Important-virus Alert

Valve Replacement Forums

Help Support Valve Replacement Forums:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.

Ross

Well-known member
Joined
Dec 15, 2001
Messages
25,981
Location
On The Hot Seat
Many people who are running Windows XP, 2000, NT, and so forth are currently being attacked by a worm. This worm is using a DCOM RPC Exploit and is a self infector. If you or anyone you know is having warning messages just about every 2 minutes which require you to shut down the computer, you are infected. You must go to Microsoft and get the patch to stop the infection and then update your virus definitions and rid yourself of the infection or manual remove it from your system.

Microsoft Patch:

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp

Norton Removal instructions

http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html

Norton Repair Tool

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

http://www.secadministrator.com/Articles/Index.cfm?ArticleID=39837
http://isc.sans.org/diary.html?date=2003-08-11

http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100547

W32.Blaster.Worm
Discovered on: August 11, 2003
Last Updated on: August 12, 2003 08:37:01 AM
 
Hey Ross,
Thanks for the info. Your are the MAN!

Dave
_________________________________
Surgery: 4/21/03
Aortic Aneurysm Repair
AVR, with a St. Jude Mechanical 27mm
 
I just checked again and I'm up to 214 hits on port 135 since 4 this afternoon. Looks like it's starting to slow down a bit. The real fun thing will be tomorrow morning when everyone gets into work. I pitty all the IT techs.
 
Thanks Ross-

This site is so great. There is all kinds of good information. Sometimes it's a good thing to be outdated. I use Windows 98.

So I guess I'll just stay my old-fashioned self for a while.
 
Hi Ross...
Yeah, everything at work is screwed up this morning. IT techs were working all night and we still have some drives messed up. I'm like Nancy with my home machine except I'm still running on coal-fired Windows 95!
_________________
Les AVR '93 / '95
 
Thanks

Thanks

Thanks Ross. I have been going crazy with this problem since last night. I bet that is what is happening. I will use your links to see what I can do to undo this before my circuits overload, overload, overload! I have been blaming my husband. He had just installed GPS on my laptop and this started happening. Windows just keeps shutting down. Will let you know if this helps. Better go before it gets me again.
 
A little update:

Some people are having problems when installing Microsofts patch (Microsoft/problems= what else is new) anyway, if you encounter these problems, install the patch in SAFE MODE and run the Virus scan in SAFE MODE. That will keep all 32bit drivers from loading and reloading the worm.

As many have found out already, this is not a pleasant worm even though it's removal is basically easy.

P.S. Sylvia stop laughing at all of us Windows people! I can hear you snickering all the way over here, sitting in front of your MAC.
 
funny you should mention that....

funny you should mention that....

actually ross,
i feel badly because i'm the only mac in this household and my kids often laugh at me for "not converting"!!!!
i am really lucky when it comes to these things. saves me so many headaches!!
hope this isn't too much of a problem for all.
be well you funny guy!
 
Queston ?

Queston ?

Ross,

I got the virus last night and took care of it with the Microsoft Patch for XP. However, I have friend who has a 56K connection and cannot download the patch prior to the system going down and rebooting, thereby losing what was partially downloaded !! Is there solution or do I need to download the patch and burn to on CD for her ?

Thanks
 
If you can, burn it to a CD and install from that. This is one of the things that is giving everyone such a hard time. The worm shuts you down before you get anywhere.

If you have the patch on the cd, she wouldn't even need to connect to the internet and that would be a definate plus until it's removed from the system.

Symantec has now elevated the threat to a level 4 and is providing a removal tool. You may want to try this as well as getting the patch.

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
 
hi ppl
peachy`s other half here... yea i know we run Linux here and all that ..... )))))
so no viruses here..
Apart from dumping windows doing simple stuff like running your
account in eg. ( xp nt 2k ) as a limited user so that you cant install software is a great help to your system,
You should only use your admin account for that and nothing else.

Also not using outlook for email is a good idea as well ... anything that allows you to read emails as text and not only as a webpage ( html )

ok. trying my best not to get all nerdy and all that so ill stop here )))


LtCdData
 
Nancy said:
Thanks Ross-

This site is so great. There is all kinds of good information. Sometimes it's a good thing to be outdated. I use Windows 98.

So I guess I'll just stay my old-fashioned self for a while.
I'm right with you Nancy. We need to get Les at least up to Win 98se. I thought I was the only one still doing things from the stone age! :D

LtCdData this is true. If anyone has questions about how to make their computers more secure, I'd be more then happy to help. Just send me a PM, email, or $1000 er wait a minute, that isn't it. :D
 
Back
Top