Notices
Non Scooby Related Anything Non-Scooby related

**** WARNING: Blaster worm ****

Thread Tools
 
Search this Thread
 
Old 12 August 2003, 11:27 AM
  #1  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Exclamation

Mods plz leave here for a bit!

Spreading like wildfire at the moment. Automatically installs itself on vulnerable machines, then sits scanning for more.

Will do an attack on windowsupdate.com after the 15th of Aug.

Please please please patch your machine's DCOM software.

See here for Windows XP and Windows 2000 here

Information on the virus is here.

Email me if you want some more comprehensive removal instructions, as i'm having to remove it from reps machines at the rate of 5 already today!!!

Andy
Old 12 August 2003, 11:35 AM
  #2  
flat4
\m/ ^_^ \m/
 
flat4's Avatar
 
Join Date: Dec 2001
Location: 2010 Time Attack Club Pro Champion - Powered by ScoobyClinic
Posts: 36,816
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

i know of two people aswell who have had this last night, i'll be checking mine tonight
Old 12 August 2003, 12:19 PM
  #3  
beemerboy
Scooby Regular
 
beemerboy's Avatar
 
Join Date: Sep 2002
Location: Essexville
Posts: 4,391
Likes: 0
Received 0 Likes on 0 Posts
Post

all right boys,
i had 5 webservers go down last night with this ******!!!!

was in at 8am, and had them sorted by 9.28 (2 mins before opening time at the zoo)

i'm now back home supping beer!!!

basically i took the servers offline, checked the reg for HKLM/software/microsoft/windows/run for spurrious entries (and deleted them)
then i installed patch windows2000-KB823980-x86-ENU.exe
ontop of sp3

i have heard that sp4 can actually open up the vulnerability again, so do be careful.

good luck virus warriors

Dazza
Old 12 August 2003, 12:27 PM
  #4  
ianmiller999
Scooby Regular
 
ianmiller999's Avatar
 
Join Date: Feb 2003
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
Post

What does it actually do?
Old 12 August 2003, 12:30 PM
  #5  
NACRO
BANNED
 
NACRO's Avatar
 
Join Date: Apr 2003
Location: Your home is worthless.You can't afford to run your car.Your job is on the line.Schadenfreude rules.
Posts: 4,787
Likes: 0
Received 0 Likes on 0 Posts
Post

NB: you will need SP2 or better installed for this to work.
Old 12 August 2003, 12:33 PM
  #6  
PG
Scooby Regular
 
PG's Avatar
 
Join Date: Jul 2001
Location: Perthshire
Posts: 6,396
Likes: 0
Received 0 Likes on 0 Posts
Post

It doesnt sound good !
But I have a load of information stuck to the wall behind me where it flew right over my head
I downloaded and ran the XP download thingy....is that job done ??
Old 12 August 2003, 12:33 PM
  #7  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

Ian have a look at the info page in my post. Tells you all you wanna know + more!!


Andy
Old 12 August 2003, 03:16 PM
  #8  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

Everyone patch patch patch!!

For those of you that have already been hit and RPC is causing machine to reset 60secs after venturing into an internet program - here's a quick guide i knocked together for removing it.

Andy
Old 12 August 2003, 03:18 PM
  #9  
scoob_babe
Scooby Regular
 
scoob_babe's Avatar
 
Join Date: Feb 2002
Location: Nobody knows how to tie the simple knots that I know
Posts: 8,010
Likes: 0
Received 0 Likes on 0 Posts
Talking

got my mcafee nicely updated!
Old 12 August 2003, 03:27 PM
  #10  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

Yes but it doesn't come in as a file on an email or website. Its due to a remote vulnerability. You should still remove the bug.

All the machines I've seen it on had AV software running, as soon as its on it prevents updates being done i think, or hinders the AV engine..

Andy
Old 12 August 2003, 03:35 PM
  #11  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,853
Received 51 Likes on 34 Posts
Post

We - McAfee - detected it proactively. Not all Antivirus is the same.

Info here
Old 12 August 2003, 04:23 PM
  #12  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

We use mcafee on our laptops and desktops at work

Andy
Old 12 August 2003, 04:51 PM
  #13  
AdrianFRST
Scooby Regular
 
AdrianFRST's Avatar
 
Join Date: Oct 2000
Posts: 368
Likes: 0
Received 0 Likes on 0 Posts
Post

Installed the patch, rebooted and now it seems to have taken out my ProtectedStorage service (Win2k Server)...

"The IIS Admin Service service depends on the following nonexistent service: ProtectedStorage"

Coincidence?

Old 12 August 2003, 07:57 PM
  #14  
Stueyb
Scooby Regular
 
Stueyb's Avatar
 
Join Date: May 2002
Posts: 1,893
Likes: 0
Received 0 Likes on 0 Posts
Post

Ive just finished patching all my machines. However I have noticed something strange on a few machines. Namely that if you go to control panel, instead of getting what youd expect ie the icons in the right hand pane and the bumf on the left, the left contains all the icons. and the right is blank. This occured on 2 win2k systems. I ran the norton removal tools but they didnt find anything. Could this be the same problem ? Just seems strange getting it on two systems totally seperate and all, and both acting up. Also the user control panel icon was gone completely. Very suss.

Any ideas
Old 12 August 2003, 07:58 PM
  #15  
Taff107
Scooby Regular
 
Taff107's Avatar
 
Join Date: Nov 2002
Location: Hants
Posts: 1,489
Likes: 0
Received 0 Likes on 0 Posts
Post

Sh1te, got the damn thing on the other PC now!
Old 12 August 2003, 08:15 PM
  #16  
ianmiller999
Scooby Regular
 
ianmiller999's Avatar
 
Join Date: Feb 2003
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
Post

Check out symnatec or however it is spelt they got someit to deal with it now aswell
Old 12 August 2003, 08:22 PM
  #17  
Stueyb
Scooby Regular
 
Stueyb's Avatar
 
Join Date: May 2002
Posts: 1,893
Likes: 0
Received 0 Likes on 0 Posts
Post

Ive just finished patching all my machines. However I have noticed something strange on a few machines. Namely that if you go to control panel, instead of getting what youd expect ie the icons in the right hand pane and the bumf on the left, the left contains all the icons. and the right is blank. This occured on 2 win2k systems. I ran the norton removal tools but they didnt find anything. Could this be the same problem ? Just seems strange getting it on two systems totally seperate and all, and both acting up. Also the user control panel icon was gone completely. Very suss.

Any ideas
Old 12 August 2003, 08:23 PM
  #18  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

Tool for removing worm is here

Andy
Old 12 August 2003, 08:24 PM
  #19  
Stueyb
Scooby Regular
 
Stueyb's Avatar
 
Join Date: May 2002
Posts: 1,893
Likes: 0
Received 0 Likes on 0 Posts
Post

Ive just finished patching all my machines. However I have noticed something strange on a few machines. Namely that if you go to control panel, instead of getting what youd expect ie the icons in the right hand pane and the bumf on the left, the left contains all the icons. and the right is blank. This occured on 2 win2k systems. I ran the norton removal tools but they didnt find anything. Could this be the same problem ? Just seems strange getting it on two systems totally seperate and all, and both acting up. Also the user control panel icon was gone completely. Very suss.

Any ideas
Old 12 August 2003, 08:27 PM
  #20  
ianmiller999
Scooby Regular
 
ianmiller999's Avatar
 
Join Date: Feb 2003
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
Post

So in comparison to other bugs how big a threat is this, love bug scale-more less?
Old 12 August 2003, 08:43 PM
  #21  
pugoetru
Scooby Regular
 
pugoetru's Avatar
 
Join Date: Mar 2003
Location: from a land thats cold and wet
Posts: 2,088
Likes: 0
Received 0 Likes on 0 Posts
Post

yea herbies gona get ya lol
Old 12 August 2003, 09:01 PM
  #22  
unclebuck
Scooby Regular
 
unclebuck's Avatar
 
Join Date: Nov 2002
Location: Talk to the hand....
Posts: 13,331
Likes: 0
Received 0 Likes on 0 Posts
Post

patch patch patch!!

done, done, done!!

Seems to have rebooted with everything still working.

Cheers chaps.

BTW would Zone Alarm (free not Pro) be man enough to stop the virus?

UB
Old 12 August 2003, 09:12 PM
  #23  
pugoetru
Scooby Regular
 
pugoetru's Avatar
 
Join Date: Mar 2003
Location: from a land thats cold and wet
Posts: 2,088
Likes: 0
Received 0 Likes on 0 Posts
Post

i got 4 wierd emails today didnt open them could that be how it gets in?
Old 12 August 2003, 09:20 PM
  #24  
Andrewza
Scooby Regular
 
Andrewza's Avatar
 
Join Date: Jan 2002
Posts: 667
Likes: 0
Received 0 Likes on 0 Posts
Post

If you're having trouble staying on the net to get the patch and get it installed, disconnect from the net (even unplugging the cable), get up the properties of your net connection, be that dialup or network card and click the advanced tab, then tick the box "Protect my computer and network by limiting..." under "internet connection firewall" it's not good, but it's sufficient to stop this work exploiting your machine and crashing it while you install the patch and run the removal tool.
Old 12 August 2003, 09:25 PM
  #25  
Scoobydick
Scooby Regular
 
Scoobydick's Avatar
 
Join Date: Mar 2001
Posts: 628
Likes: 0
Received 0 Likes on 0 Posts
Post

Is there a patch for Windows 98
Cheers
Old 12 August 2003, 10:21 PM
  #26  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

I dont think it sufers from the problem.??? Anyone know?

Andy
Old 12 August 2003, 10:38 PM
  #27  
markr1963
Scooby Regular
 
markr1963's Avatar
 
Join Date: Jun 2002
Location: Perth, Western Australia
Posts: 1,866
Likes: 0
Received 0 Likes on 0 Posts
Post

No, just Win2k annd XP according to symantec

Mark
Old 12 August 2003, 10:42 PM
  #28  
PG
Scooby Regular
 
PG's Avatar
 
Join Date: Jul 2001
Location: Perthshire
Posts: 6,396
Likes: 0
Received 0 Likes on 0 Posts
Post

So I shouldnt have a prob with my Laptop running ME????.........well other than the fact it is running ME

Will this cause an XP machine to tell you to save all your stuff 'cos it is about to close the connection ?

If so my mate has it
Old 12 August 2003, 10:47 PM
  #29  
SiDHEaD
Scooby Regular
Thread Starter
 
SiDHEaD's Avatar
 
Join Date: Apr 2002
Location: Birmingham
Posts: 9,196
Likes: 0
Received 0 Likes on 0 Posts
Post

Yes PG, he has it!!!

Andy
Old 12 August 2003, 10:50 PM
  #30  
PG
Scooby Regular
 
PG's Avatar
 
Join Date: Jul 2001
Location: Perthshire
Posts: 6,396
Likes: 0
Received 0 Likes on 0 Posts
Post

so I have the patch download on my desktop can I burn this file take it to him, patch it then get online to run the removal ??


Quick Reply: **** WARNING: Blaster worm ****



All times are GMT +1. The time now is 04:45 PM.