Virus shuts down XP and 2k boxes

89 public posts in this discussion.

Post 1

Yep, Its that time of the year again that unpatched systems get hit by a virus.

The virus is pretty busy in darwin (and the rest of the world) shutting down unpatched machines that have TCP port 135 open on the net.

The net may be slower than normal this week, and also expect delays on the weekend when the virus does a DOS attack on microsoft.

At the moment, many machines can't stay on the net for much longer than 5mins, so downloading the patch may need to be done from another location/pc.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp

http://www.sarc.com/avcenter/venc/data/w32.blaster.worm.html

Getting your pc running again isn't that hard for the average gamer.

But if your a business, and you are losing money being offline, we can help with onsite professional service. Call Darwin Computer Doctor on 8932 1235

Post 2

thank god i havent got it.... yet proly wont get it either

Post 3

Thats prolly why my pc just fkn died on me, couldnt run anything, notepad, cmd, regedit... i just re-installed... thanks for the heads up

Post 4

Actually It comes in via port 4444 is what I heard,

I just finished fixing the comp that I am posting this at,

It brings up a message about the RPC protocol, and then your comp shuts down..

Its pretty easy to see if you are infected, Ctrl+Alt+Del, and if in task manager you can see a program called msblast.exe, you are infected

Ill dig up some help about it

http://www.tandmdigital.com/ have links to the correct patches, and info on how to remove

AVG's latest dat file will pick up the virus aswell

Post 5

Thanks for the info.

Port 4444 is used after you are infected. The initial point of attack is tcp 135, then once infected the virus will listen on udp 69 (tftp server) and 4444 tcp (remote shell) for instructions.

Post 6

Heres a image of what you may get on your screen before shutdown.

[Image: http://ntantivirus.com/blaster.JPG]

Post 7

Note:

For those of you who aren't using firewalls, sorry to say it, but you're BEGGING for this sort of crap to happen, as well as folk to jump onto your shared directories and play silly buggers with your hard drive.

Get a firewall. Now. Go download Zonealarm from http://www.zonelabs.com/ or SOMETHING.

Don't run your computer on the 'net without a firewall.

Post 8

haha all the computer at school were fucked up
well not all but some
i dont know if this was the cause
but i never got this silly message thank god

Post 9

I'm friggin allergic to ZoneAlarm, since it fucked up all my networking. Kept getting "Transmit error code 65" or something like that when I tried pinging. couldnt even send files via MSN. Was a hair away from formatting my entire system when I was FORCED to try the microsoft support site, where they had an article saying that the problem was ZoneAlarm (which was disabled by the way). All better now, but never EVER touching ZoneAlarm again. Get something different.

Post 10

I think i may have got the virus as my computer was doing the same thing. But as i didn't think it was a virus and is was only happening when i had my comp on the home network i ran the network setup wizard and it fixed it. (probably as it turned my firewall on as i had it off so i could play Generals online).

Hmm scanned for viruses used the latest AVG and found nothing.

Post 11

so is there a fix for this virus?

Post 12

Ahhh AVG found it a worm called LOVSAN? damn it i guess it would have spread on other computers on my network :(

Post 13

fix is available

dl it from here http://securityresponse.symantec.com/avcenter/FixBlast.exe

u might wanna read these instructions before u run the fix tool tho
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

Post 14

Whats a better firewall than zonealarm?

Post 15

http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS03-026.asp

thats the link for the windows fix

Post 16

Quote from Minorci:
Whats a better firewall than zonealarm?

hardware firewall!!!

Post 17

yeah i got hit with the virus, f*cking annoying thing!!!
downloaded a patch for it all good, symantec also has a free scanner/remover for it aswell

i had heaps of problems with zonealarm too!

Post 18

If I clicked the righ links theres a microsoft patch for it too.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp

Post 19

hopefully this makes people realise that prevention is better than a cure. paranoia is helpful too :)

Post 20

jec look up 3 posts :roll:

Post 21

i think my comps got it...
progrma error pops up, cant copy and paste... and watch vids, says low memory...

Post 22

hrrmm its fine so far i just deleted the msblast.exe now im just test for further notice err what else oh and i installed the windows xp update

Post 23

i got a patch from microsoft site, all fixed, thanks guys.

Post 24

ok maybe not good now im download hehe might work now

so hows the internet now timmy?

Post 25

its all good bro
no erros, and i can copy and paste now :D

Post 26

well atm i hope mine works :?

Post 27

I have told the Auto update thing to remind me in 3 days but now i want to install the updates how can i without re downloading them?

Post 28

i had it.... all i did was use msconfig to remove it from startup cause i hadnt seen that proggie there before then just deleted it off the comp

hasnt bugged me since

Post 29

Fix for blatant security hole:

www.gentoo.org

:)

Post 30

If you just applied the patch and didnt remove the actual virus, then on the 16th of this month, it is going to launch a DDoS attack on windowsupdate.com

Just letting people know :P

Post 31

got it.. a mate of mine got it...

why do fuck wits do this.. it hurts microsoft but doesen't help the home user.. probably some 42 year old virigin :S

Post 32

So angry....... Filthy swines..... :evil:

Post 33

what kind of low lifes would make viruses its just plain saD!!!

Post 34

Alot of "low lifes" that make virus's are people who have found security flaws, gone to MS and been told to piss off so they think, well why not prove it.

Post 35

DDoS attack on microsoft.com.
This is a bad thing how.

Post 36

stupid virus :(

Post 37

man i wunda what the world would be like without hackers

Post 38

Hey just for those people that might unfortunately get the virus...you might alrerady know this but it worked for a friend, and its just something i hope will help someone out :)

when you can boot up goto Start --> run and type "shutdown -a" without the ""

you all prbably knew it but like i said anything to help and it worked for a mate, he had time then to delete the virus :)

Post 39

shit looks liek alot of u peopel got it
o well teach ya's all a lesson i supose
lucky its not too harmfull

but anywyas if i was the creator of this program and saw all these threads sayign shit i got it and blah blah i bet he is in the biggest orgasmic state atm
lol oliek look how many GU members got it alone
imaging how many got it in australia and anywhere else for that matter
i dont think these peopel who make things liek this are very nice but i recon WD to this bloke cause his went a fair way in one day :P

Post 40

i love reading your posts knight, i love just sitting here counting the spelling mistakes... SPMA

Post 41

Thatnks for the warning guys, just downloading the patch now :D

Post 42

Talking about bad security
the government got hit today hahaha

Post 43

Quote from SperO:
Talking about bad security
the government got hit today hahaha

Is that the NT State Govt. ?

If so TN1 is going to be busy .... :)

Post 44

Heh... thanks a lot guys! I'm heaps lucky, since my computer is hidden behind a hub :) so I don't need a firewall or anything (which is excellent, firewalls are annoying). However a few of my friends have got this, so I downloaded "FixBlast" and I'll go help them (girls, of course...).

As a last note, ZoneAlarm IS really crap. One of my friends has it (gamer), and he keeps saying "Oh ZoneAlarm just stopped like 527 attacks on my computer" (not 527, but is a lot, like 19 or something) and I say: "Um, people have better lives then to keep attacking your computer... you'll find that they're port scanners" - ZoneAlarm blows!

Post 45

Um a hub aint gunna stop nothing ......

Post 46

the only firewall i had was te one that u tick on ya internet connection properties
and no one in this house got it
maybe my switch stopped it?

Post 47

um a switch wont stop it either

need a firewall or port filtering device

Post 48

If you're still worried and a little confused about the information given by the original post; download this

Post 49

I'm behind a NAT and have not been infected so far, we'll see if I have it when I get home tonight.

Post 50

[quote=Sa' Martok]... prevention is better than a cure.[/quote][/b]

Post 51

Quote from TopGun:
[quote:65e74584b4="SperO"]Talking about bad security
the government got hit today hahaha

Is that the NT State Govt. ?

If so TN1 is going to be busy .... :)[/quote:65e74584b4]

Tn1's work got hit yesterday with it... came from america... they traced it back to somewhere there....

Post 52

Quote from Amphibious One:
[quote:2c46d5f574="Sa' Martok"]... prevention is better than a cure.[/quote:2c46d5f574]

I want to see if the NAT does stop it or not.

Post 53

i feel like a systems tech *grin* i got my hands full helping all my family's infections and friend of the family.

The problem with this virus is that it hits the computer illiterate.. which just isnt fair :/

However computer companies must be making a mint fixing those sorta peoples problems.

Post 54

lol yesturday i got 3 peopel on msn saying shit its dixssconnection every second so i helped fix 3 and them flam last night
lol
o well hopefully it goes away soonish

Post 55

no one messaged me :cry:

Post 56

Hmm yeah seems a few did get it - sorry to those who did, thankfully its easily fixable :D

Yeah and reaper in same boat as you atm mate, I havent had any probs as of yet.

Post 57

Quote from Jono:
I havent had any probs as of yet.

Post 58

Yeah i think my alcatel speed touch pro telstra modem ( :oops: ) has a built in firewall that drops everything thats going through ports i havent specified to be open, so im lucky :) .

It took me a long time to realise that, I was wondering why the hell i couldnt host diablo II games for like a year :? .

Post 59

Quote from LemonJuice:
man i wunda what the world would be like without hackers
Crap, there wouldn't be any Linux, Apple computers or CS :roll: :lol:

Also Im behind my other comp which has a firewall, so all should be good :D

Post 60

i haven't picked this up just yet....but how EXACTLY does it infect the computer...internet obviously, but through what? Scanning computers?

Post 61

everything one of my friends got it straigt after he finshed d/ling the test center files for Planet side will we think anyway

Post 62

I've been a busy boy today :) and most probs tomorrow aswell

Post 63

Quote from Unseen:
I've been a busy boy today :) and most probs tomorrow aswell
lol yeah i was thinking today shit i wonder how margret and bill are coping with all these people comming in saying my computer is doing thins and this and arrhh god
lol so kurt mck issues with this?

supose its good for techs tho casue it takes 5 min to fix and then u charge them the fee to lok at it so easy money for busneiss

Post 64

Quote from BrAiN DaNcE:
If you just applied the patch and didnt remove the actual virus, then on the 16th of this month, it is going to launch a DDoS attack on windowsupdate.com

Just letting people know :P
what is all this about robbie?

Post 65

Quote from Symantec:

If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on Windows Update. The worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.

windowsupdate.com is going down in 3 days :twisted:

Post 66

I need help. MS fix for this evil virus doesn't install on my pc. It says it needs SP2 or higher to install and I have SP2. I re-installed SP2 again and it is still saying the same crap. I don't know what to do, for now I'm going to panic and run around in circles like a headless chicken.

[Image: http://www.angelfire.com/ultra/captainodyssey/redalert.gif]

Post 67

Quote from Symantec:
Calculates a random IP address, A.B.C.0, where A, B, and C are random values between 0 and 255.

NOTE: 40% of the time, if C > 20, a random value less than 20 will be subtracted from C.

Once the IP address is calculated, the worm will attempt to find and exploit a computer on the local subnet, based on A.B.C.0. The worm will then count up from 0, attempting to find and exploit other computers, based on the new IP.

So once youve got it you send it to pretty much random people across the internet, very wild and quite well designed as everyones already seen :roll: Good thing it doenst do anything serious like format your c drive or something or there would be a lot of people seriously screwed right now.

Post 68

Just saw this on the news

Said to my mum "I got that virus" - she was shocked

"But I got rid of it, coz I'm such a wiz" - Equally shocked

Post 69

Quote from Odyssey:
I need help. MS fix for this evil virus doesn't install on my pc. It says it needs SP2 or higher to install and I have SP2. I re-installed SP2 again and it is still saying the same crap. I don't know what to do, for now I'm going to panic and run around in circles like a headless chicken.

Bet you sure wish you had installed SP4 when I said it was out and advised so ;)

Anyway my server has it and that's as far as it's got on my network however. Although I've got another 6 machines to fix for my friends now too.

Post 70

Quote from Knight Of Nih:
fix is available

dl it from here http://securityresponse.symantec.com/avcenter/FixBlast.exe

u might wanna read these instructions before u run the fix tool tho
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

There's a problem... Symantec's down hmm

Post 71

LOL I noticed on the page for the fix that ME isnt affected, guess whoever made the worm figured there were already enough problems with ME as it is :lol:

Post 72

A few of the medical centres around darwin got hit too, RDH being one..
Poor Unseen, having to drive around and fix all the problems.. hehehehehe, better you than me dude ;)

its my understanding that DOS based OS's (95/98/ME) aren't infected by the virus because it was made to enter a machine via a port that is, by default, opened by the NT based OS's, does that sound right? or am i totally thinking of the wrong thing??

Post 73

Quote from Jay:
Bet you sure wish you had installed SP4 when I said it was out and advised so ;)
Bitch!

I now have SP2 and the patch installed :P sif SP4.
Stand down Red Alert, condition Green.

Post 74

Quote from Odyssey:
Stand down Red Alert, condition Green.

You use win 2000 you should say shields up, go to red alert, arm the photon torpedos, charge phaser banks. I do :)

Post 75

Or I could go to a Starbase for sanctuary...MacOS 8)

Post 76

I downloaded some weird path thing - what do I do with it and how does it help me ?

Post 77

My brother got the damn virus i had no idea what it was and couldn't connect to the internet to find out, so i hooked up an old machine that had not been connected to the net ever b4 and within 2mins it too had the virus.
I put the modem in my comp (still didn't know wat it was) connect to the internet and i didn't end up getting the virus.. ran the patch on my machine then to my bros and yeah works fine now.
I think i found that if ur windows xp isn't on the automatic updates or u dont update, u most probably will get the virus :)

exodus, who cares wat it does as long as it works :)

Post 78

yes I am always the lucky one.

I got it last night. Came up with the little window box saying it is going to shut down in 30secs.

It has only done it once. Got the update patch for norton before, did a full scan and it did not detect it.

Thanks for the links for the patch downloading as i speak.

Post 79

Omg all these people on the radio with the "how you fix it" solutions, that require a "clean computer" with a burner, a cd, and the blood of 3 virgins...

seriously, if you have it, kill it in your processes, find and delete the exe, and then get the patch... stupid newspaper, they were all like.. it's a catch 22 you can't fix it, you should bring it to us and we'll charge you $200 to get rid of this impossible conundrum, in like 3 minutes :P

Post 80

ner ner

i didnt get it cause i am behind a netwerk firewall and i am stealth 8)

Post 81

Hi Harbinger

As you know, newspaper journos have a habit of twisting the words/meaning to make a story. In the end of the article it even suggests for users to give it a go first.

It is kind of a "catch 22" in the sense that many basic users can't download the patch before the shutdown counter starts. Most customers I recommend getting the patch for an alternative source first, as this is the most easy to explain over the phone.

As a more advanced computer user, most of us can find ways around the worm attack reboot issue, it like shutdown -a during the countdown or reconfigure RPC not to autoreboot on failure. Obviously I've been carrying the patches around with me today, but if the customer is up to it, I will always suggest a cheaper/better way to fix their computer themselves.

Most nontechnical (computer illiterate) customers find it easier to get expert advice or onsite assistance - or at the least the dozen or more different customers I attended today thought so and are happy to pay for.

Post 82

that was you in the paper wasnt it [Image: http://www.gamers-underground.com/phpBB2/download.php?id=1407]

and like ctrl-alt-del
everyone in the whole world who ever used windows knows that :|

and then is like, go processes, kill msblast...
...
...

...

must kill ppl who cant follow instruction ><

Post 83

Quote from Lucifer Dragar:
ner ner

i didnt get it cause i am behind a netwerk firewall and i am stealth 8)

yeah well i dont run any of that and i didnt get it :lol:

Post 84

going process kill msblat didnt work for me and my mothers computer

Post 85

Quote from Harbinger:
seriously, if you have it, kill it in your processes, find and delete the exe, and then get the patch... stupid newspaper, they were all like.. it's a catch 22 you can't fix it, you should bring it to us and we'll charge you $200 to get rid of this impossible conundrum, in like 3 minutes :P

It's not the msblast process that makes the computer reboot. It's because the worm is shoddily written, and when a REMOTE computer attempts to use the wrong exploit against you (ie, the Win2k exploit against a WinXP machine), the forged packets make the RPC process die, thus your computer reboots.

Solutions include turning RPC to not reboot on failure, unplugging from the network, etc etc etc.

Killing msblast.exe just stops YOU from spreading the virus to more people, it doesn't stop your computer from rebooting.

Post 86

We should all be thankful this virus isnt much more leathal, It could have been, very very easily. The exploit used in the virus allows a remote CMD shell to be opened.

When I was troubleshooting this comp, (not mine, flatmates) I rebooted, and watched the processes, and sure enough, as soon as it was on the internet, there was a cmd.exe showing up in the list. That is scary, access to all files, reboots, bios flashing, you name it. It could have all been done.

Dont get me wrong, the person who did this is still a turd, but he could have been an utter asshole.

And now with the code being dissasembled and spread arround, it wont be long before all the 1337 script kiddies get there hands on it and add a simple "format c: /u"

and then what are you going to do..

Post 87

We should all be thankful this virus isnt much more leathal, It could have been, very very easily. The exploit used in the virus allows a remote CMD shell to be opened.

When I was troubleshooting this comp, (not mine, flatmates) I rebooted, and watched the processes, and sure enough, as soon as it was on the internet, there was a cmd.exe showing up in the list. That is scary, access to all files, reboots, bios flashing, you name it. It could have all been done.

Dont get me wrong, the person who did this is still a turd, but he could have been an utter asshole.

And now with the code being dissasembled and spread arround, it wont be long before all the 1337 script kiddies get there hands on it and add a simple "format c: /u"

and then what are you going to do..

Post 88

Yep, Darkwolf is spot on. The msblast.exe process doesn't cause the shutdown on the local machine, instead it means that particular attempt/attack from the net was unsuccessful in infecting you.

Some customers I find get infected first, next comes the shutdown due to RPC flaw. Others shutdown first and no infection.

The concern is those who are still infected with the worm, have no AV software but have only applied the MS patch. The MS patch itself doesn't kill any virus !!

In this case the shutdown issue is fixed and they think they are all ok, but they are still spreading the worm and set to participate in this DOS attack on Sat.

Also keep an eye out for teekids.exe and penis32.exe and any other variants.

Cheers
Peter

Post 89

Thanx for that warning