If your antivirus is up-to-date, but
your patches are not, your computer may be caught in a cycle where it will
continuously restart after giving an error message about LSASS.

If your computer is exhibiting these symptoms you should remove it from
the network. Once removed from the network, it will stop restarting and
you will then be able to apply the patches. Download them, burn them to a CD
and apply them to your machine while it is off the network. Reboot, put it
back on the network and then visit Windows Update and Symantec to update
your operating sytem and antivirus definitions.

Mitaic
2004-05-03, 05:13 PM
For WinXP here's the patch

http://gd.tuwien.ac.at/pc/microsoft/winxp/Security_Bulletins/WindowsXP-KB837001-IA64-ENU.EXE

Article One
2004-05-03, 05:36 PM
for those who'd rather take it off the Microsoft site and read what its all about, here's the link:


http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

Mitaic
2004-05-03, 06:15 PM
yes, do the microsoft thing like Article One said.

and update all your critical updates!!!!