PDA

View Full Version : Anybody infected by a virus called Blaster Worm this week?


haha604
08-13-2003, 06:37 PM
Damn this virus. Nearly wiped out my half of my Jabbas Video Collection. Before my antivirus software did anything my comp was in an unusable state. Here is a link for those who are interested.

http://www.microsoft.com/security/incident/blast.asp


If you are using windows NT, 2000, XP, or Servers 2003, and ur comp has not been infected yet, u might want to update ur windows to prevent this stupid worm from taking over.

TT
08-13-2003, 06:44 PM
I still run on win98.. and I begin to like the fact all the hackers are concentrating their attacks on the never systems ...

gis
08-13-2003, 06:54 PM
AH yes yes,i had the virus.i got rid of it though this mornin,thanks to jabba givin me the blaster removal tool

it was beginnin to piss me off,lol.but its sorted now but i hear a lot of people are havin trouble with it

TT
08-13-2003, 07:00 PM
Dang, Skynet is slowly gaining control already ;)

666fast
08-13-2003, 07:56 PM
Heh, I already had the patch installed, so I'm all good I guess, I updated Spybot and it says all is good. My firewall (Norton Internet Security, I recommend it) has been logging quite a bit of TCP port attacks with them not having any success. So I'm sure I'm safe.

Apparently it goes after port 135. Go here to test your port, don't worry, it's safe. http://grc.com/default.htm
I come up as stealth, so my firewall is doing it's job.

Windows ME/XP users read before removing:
http://www.trendmicro.com/en/security/advisories/win_me_clean.htm

Removal Instructions:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RPCSDBOT.A

The patch from Microsoft is here:
http://support.microsoft.com/default.aspx?scid=kb;en-us;823980

If you really want, you test all your ports here, once again, don't worry, Sygate is trustable.
http://scan.sygate.com/

stracing
08-13-2003, 09:27 PM
me being behind a router is all good...i think. the port isn't open so i assume i'm safe?

if they start attacking my p2p ports, then i'm screwed. :(

novass
08-13-2003, 11:05 PM
thanks for the info guys. i hope i dont get infected :(

666fast
08-14-2003, 12:29 AM
thanks for the info guys. i hope i dont get infected :(

if you use a firewall, you should be ok. But it can get through.
Just incase anyone here doesn't know, the worm only goes after new versions of Windows. If you are on Win98 and older you should be fine, it's only for XP and newer users I believe.

Even if you are on dialup, you should run a firewall. Zone Alarm and Sygate make excellent ones that are free to download from their sites. They are probably on download.com too.

possessed_beaver
08-14-2003, 03:06 AM
hahah i got infected, and done the sensable thing, blamed evreyone else who uses the computer in the house :)
hahaha i shat thoe, i thought i had 2 re-install XP
but it's all good now *knock on wood*
:)

cho_888
08-14-2003, 03:54 AM
My house is networked, so lucky it didnt get past the firewall. But i have patched it up and everything is fine. Alot of friends got it though.

TT
08-14-2003, 04:01 AM
In these pas months I think this one was one of the biggest hitter, or am I wrong? I keep reading of ppl infected.. it really touched lot of PC this bastard!

Jabba
08-14-2003, 05:24 AM
yep got me good on Monday....and in the process of doing its stuff it corrupted lots of critical system files...hence the lack of videos recently....and I still dont have internet access at home...now I am having to back up everything and carry out fresh installs...what a complete waste of time and a total pain....what can you say about the people that create these things.... :twisted: :twisted: :twisted:

gat
08-14-2003, 05:49 AM
i am on my universitys network, so i guess im safe.

but i bring my home pc to work and plug it in the network, so i can take advantage of the DL speeds.

Do you think i will be ok? bering in mind im part of a huge network with what i presume would be a substantial firewall.

Any ideas?

haha604
08-14-2003, 01:29 PM
Heh, I already had the patch installed, so I'm all good I guess, I updated Spybot and it says all is good. My firewall (Norton Internet Security, I recommend it) has been logging quite a bit of TCP port attacks with them not having any success. So I'm sure I'm safe.


Yeah Norton Internet Security is a neat program. I installed it and found its ip tracking feature to be great. I've had several warnings since I installed it and it tracks the hacker right down to his home address. Although there is not much I can do with the info it is still cool nonetheless. Maybe I should learn some hacking skills and return fire :P.

666fast
08-14-2003, 01:34 PM
Heh, I already had the patch installed, so I'm all good I guess, I updated Spybot and it says all is good. My firewall (Norton Internet Security, I recommend it) has been logging quite a bit of TCP port attacks with them not having any success. So I'm sure I'm safe.


Yeah Norton Internet Security is a neat program. I installed it and found its ip tracking feature to be great. I've had several warnings since I installed it and it tracks the hacker right down to his home address. Although there is not much I can do with the info it is still cool nonetheless. Maybe I should learn some hacking skills and return fire :P.

Well, it does give you thier node name and IP address. You could easily send a email to the ISP with that info and they can find out who did it. The only problem is that a when you get the Trojan horse warnings, it might be someone trying to connect through Kazaa. It's not always someone out to get you. It is neat though.


If you got the worm, put your computer in safe mode, I'm told it'll keep the PC from restarting so you can fix the problem.

Ziploc
08-14-2003, 02:06 PM
how the hell you know if you have it?

Wide
08-14-2003, 04:08 PM
If you are in network.. I advice the updated blackice (v 3.6 cbd)
Its fully protecting your computer in network either net activity..
can be found easily at download.com..

DR.GONZO
08-14-2003, 04:38 PM
yea I had it too, I got rid eoff that shit!!! I still have a couple of viruses that norton can't quartintine or delete svchost.exe and a couple others but the worm is gone!!!! Im gonna fix the rest tonight.

666fast
08-14-2003, 06:11 PM
yea I had it too, I got rid eoff that shit!!! I still have a couple of viruses that norton can't quartintine or delete svchost.exe and a couple others but the worm is gone!!!! Im gonna fix the rest tonight.

Try Spybot.

Ziploc
08-15-2003, 02:19 PM
my uncle has it :(

so he is stuck to using safe mode :| and he wants to know hoe to remove it

he says he can't connect tot the internet in safe mode...

ideas?

666fast
08-15-2003, 04:09 PM
Removal instructions:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RPCSDBOT.A

Go to the first page of this thread, I posted a bunch of stuff on what to do and whatnot.