PDA

View Full Version : MSBlast.exe



Xilo
08-11-2003, 11:37 PM
W32.Blaster.Worm is a worm that will exploit the DCOM RPC vulnerability using TCP port 135. It will attempt to download and run a file, msblast.exe.

Infection Length: 6,176 bytes

Systems Affected: Microsoft IIS, Windows 2000, Windows NT, Windows XP

Systems Not Affected: Linux, Macintosh, OS/2, UNIX

For those of you wondering what port 135 is there for, it is none other than the Windows Update Port! Hooray, thanks Microsoft... not only do you open doors, but backdoors as well. The Symantec website listed below has removal instructions for the worm if you are infected. Also be sure to check Windows Update and look under "Critical Updates & Service Packs", this is where the patch is located for this exploit.

Symantec Security Response (http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html)
Microsoft Window's Update Webpage (http://windowsupdate.microsoft.com/)

(Ya, I know it was discussed in another topic, but it's best to have a topic to keep people informed easier...)

ooo
08-11-2003, 11:38 PM
new virus or old? lol i havent updated my norton 2003 definitions in 2 months... :/

OMG I CANT DO A LIVE UPDATE!!!... arg i prob got a virus killin my norton... :/

no wonder my ie hasnt been functioning properly for the last few days.... time to install 2004 :/ hope it works!

ultimatejester
08-11-2003, 11:39 PM
Originally posted by Soul814@11 August 2003 - 23:38
new virus or old? lol i havent updated my norton 2003 definitions in 2 months... :/
its a new 1

RPerry
08-11-2003, 11:40 PM
W32.Blaster.Worm
Discovered on: August 11, 2003
Last Updated on: August 11, 2003 03:52:23 PM

actually pretty new Soul, ;)

ooo
08-11-2003, 11:41 PM
haha im now like 90 percent sure i got a virus! i cant do search.. fug... i've been copyin programs to cd n transferin it between programs... n i didnt feel like puttin an anti virus on one of my com since it had no internet... :/ now i gotta do a check

MetroStars
08-11-2003, 11:42 PM
Thanks for the update Xilo.. bastard worm...

sharedholder
08-11-2003, 11:42 PM
:lol: I formated my disk yesterday :lol: :lol: I have a nasty virus maybe its this .

ooo
08-11-2003, 11:44 PM
DAMN BITCH I WAS WONDERING WHY MY IE WASNT FUNCITONING PROPERLY! I GOT THE DAMN VIRUS!!!!

arg...

i found that hotmail doesnt work yahoo doesnt work... my internet freezes up and i d/ced my internet yet i still dl!... thatz a fag... n i cant click direct links... so to remove this damn virus i gotta type in that long link... :/

i cant do a search... i had to do ctrl + f


ya THANKS XILO!

AznRocky
08-12-2003, 12:18 AM
ok i got this folder and its titled $NtUninstallKB823980$ and i'm not sure i should delete it or is hould just leave it alone it has some files that i' not sure i should keep!

ooo
08-12-2003, 12:20 AM
umm i cant run my virus scan what now? that sucks... :/... somethings killin my norton... itz not letting my norton do a live update or do a virus scan... ahh!

AznRocky
08-12-2003, 12:22 AM
wait so what does the worm actually do..........

EnJoi
08-12-2003, 12:24 AM
restart ur comp

Stonecoldfreak1
08-12-2003, 12:24 AM
Originally posted by AznRocky@12 August 2003 - 00:22
wait so what does the worm actually do..........
its been restarting my computer like a minute after i log on... i get a win32 error then it says you have 1 min till your system is restarted

Icey
08-12-2003, 12:28 AM
this is happning to sooo many ppl.. every make sure ur firewall, anti-virus and windows is upto date!

EnJoi
08-12-2003, 12:29 AM
its like the T3 virus what in the hell did u guys all download?

AznRocky
08-12-2003, 12:30 AM
yeah thats the problem i dont know what i downlaoded and my PC Cillin cant read it maby i should actually buy a Virus Scanner does anybody know a good UPDATED Virus scanner i can downlaod from scanner?

iMartin
08-12-2003, 12:41 AM
From Mess.be:

Security threat: beware MsBlast.exe

dwergs says:

D'z warned me about a hole in the MSN Messenger protocol that has lately been taken advantage of. It's the first thing I hear about it, but according to him "several people have already been hit by exploiters, gaining too much access".

To find out whether you're infected, press Ctrl+Alt+Del and verify if the process 'MsBlast.exe' is running. If it is, consider following the instructions below, but since there is no official security bulletin released on this topic yet... you are on your own.

- Kill the process MsBlast.exe from the task manager you just checked.
- Next, execute regedit.exe and search for the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Windows Auto Update

If it mentions MSBLAST in the path, remove that.

- Final step: delete msblast.exe from either the windows system or and system32 folders.

More on this as the story unfolds...

Storm
08-12-2003, 12:51 AM
well this fucker spreads mega fast............... i think its via KaZaA as well, though thats just a guess.........

i had it to, and i hope i dint spread it out 2 much......... newayz, like said b4 and cannot be stressed enough: UPDATE ur AV!!!!

i had updated mine 4 days ago, and i still got it............. and im updating regularly............

u can fix it by the means mentioned above, or dl a patch (http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp) (from m$ unfortunatly, so itll prolly mess up sumthing else) (thnx 2 MetroStars).......

when u dl this, make sure u SAVE it and dont open it.......... since your comp will restart every couple of mins.

once downloaded, reboot and upon rebooting, press F8 and let win boot in safe mode, without the posibility to connect to the internet!!! this will give u the time u need to install the patch, since the worm cant dl the msblast file.......

once installed, reboot, and ur homefree..................

Icey
08-12-2003, 12:57 AM
i dunno how this is spreading.. so many ppl got it at the same time ;)

callum
08-12-2003, 01:15 AM
Originally posted by AznRocky@12 August 2003 - 01:18
ok i got this folder and its titled $NtUninstallKB823980$ and i'm not sure i should delete it or is hould just leave it alone it has some files that i' not sure i should keep!
That's the fix metrostars suggested.

http://microsoft.com/technet/treeview/defa...in/MS03-026.asp (http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp)

AznRocky
08-12-2003, 01:17 AM
Originally posted by callum+12 August 2003 - 01:15--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (callum @ 12 August 2003 - 01:15)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin-AznRocky@12 August 2003 - 01:18
ok i got this folder and its titled &#036;NtUninstallKB823980&#036; and i&#39;m not sure i should delete it or is hould just leave it alone it has some files that i&#39; not sure i should keep&#33;
That&#39;s the fix metrostars suggested.

http://microsoft.com/technet/treeview/defa...in/MS03-026.asp (http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp) [/b][/quote]
WHAT R U TALKING i asked if i should delete i dont get how ur suppose to help????
since it has a funny title i&#39;m not sure if i should delete it or not??

callum
08-12-2003, 01:28 AM
Originally posted by AznRocky+12 August 2003 - 02:17--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (AznRocky &#064; 12 August 2003 - 02:17)</td></tr><tr><td id='QUOTE'>
Originally posted by callum@12 August 2003 - 01:15
<!--QuoteBegin-AznRocky@12 August 2003 - 01:18
ok i got this folder and its titled &#036;NtUninstallKB823980&#036; and i&#39;m not sure i should delete it or is hould just leave it alone it has some files that i&#39; not sure i should keep&#33;
That&#39;s the fix metrostars suggested.

http://microsoft.com/technet/treeview/defa...in/MS03-026.asp (http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp)
WHAT R U TALKING i asked if i should delete i dont get how ur suppose to help????
since it has a funny title i&#39;m not sure if i should delete it or not??[/b][/quote]
Did you read this thread?

http://www.klboard.ath.cx/index.php?showtopic=61117

Then did you download this.

http://microsoft.com/downloads/details.asp...&displaylang=en (http://microsoft.com/downloads/details.aspx?FamilyId=2354406C-C5B6-44AC-9532-3DE40F69C074&displaylang=en)

I.am
08-12-2003, 01:32 AM
Thanks for sharing useful piece of information with us. I was really curious about that file doing in system folder when Dapadipz mentioned.
Damn whoever created that&#33;

AznRocky
08-12-2003, 01:40 AM
Originally posted by callum+12 August 2003 - 01:28--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (callum &#064; 12 August 2003 - 01:28)</td></tr><tr><td id='QUOTE'>
Originally posted by AznRocky@12 August 2003 - 02:17

Originally posted by callum@12 August 2003 - 01:15
<!--QuoteBegin-AznRocky@12 August 2003 - 01:18
ok i got this folder and its titled &#036;NtUninstallKB823980&#036; and i&#39;m not sure i should delete it or is hould just leave it alone it has some files that i&#39; not sure i should keep&#33;
That&#39;s the fix metrostars suggested.

http://microsoft.com/technet/treeview/defa...in/MS03-026.asp (http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp)
WHAT R U TALKING i asked if i should delete i dont get how ur suppose to help????
since it has a funny title i&#39;m not sure if i should delete it or not??
Did you read this thread?

http://www.klboard.ath.cx/index.php?showtopic=61117

Then did you download this.

http://microsoft.com/downloads/details.asp...&displaylang=en (http://microsoft.com/downloads/details.aspx?FamilyId=2354406C-C5B6-44AC-9532-3DE40F69C074&displaylang=en) [/b][/quote]
HOW THE HELL IS MY QUESTION ANSWERED&#33;&#33;&#33;&#33; I&#39;m WOUNDERIN IF I SHOULD DELETE OR NOT WHY IN THE WORLD DID U GIVE ME ALINK TO A PATCH AND TO ANOTHER FORUM&#33;&#33;&#33;

callum
08-12-2003, 01:45 AM
Originally posted by AznRocky@12 August 2003 - 02:40
HOW THE HELL IS MY QUESTION ANSWERED&#33;&#33;&#33;&#33; I&#39;m WOUNDERIN IF I SHOULD DELETE OR NOT WHY IN THE WORLD DID U GIVE ME ALINK TO A PATCH AND TO ANOTHER FORUM&#33;&#33;&#33;
That was a link to this forum. :lol:

Look at the filename of that patch and look at the name of file you&#39;re wondering about.
Your file is the temporary folder for that patch.

The answers is NO you do not need to delete it.

I.am
08-12-2003, 01:48 AM
I am posting what I read recently. This will help many of us.
UPDATE

Aliases
msblast.exe
tftp
W32.Blaster.Worm (Symantec)
Win32.Poza (CA)
WORM_MSBLAST.A (Trend)

ABOUT THE VIRUS - REMOVAL INSTRUCTIONS FOR UR OS (http://vil.nai.com/vil/content/v_100547.htm)

AznRocky
08-12-2003, 01:55 AM
Originally posted by callum+12 August 2003 - 01:45--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (callum @ 12 August 2003 - 01:45)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin-AznRocky@12 August 2003 - 02:40
HOW THE HELL IS MY QUESTION ANSWERED&#33;&#33;&#33;&#33; I&#39;m WOUNDERIN IF I SHOULD DELETE OR NOT WHY IN THE WORLD DID U GIVE ME ALINK TO A PATCH AND TO ANOTHER FORUM&#33;&#33;&#33;
That was a link to this forum. :lol:

Look at the filename of that patch and look at the name of file you&#39;re wondering about.
Your file is the temporary folder for that patch.

The answers is NO you do not need to delete it. [/b][/quote]
THX U Thats all u had to do besides making all thoes other crappy post this one was needed THX U&#33;&#33;

ooo
08-12-2003, 02:02 AM
umm alright im thinkin are you sure the virus doesnt do anything else?

lol since i cant

copy hyperlinks or click em from the ie and i cant drag around any files in folders... weird shit...

AznRocky
08-12-2003, 02:14 AM
i&#39;m scared to download from kazaa and BITTORENT IS IT SAFE TO DOWNLOAD????

Cygnuz-Y
08-12-2003, 02:27 AM
THanks people, i was about to reinstall WINXP but thanks to you everything is back to normal&#33;&#33;&#33;&#33;&#33;

DWk
08-12-2003, 02:28 AM
lol...i had a virus infecting my system about 3 months ago....that was the time i realized I was dumb to NOT have mcafee installed. All my exes were corrupted so i couldnt execute anything. I installed McAfee but it got infected, so the virus couldnt be removed....

SOOOOO, i had to burn cds with windows cd burner&#33;&#33;&#33;&#33; not .exes cuz they were infected... then format machine :(

Since then, I always tell my friends to NOT BE DAMN STUPID and get an antivirus... lol and some of them call me a newbie... go figure...

Well one of my friends already got it..., and I would almost bet the one that called me newbie also got it....

man...shame on you. TODAY IS THE DAY you take the red pill and see how deep the damn rabbit hole goes&#33; BE SMART and get an AV before you end up like me :D

DWk

DWk
08-12-2003, 02:31 AM
lol why do people always blame XP when talkin about virus issues.....or more like EVERY issue? like 98 was so nice when u got the blue screen of death....

DWk

Skank
08-12-2003, 03:14 AM
the virus was designed to launch a denial of service attack against windows update site on the 15th or 16th of this month,whoever wrote this script is somwhat of a genius considering all the people who are infected at the time of writing

oh well hope u all sort ya shit out by the 15th cause u can bet ya ass theres more to come,this is probably the lull before the storm...


i love u billy san

AznRocky
08-12-2003, 03:30 AM
WINDOWS 98 WAS DA BOMB but like he said the blue screen of death its horrrible&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;&#33;

Acecool
08-12-2003, 08:15 AM
What does the virus do...

Cant copy + paste
Cant cut + paste
Cannot drag files
Cannot disconnect using system tray and network area once your on the internet.
Uses you computer to launch DOS attacks
A few websites do NOT work
It slows your internet down by at LEAST 50%
Cant use search (try F3 not sure if working.)

##
Cant find the registry keys (Not in run, searching for msblast.exe)


How do I remove it, I cant friggin dl the damned files on that removal site etc...

Dapadipz
08-12-2003, 11:30 AM
lol to make sure my pc dont fuck up i just remastered my pc, installed systemworks firewall etc
and updated all the virus definitions. just installed that patch again too

MetroStars
08-12-2003, 12:01 PM
fucking worm i did wipe my computer, and it&#39; didn&#39;t solve anything...

Dapadipz
08-12-2003, 12:04 PM
duz urs still restart metro

mine hasnt since yesterday now

MetroStars
08-12-2003, 12:08 PM
oh yea it&#39;s working fine now... but yesterday i thought if i wiped my machine it would work how wrong was i... just glad it&#39;s working now....

hugoharding
08-12-2003, 12:46 PM
Whenever I dial up to the internet after about a couple of minutes, my computer decides that it has to shut down, and this screen apears giving me one minute to close everything, then it shuts down:

http://www.angelfire.com/alt/hugo/systemshutdown.JPG

Also, sometimes this comes up just before the countdown:

http://www.angelfire.com/alt/hugo/genericprob.JPG

How can I fix this?

Hugo.

Adster
08-12-2003, 12:47 PM
lol maybe this topic will help you http://www.klboard.ath.cx/index.php?showtopic=61215 :lol:

seriously sorry though :(

DrSpud
08-12-2003, 01:02 PM
Something rather strange has started going on with my copy of Windows. Only a few days ago, I started randomly getting dialog boxes stating that the Remote Procedure Call had failed and that I should log off and restart, and it had a timer that counted down before it restarted by itself. In an attempt to stop it from forcing a restart, I changed the response to its failure in the computer management console from &#39;Restart the Computer&#39; to &#39;Take No Action&#39;. I didn&#39;t see any more RPC failure dialogs, as I expected, but then I started getting some really screwy issues. The first thing I noticed was that I couldn&#39;t copy and paste files in explorer. I later noticed that I couldn&#39;t drag files, in any program. Then a number of programs I regularly use started taking a long time to load (at least 5-10 minutes) and had some weird behavior: Nero gave an &#39;Invalid Handle&#39; error when trying to copy files to a compilation (Ctrl+1), WinRar took ~15 minutes to open an &#39;Extract To&#39; dialog, others just hung in random spots, restarting Windows took 10 minutes as opposed to 1, etc. And after a full restart (but not logging off & back on), the problems weren&#39;t present, but after just a few minutes they returned just the same as before.

Edit: It&#39;s all because of that damn Msblast virus. Bastards&#33;
Sorry for creating another topic about it. :rolleyes:

Livy
08-12-2003, 01:08 PM
i think you should read this post http://www.klboard.ath.cx/index.php?showtopic=61215
and this site http://securityresponse.symantec.com/avcen...moval.tool.html (http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html)

WARSUPPORT
08-12-2003, 01:09 PM
Sorry to tell you but you have the W32/Msblast virus.update your virus defs you should find msblast.exe in windows system32. just delete the file and restart your computer. I also got hit with this yesterday. Also use microsofts update website and apply the proper patches too prevent this happening in the future.

Adster
08-12-2003, 01:12 PM
Sorry to tell you but you have the W32/Msblast virus.update your virus defs you should find msblast.exe in windows system32. just delete the file and restart your computer. I also got hit with this yesterday. Also use microsofts update website and apply the proper patches too prevent this happening in the future.

Its not as easy as that&#33;&#33;

I tryed that plus 100 other things didnt work had to format&#33;&#33;

but u may be lucky

Adster
08-12-2003, 01:13 PM
oh not not anothe one hit by the MSBLAST&#33;&#33; :lol:

DrSpud
08-12-2003, 01:18 PM
Dammit&#33; I read some of the other posts about Msblast just now. Funny, I manually disabled a lot of the unneccessary services, including the WU service. Oh well, at least I know that XP sucks in a completely different way than I thought it did. <_<

Adster
08-12-2003, 01:22 PM
its not XP the problem

also 200 and NT4 as well suffer from this bastard

Dapadipz
08-12-2003, 01:53 PM
jus read this on neowin

If your having problems installing the patch within the 60 sec, when you see the window pop up telling you 60 sec, Go to Start, Run and type in shutdown -a. This will cancel the shutdown attempt. Thanks Sub for this tip&#33;

Acecool
08-12-2003, 01:58 PM
Hmm...

I didnt have any shutdown probs, only the (CAN COPY AGAIN YAY)


(
What does the virus do...

Cant copy + paste
Cant cut + paste
Cannot drag files
Cannot disconnect using system tray and network area once your on the internet.
Uses you computer to launch DOS attacks
A few websites do NOT work
It slows your internet down by at LEAST 50%
Cant use search (try F3 not sure if working.)

##
Cant find the registry keys (Not in run, searching for msblast.exe)


How do I remove it, I cant friggin dl the damned files on that removal site etc...

)

I got it removed, had somone send me the windows 2000 pro english patch, then it died...

ttttttttt
08-12-2003, 02:50 PM
go to http://www.cnn.com/2003/TECH/internet/08/1...reut/index.html (http://www.cnn.com/2003/TECH/internet/08/12/windows.worm.reut/index.html)

ttttttttt
08-12-2003, 03:10 PM
What if my home computer was infected and i burend a file that was infected then I used the cd on the network at school and now the school computers and laptops are having the same problems did i do it (like i care lol)

MetroStars
08-12-2003, 03:20 PM
What if my home computer was infected and i burend a file that was infected then I used the cd on the network at school and now the school computers and laptops are having the same problems did i do it (like i care lol)

That&#39;s funny, as long as your home computer isn&#39;t hurt then it&#39;s ok

RPerry
08-12-2003, 03:55 PM
I would laugh, but I almost got fired when I got my company&#39;s whole network virused by the anna kournicova virus :(

ultramagna
08-12-2003, 06:05 PM
You people must be foolz....that&#39;s why we have this problem today...users not caring about who or what they infect. well, what goes around will finally hit you too, and hopefully shut you down for good :rtfm:

ooo
08-12-2003, 06:07 PM
Originally posted by Acecool@12 August 2003 - 09:15
What does the virus do...

Cant copy + paste
Cant cut + paste
Cannot drag files
Cannot disconnect using system tray and network area once your on the internet.
Uses you computer to launch DOS attacks
A few websites do NOT work
It slows your internet down by at LEAST 50%
Cant use search (try F3 not sure if working.)

##
Cant find the registry keys (Not in run, searching for msblast.exe)


How do I remove it, I cant friggin dl the damned files on that removal site etc...
thank u for confirming&#33;... lol yep i figured that out .... lol and yea i dont have the shut down problem

maybe itz a win 2000 thing :P

AznRocky
08-12-2003, 07:50 PM
http://securityresponse.symantec.com/avcen...moval.tool.html (http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html)

go to this site if u think u have the virus its a program just made for this virus worm and can take it out easily&#33;

Izagaia
08-12-2003, 08:20 PM
Thank-you, all. :) I do not have this virus (yet) however at least now I have a floppy with everything (I hope) necessary to combat it should my system fall victim to it. :unsure:

DarkBlizzard
08-12-2003, 08:23 PM
What do u download to get this?

Izagaia
08-12-2003, 08:33 PM
The virus itself?..

Just about damn-near anything from any site. P2P users are especially at risk because of the shear amount of data that normally flows to and from their systems in the form of the files they...uh... share.

At any rate, just browse through each page of this thread and you will get an idea of how it is spreading based upon what other users have already explained.

ultramagna
08-12-2003, 10:30 PM
I&#39;ve got an idea for these virus maker "studs". Why don&#39;t you make a virus which are directed toward SPAM servers, which will at least help out in that area, and not just pick on poor ol&#39; Bill and his followers -- us.

DWk
08-12-2003, 11:06 PM
lol my university network was infected by "something". I didnt get the full news but I bet it was this virus.... Everyone was kicked out the lab and the ppl started trying to fix it.... lol i bet none uses this board ;)

Either way...its weird cuz the server is linux (think debian, or devian) but all the computers connect thru win xp...

who knows lol, but i guess its funny :D

DWk

swarnel
08-12-2003, 11:38 PM
is windows 98 imune from this virus?

cborga1985
08-13-2003, 12:37 AM
Originally posted by swarnel@12 August 2003 - 19:38
is windows 98 imune from this virus?
yeah i would like to know also&#33;

Adster
08-13-2003, 01:08 AM
No windows 98 is fine cannot get afeected

swarnel
08-13-2003, 01:23 AM
good old windows 98, ive never had any problems with it

cborga1985
08-13-2003, 03:01 AM
Originally posted by Hogster@12 August 2003 - 21:08
No windows 98 is fine cannot get afeected
cool nice i&#39;m not being affected&#33; Oh well I just installed ZoneAlarm 4 Pro and have Norton Systemworks 2003 so I hope that will help protect me from other viruses knowing they will probaly will make a Win98 version of the Msblast virus.

ehnoismemu
08-13-2003, 03:47 AM
you guys don&#39;t know how you got infected? you don&#39;t know which infected file you&#39;ve downloaded?

the guy who wrote this damn virus is a real genius&#33;&#33;&#33; from what i&#39;ve read, i understood that YOU DON&#39;T HAVE TO DOWNLOAD ANYTHING to get infected&#33;&#33;&#33; so how do you get infected?

there&#39;s a script (portscan) that searches a range of I.P. numbers for open ports, in this case, 145 and 2 more, i don&#39;t remember well.

and guess what, if you have a not updated windows xp/2000/nt, you&#39;re in trouble.

if you have windows xp/2000/nt and a firewall software that is not updated, guess what? you&#39;re in trouble&#33;&#33;&#33;

if you have windows xp/2000/nt, a firewall software and a NORTON ANTIVIRUS updated every wednesday (that&#39;s when symantec releases their weekly update for automatic live update), YOU&#39;RE IN TROUBLE&#33;&#33;&#33;&#33; hell, i update my NAV every wednesday and this sh&#33;t has just caught me&#33;&#33;&#33; i also have NORTON INTERNET (IN)SECURITY (updated every wednesday too) and that sh&#33;t has just caught me&#33;&#33;&#33;

imo, the key is: become paranoid and check windows update everyday, update your antivirus software everyday, and update your firewall software everyday.

and this kind of thing makes me think: was it worth every penny paid for Norton AntiVirus Professional? does symantec deserve every cent i paid for Norton Internet Security??? thank godness I DO HAVE A PIRATED OS&#33;&#33;&#33; now, do you think i&#39;ll buy my next license for updating NORTON definitions??? :lol:

EDIT
if you cannot stay connected time enough to download a removal tool (http://securityresponse.symantec.com/avcenter/FixBlast.exe), do the following:

block access to ports 145, 69 and 4444.
click the start button => run... and type regedit.exe
go to hkey_local machine => software => microsoft => windows => currentversion => run and delete the microsoft windows update entry
restart your computer
go to your %windir%&#092;system32 directory and delete the file named msblast.exe
download the removal tool linked above, run it, then update your windows, antivirus, firewall, kazaa lite, icq, notepad... :lol:

EDIT2
This is what the damn virus do:

http://www.ehnoismemu.kit.net/it_does_the_following.gif

WARSUPPORT
08-13-2003, 02:13 PM
Originally posted by Hogster@12 August 2003 - 13:12

Sorry to tell you but you have the W32/Msblast virus.update your virus defs you should find msblast.exe in windows system32. just delete the file and restart your computer. I also got hit with this yesterday. Also use microsofts update website and apply the proper patches too prevent this happening in the future.

Its not as easy as that&#33;&#33;

I tryed that plus 100 other things didnt work had to format&#33;&#33;

but u may be lucky
That&#39;s all I had to do, was delete the file and restart, that&#39;s it&#33; The purpose of this virus is to flood Microsoft this Saturday, not destroy your files. You should have no problems getting rid of this virus. When i was hit by this my virus scanner didn&#39;t even pick it up, I noticed the file in my windows task manager before my computer could shut down. It wasn&#39;t untill a couple of hours later that my virus definitions, were ready for this virus. So it&#39;s not like my virus scanner disinfected the file, I just deleted it and restarted. Sorry to hear that alot of people are having some bad luck with this.

[B][O][T]
08-13-2003, 02:30 PM
All OS others than Windows XP and Windows 2000 is safe.

BOT

Nightwolf
08-14-2003, 08:34 PM
Yeah, this is f***ed-up. I just upgraded from Win98 to XP (finally). I am positive that I did NOT have this virus two days ago, because the last thing I did was check my running processes with msconfig. Then after installation completed, I went to Windows Update and installed 28(&#33;) updates. I also downloaded drivers for my sound card (from Gateway and Creative&#39;s websites) and for my scanner (from Driverguide.com). Then things started getting sluggish, and my comp kept rebooting without warning. I ran msconfig again and sure enough, there was msblast.exe&#33; Luckily I caught it and removed it before it did any damage. Now I just wish I knew exactly where I got it from. :(

ace2003k
08-14-2003, 09:09 PM
to get rid of this virus just go

to RUN

TYPE &#39;&#39;MSCONFIG&#39;&#39;

DISABLE ALL PROGRAM ON STARTUP

RESTART YOUR MACHINE

APPLY THE SYMANTEC FIX BLAST EXE

DOWNLOAD AND APPLY MICROSOFT FIX

MSBLAST.EXE IS NO MORE&#33;&#33;

at least if you disable all program in msconfig on startup you dont need to worry about the 60 secs to apply the patch

hopefully this will help

ace

Supernode
08-14-2003, 10:04 PM
is&#39;nt a virus. Harmless fucker.
Its a popup that says that microsoft sucks.
No big deal............ :lol:

Keikan
08-15-2003, 01:52 AM
*sigh* the windows NT code is so troublesome :(&nbsp; but I don&#39;t want to go back to 9x code maybe Billy gates SHOULD stop making money and fix it&#39;s NT code

Adster
08-15-2003, 02:31 AM
damm Lunix servers probaly

MagusDraco
08-15-2003, 05:33 AM
small question. While I know that MSBlast shouldn&#39;t be able to hit a 98se computer, anyone know why the hell my computer would be locking up for a minute or so from time to time? (I think it might just be the old system lag striking back in a different way. Before I got my new hard-drive...again, (last one died a good couple weeks ago, head-drive crash.) the computer would at times get jumpy. The mouse cursor would skip frames, things loading would take longer then normal, and mp3s would distort. That&#39;s what I mean by system lag. Now at times for no apparent reason, the computer will lock up, and explorer.exe or some other file will say it is not responding. I can move the mouse, winamp and alt+tabing work, but the start menu is lagged, internet explorer can just be a bunch of white screen (though opera will still work fine usually) and mostly any non M&#036; software will still work normally. After a minute or two the computer will catch up and the start menu&#39;ll open and close about three times.) Just wondering what would cause that.

Rocktron
08-15-2003, 07:29 AM
I got this email from my provider this morning (a bit late to my opnion)

Yes it&#39;s Dutch sorry&#33;

Geachte Wanadoo-abonnee,

Het LoveSan-virus, waarvoor deze week werd gewaarschuwd,
is wereldwijd al op honderdduizenden computers aangetroffen.
LoveSan, ook wel MSBlaster en Blaster genoemd, slaat toe op
pc&#39;s waarop het besturingsprogramma Microsoft Windows
geïnstalleerd is.

Omdat het virus via een bepaalde poort de pc binnenkomt, is
Wanadoo gestart met het filteren van deze poort. Abonnees die
inbellen of via de kabel internetten lopen hierdoor minder
risico geïnfecteerd te worden door het virus. Helaas is Wanadoo
niet in staat alle connecties te beveiligen, waardoor abonnees met
een ADSL-verbinding nog steeds kwetsbaar zijn. Waar mogelijk
installeert Wanadoo filters om dit tot een minimum te beperken.

Om er zeker van te zijn dat uw computer beveiligd is, kunt u
op http://www.microsoft.nl een patch downloaden. Bent u al
besmet, ga dan naar http://www.bitdefender.com om het virus
weer te verwijderen.

Ga voor het laatste nieuws over dit virus naar
http://www.wanadoo.nl.

We hopen u hiermee voldoende te hebben geïnformeerd.

Met vriendelijke groet,
Wanadoo

sam33
08-15-2003, 02:29 PM
without it sounding like "I told you so", but why don’t you guys apply the MS Critical updates, impractically the one that came out a month ago that protected you against this venerability?

just thought there is probably some people who have reasons for not doing it?

sam

bulio
08-15-2003, 06:31 PM
ha, the worm dosen&#39;t effect me (win me) but still I get so many dam kernel 32 errors