Go Back   FormKaos: Board > General Discussion > Coffee Lounge > Punching Bag
FAQ Community Arcade Today's Posts Search

Punching Bag Bitch, cry and whine your way into oblivion.

Reply
 
LinkBack Topic Tools Rate Topic
  #1 (permalink)  
Old Aug 12, 03
The.House.Brothers
 
Join Date: Apr 2003
~god~ is an unknown quantity at this point
computer virus!

hallo. uum this stupid worm spreading pretty quickly where it 'endtasks' your SVChost automatically and your computer restarts repedetly.. its actually pretty well written, but was wonderin' where it came from. I already fixed it.. i checked and it was using ports 135 and 69, so i shut them.

but how the fuck did it form on my msblast.EXE?
uugghh. nice virus tho. two thumbs up!!

-sean.
Reply With Quote
  #2 (permalink)  
Old Aug 12, 03
DONT BE BITTER BE BETTER
 
Join Date: Apr 2001
rawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to all
msblast.exe is part of the worm.

stop the process in task manager, delete it.

open up regedit, do a search for msblast and MSBLAST and delete those keys.

run windows update, because the dcom patch is in there.
Reply With Quote
  #3 (permalink)  
Old Aug 12, 03
DONT BE BITTER BE BETTER
 
Join Date: Apr 2001
rawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to all
yeah fuck that noise i just said, symantec just released a removal tool:

http://securityresponse.symantec.com...oval.tool.html

but you still have to patch it. if you can't use msupdate you can download the patch straight from here:

http://www.microsoft.com/technet/tre...n/MS03-026.asp

even with the 60 second shutdown time, it's pretty easy to download both programs to your desktop. just unplug your interweb and use the removal tool and install the patch.
Reply With Quote
  #4 (permalink)  
Old Aug 12, 03
Cubed
 
Join Date: Jul 2003
Lostcause is an unknown quantity at this point
easiest Way to remove this thing.

restart the unit.

#2. Click on Start | Right click on My Computer | Click on Manage.

#3. Under Services and Applications - click on Services

#4. Find Remote Procedure Call (RPC) on the right side, right click on it - Click on properties.

#5. Find the Recovery Tab - 3 columns, change 'Restart the computer' to 'Take no action.'

#6. Connect to the internet

#7. Browse to www.google.com

#8. Type in download stinger - first page at the top 'Network Associates, Inc.' - click on it.

#9. Click on Download Stinger - Click on 'Open' when the download dialogue appears.

#10. When Stinger opens, click on 'Scan Now'

While running the scan...

#11. Goto www.technet.com - First page you see, two articles down is 'Read Security Bulletin.' - Click on it

#12. Click on 'Windows XP 32 bit Edition' - On the right side, click on 'Download' - Now click on 'Open' when the download dialogue appears.
Reply With Quote
  #5 (permalink)  
Old Aug 12, 03
STOLE YOUR BIKE
 
Join Date: Jan 2001
stringbeans has a spectacular aura aboutstringbeans has a spectacular aura about
our network at work is down.. im not sure if its because of this virus or something else, but yeah.. this sucks!

john
2899131
Reply With Quote
  #6 (permalink)  
Old Aug 12, 03
DONT BE BITTER BE BETTER
 
Join Date: Apr 2001
rawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to allrawb is a name known to all
Quote:
Originally posted by elguato
protect yourself, run a linux gateway firewall :P
if you have time to configure, run and maintain a firewall for your network you have time to run windows update on your windows boxes once a month. :c-tard:

Last edited by rawb; Aug 12, 03 at 09:15 AM.
Reply With Quote
  #7 (permalink)  
Old Aug 12, 03
'latinum respect.
 
Join Date: Jan 2002
miss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to all
ugh. viruses.

we're not allowed to check our outside e-mail at work because of them and it drives me nuts because if you are stupid enough to get an e-mail virus (oh golly! look! someone I don't know is asking for my advice on a file, better open it!) should NOT be working at IBM in the first place!
Reply With Quote
  #8 (permalink)  
Old Aug 12, 03
STOLE YOUR BIKE
 
Join Date: Jan 2001
stringbeans has a spectacular aura aboutstringbeans has a spectacular aura about
^^ i know what you mean! ive never gotten an email virus before. i've received them a bunch of times, but im always cautious when it comes to emails from people i dont know! but sometimes its because of that auto-preview feature in outlook which opens the email in that preview window as soon as you highlight it.

john
2899131
Reply With Quote
  #9 (permalink)  
Old Aug 12, 03
hosehead
 
Join Date: Jun 2001
inkster is an unknown quantity at this point
Quote:
Originally posted by miss.myra
ugh. viruses.

we're not allowed to check our outside e-mail at work because of them and it drives me nuts because if you are stupid enough to get an e-mail virus (oh golly! look! someone I don't know is asking for my advice on a file, better open it!) should NOT be working at IBM in the first place!
what do you guys run there, anyways?
Reply With Quote
  #10 (permalink)  
Old Aug 12, 03
hosehead
 
Join Date: Jun 2001
inkster is an unknown quantity at this point
Quote:
Originally posted by stringbeans
^^ i know what you mean! ive never gotten an email virus before. i've received them a bunch of times, but im always cautious when it comes to emails from people i dont know! but sometimes its because of that auto-preview feature in outlook which opens the email in that preview window as soon as you highlight it.

john
2899131
outlook is the devil!
Reply With Quote
  #11 (permalink)  
Old Aug 12, 03
STOLE YOUR BIKE
 
Join Date: Jan 2001
stringbeans has a spectacular aura aboutstringbeans has a spectacular aura about
hah, our network (nokia) is hosted by ibm, and all of our nokia branches in north america are screwed
Reply With Quote
  #12 (permalink)  
Old Aug 12, 03
Help Computer....
 
Join Date: Jul 2002
DJDeeb is on a distinguished road
Fun times in IT land today!!!!!! :c-tard:
Spent most of the day dealing with this thing!!!


Now i come home and find it on my computer here!..lol:)
Reply With Quote
  #13 (permalink)  
Old Aug 12, 03
flick ma bean
 
Join Date: Oct 2002
Kelster is an unknown quantity at this point
how else can you get a virus other then just opening bad emails?
Reply With Quote
  #14 (permalink)  
Old Aug 12, 03
Thread referee
 
Join Date: Jan 2002
lildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of lightlildonkey is a glorious beacon of light
Actually easiest way to fix it is

Control Panel
-> Internet connections
-> right Click select properties
-> Select Advanced tab
-> Select Use firewall
-> Apply

Done.
Reply With Quote
  #15 (permalink)  
Old Aug 12, 03
Help Computer....
 
Join Date: Jul 2002
DJDeeb is on a distinguished road
Quote:
Originally posted by Kelster
how else can you get a virus other then just opening bad emails?
This virus just forces itself onto a computer that has not got the security patch ( noted above ) applied to it......Also if you have not updated your virus scanner software.
It uses a known "hole" in Windows!...........pretty sneaky shit!
Reply With Quote
  #16 (permalink)  
Old Aug 12, 03
The Truth is..So Ruthless
 
Join Date: Apr 2001
AGROculture has a spectacular aura aboutAGROculture has a spectacular aura about
Can you get a virus from opening an email but not opening any attachments?

I think you can but not to sure

AGROout
Reply With Quote
  #17 (permalink)  
Old Aug 12, 03
_.-' Mizz TnA Unit '-._
 
Join Date: May 2002
sweet~kandy is an unknown quantity at this point
Oh thats not good, thats not good at all...
Reply With Quote
  #18 (permalink)  
Old Aug 12, 03
hosehead
 
Join Date: Jun 2001
inkster is an unknown quantity at this point
Quote:
Originally posted by AGROculture
Can you get a virus from opening an email but not opening any attachments?

I think you can but not to sure

AGROout
with outlook express you definately can. outlook's a bit better, but still kind of sketchy. like john said, turn off your auto-preview. this'll prevent the opening of emails that you find to be suspect (since in order to delete it, you have to click on it, which opens it in the preview).
Reply With Quote
  #19 (permalink)  
Old Aug 12, 03
karma: *****
 
Join Date: Apr 2002
Sh4n3 is an unknown quantity at this point
Quote:
Originally posted by rawb


even with the 60 second shutdown time, it's pretty easy to download both programs to your desktop. just unplug your interweb and use the removal tool and install the patch.
lol, i just went through all of this yesterday.


took my dumbass a while to unplug the net so i could open that shit though.
Reply With Quote
  #20 (permalink)  
Old Aug 12, 03
hosehead
 
Join Date: Jun 2001
inkster is an unknown quantity at this point
Quote:
Originally posted by lildonkey
Actually easiest way to fix it is

Control Panel
-> Internet connections
-> right Click select properties
-> Select Advanced tab
-> Select Use firewall
-> Apply

Done.
good advice. but not everyone of us has xp or a personal firewall.

in which case, the best way to prevent the issue is to just download the patch.
Reply With Quote
  #21 (permalink)  
Old Aug 12, 03
'latinum respect.
 
Join Date: Jan 2002
miss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to allmiss.myra is a name known to all
Quote:
Originally posted by inkster


what do you guys run there, anyways?
We don't do the running.

We have a series of hamsters running on wheels in a small room on the third floor.


...
Reply With Quote
  #22 (permalink)  
Old Aug 13, 03
[i]cvt[u]
 
Join Date: Feb 2003
beach*bum is an unknown quantity at this point
omg i have this stupid thing. thx guys. this helped out alot.
Reply With Quote
  #23 (permalink)  
Old Aug 13, 03
RIGOR VIDA
 
Join Date: May 2003
Magi is on a distinguished road
one of the few times using Windoze ME has been a good thing rather than a bad thing.
Reply With Quote
  #24 (permalink)  
Old Aug 13, 03
Love is just a fuck away
 
Join Date: Apr 2003
MissZiggy is an unknown quantity at this point
Apparently this ms.blast thing is set to hit microsoft on friday. All over the news.
I'm glad we got rid of ours a few days ago.
Reply With Quote
  #25 (permalink)  
Old Aug 13, 03
The Truth is..So Ruthless
 
Join Date: Apr 2001
AGROculture has a spectacular aura aboutAGROculture has a spectacular aura about
How do I turn off the automatic viewing on outlook?

Thats the worst!!

AGROout
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT -7. The time now is 12:12 AM.


Forum software by vBulletin
Circa 2000 FNK.CA