Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1   Report Post  
Old 12-08-2003, 06:06 AM
KenCo
 
Posts: n/a
Default OT virus




a new nasty virus started today and you dont
even have to open an attachment to get it

open windows "task manager" and see if "msblast.exe" is there,
your infected if it is.

most virus scanners cant find it because its so new

also, if you know how to use regedit
kill these
HKLM/software/microsoft/windows/current ver/run
windowsupdate/msblast.exe
system32/msblast.exe

MS fix is here for Win2000
http://microsoft.com/downloads/detai...displaylang=en

info here
http://isc.sans.org/diary.html?date=2003-08-11
or
http://www.trendmicro.com/vinfo/viru...WORM_MSBLAST.A


--
http://www.kencofish.com Ken Arnold,
401-781-9642 cell 401-225-0556
Importer/Exporter of Goldfish,Koi,rare Predators
Shipping to legal states/countries only!
Permalon liners, Oase & Supreme Pondmaster pumps


Please Note: No trees or animals were harmed in the
sending of this contaminant free message We do concede
that a signicant number of electrons may have been
inconvenienced
  #2   Report Post  
Old 12-08-2003, 11:03 AM
David Modine
 
Posts: n/a
Default OT virus

I've got it.
Can you tell me more specifics on how to get rid of it?
In laymans terms?
I'm going to follow your link & try to learn.

"KenCo" wrote in message
...



a new nasty virus started today and you dont
even have to open an attachment to get it

open windows "task manager" and see if "msblast.exe" is there,
your infected if it is.

most virus scanners cant find it because its so new

also, if you know how to use regedit
kill these
HKLM/software/microsoft/windows/current ver/run
windowsupdate/msblast.exe
system32/msblast.exe

MS fix is here for Win2000

http://microsoft.com/downloads/detai...F541-4C15-8C9F
-220354449117&displaylang=en

info here
http://isc.sans.org/diary.html?date=2003-08-11
or

http://www.trendmicro.com/vinfo/viru...e=WORM_MSBLAST
..A


--
http://www.kencofish.com Ken Arnold,
401-781-9642 cell 401-225-0556
Importer/Exporter of Goldfish,Koi,rare Predators
Shipping to legal states/countries only!
Permalon liners, Oase & Supreme Pondmaster pumps


Please Note: No trees or animals were harmed in the
sending of this contaminant free message We do concede
that a signicant number of electrons may have been
inconvenienced



  #3   Report Post  
Old 12-08-2003, 11:33 AM
Theo van Daele
 
Posts: n/a
Default OT virus

Yup, it's a real one, not a hoax:

http://securityresponse.symantec.com...aster.worm.htm
l

"KenCo" schreef in bericht
...

a new nasty virus started today and you dont
even have to open an attachment to get it



  #4   Report Post  
Old 12-08-2003, 01:12 PM
danrahan
 
Posts: n/a
Default OT virus

This appears to be a variation on an old hoax. Ms Blast.exe appears to
be a legit file. This virus does not show up on Symantic's list.

There is an MSBlaster worm which willl exploit the existing and legit
Msblast.exe file.

I don't knwo what Msblast does, I would not remove it.

  #5   Report Post  
Old 12-08-2003, 01:23 PM
danrahan
 
Posts: n/a
Default OT virus

Symantec's response to the virus msblaster is here

http://www.symantec.com/avcenter/ven...ster.worm.html



  #6   Report Post  
Old 12-08-2003, 01:33 PM
danrahan
 
Posts: n/a
Default OT virus

Symantec's response is here

http://www.symantec.com/avcenter/ven...ster.worm.html


  #7   Report Post  
Old 12-08-2003, 03:17 PM
Lori
 
Posts: n/a
Default OT virus


I've got it.
Can you tell me more specifics on how to get rid of it?
In laymans terms?
I'm going to follow your link & try to learn.


W32.Blast is a worm.

Virus Information Center
Win32.Poza
Alias: DcomRPC.exploit,
W32.Blaster.Worm (Symantec) ,
W32/Lovsan.worm (McAfee),
W32/Msblast.A (F-Secure) ,
Win32/Poza.Worm ,
WORM_MSBLAST.A (Trend)
Category: Win32
Type: Worm
Published Date: 8/11/2003
Last Modified: 8/11/2003

Download ClnPoza.zip he
http://www3.ca.com/virusinfo/virus.aspx?ID=36265
  #8   Report Post  
Old 12-08-2003, 03:18 PM
Lori
 
Posts: n/a
Default OT virus


There is an MSBlaster worm which willl exploit the existing and legit
Msblast.exe file.


W32.Blast is a worm.

Virus Information Center
Win32.Poza
Alias: DcomRPC.exploit,
W32.Blaster.Worm (Symantec) ,
W32/Lovsan.worm (McAfee),
W32/Msblast.A (F-Secure) ,
Win32/Poza.Worm ,
WORM_MSBLAST.A (Trend)
Category: Win32
Type: Worm
Published Date: 8/11/2003
Last Modified: 8/11/2003

Download ClnPoza.zip he
http://www3.ca.com/virusinfo/virus.aspx?ID=36265

I don't knwo what Msblast does, I would not remove it.


It will keep throwing up error messages and reboots your computer,
monotonously(sp?) as long as your modem is running.
  #9   Report Post  
Old 12-08-2003, 04:43 PM
KenCo
 
Posts: n/a
Default OT virus

David Modine wrote:

I've got it.
Can you tell me more specifics on how to get rid of it?
In laymans terms?
I'm going to follow your link & try to learn.





use the remover tool from the antivirus sites then
basicly all you need to get is the microsoft patch to
plug/stop the port/s from being attacked again.

service pack 2 is needed also.

http://microsoft.com/downloads/detai...displaylang=en




"KenCo" wrote in message
...



a new nasty virus started today and you dont
even have to open an attachment to get it

open windows "task manager" and see if "msblast.exe" is there,
your infected if it is.

most virus scanners cant find it because its so new

also, if you know how to use regedit
kill these
HKLM/software/microsoft/windows/current ver/run
windowsupdate/msblast.exe
system32/msblast.exe

MS fix is here for Win2000

http://microsoft.com/downloads/detai...F541-4C15-8C9F
-220354449117&displaylang=en

info here
http://isc.sans.org/diary.html?date=2003-08-11
or

http://www.trendmicro.com/vinfo/viru...e=WORM_MSBLAST
.A




--
http://www.kencofish.com Ken Arnold,
401-781-9642 cell 401-225-0556
Importer/Exporter of Goldfish,Koi,rare Predators
Shipping to legal states/countries only!
Permalon liners, Oase & Supreme Pondmaster pumps


Please Note: No trees or animals were harmed in the
sending of this contaminant free message We do concede
that a signicant number of electrons may have been
inconvenienced
  #10   Report Post  
Old 12-08-2003, 08:06 PM
Wilson
 
Posts: n/a
Default OT virus

This program continually shuts your computer down when you are trying to get
the update patch....an easy way to get around this is to DL ZoneAlarm which
will allow you get get the files you need. ZoneAlarm detected and blocked
over 100 alerts in a 3 hour period this morning.....this is a nasty one.

KenCo wrote in message
...



a new nasty virus started today and you dont
even have to open an attachment to get it

open windows "task manager" and see if "msblast.exe" is there,
your infected if it is.

most virus scanners cant find it because its so new

also, if you know how to use regedit
kill these
HKLM/software/microsoft/windows/current ver/run
windowsupdate/msblast.exe
system32/msblast.exe

MS fix is here for Win2000

http://microsoft.com/downloads/detai...F541-4C15-8C9F
-220354449117&displaylang=en

info here
http://isc.sans.org/diary.html?date=2003-08-11
or

http://www.trendmicro.com/vinfo/viru...e=WORM_MSBLAST
..A


--
http://www.kencofish.com Ken Arnold,
401-781-9642 cell 401-225-0556
Importer/Exporter of Goldfish,Koi,rare Predators
Shipping to legal states/countries only!
Permalon liners, Oase & Supreme Pondmaster pumps


Please Note: No trees or animals were harmed in the
sending of this contaminant free message We do concede
that a signicant number of electrons may have been
inconvenienced





  #11   Report Post  
Old 12-08-2003, 08:18 PM
KenCo
 
Posts: n/a
Default OT virus

Wilson wrote:

This program continually shuts your computer down when you are trying to get
the update patch....an easy way to get around this is to DL ZoneAlarm which
will allow you get get the files you need. ZoneAlarm detected and blocked
over 100 alerts in a 3 hour period this morning.....this is a nasty one.



luckily its just annoying and not renaming files like
some of the other viruses.




--
http://www.kencofish.com Ken Arnold,
401-781-9642 cell 401-225-0556
Importer/Exporter of Goldfish,Koi,rare Predators
Shipping to legal states/countries only!
Permalon liners, Oase & Supreme Pondmaster pumps


Please Note: No trees or animals were harmed in the
sending of this contaminant free message We do concede
that a signicant number of electrons may have been
inconvenienced
  #12   Report Post  
Old 12-08-2003, 08:18 PM
Kelly E Jones
 
Posts: n/a
Default OT virus

In article ,
Wilson wrote:
This program continually shuts your computer down when you are trying to get
the update patch....an easy way to get around this is to DL ZoneAlarm which
will allow you get get the files you need.


Unfortunately, one of the effects of this bug is that it can
crash/reboot your system before you're able to download ZA, or an
update to your virus cleaning software, etc. (This prevented me from
being able to fix my system last night.)

I found this standalone blaster remover from Symantec. It's small
enough I should be able to download it before my system reboots, so
hopefully this will work:

http://securityresponse.symantec.com...oval.tool.html

Kelly
  #13   Report Post  
Old 12-08-2003, 09:12 PM
Wilson
 
Posts: n/a
Default OT virus


Unfortunately, one of the effects of this bug is that it can
crash/reboot your system before you're able to download ZA, or an
update to your virus cleaning software, etc. (This prevented me from
being able to fix my system last night.)

I found this standalone blaster remover from Symantec. It's small
enough I should be able to download it before my system reboots, so
hopefully this will work:


http://securityresponse.symantec.com...aster.worm.rem
oval.tool.html

Kelly


One thing that you MUST have on your computer besides Zone Alarm is Download
Accelerator with resume supported(even just the freebie version) this
allowed me to download ZoneAlarm to my machine even though it took me 3
times to get the full download....once you have it installed you don't get
shutdown anymore. Both ZoneAlarm and Download Accelerator are free.

I also used the symantec program...worked like a charm and I started feeling
better as I watched it run.

I would suggest everyone look into how to get rid of this virus, people are
passing it back and forth...over 50+ people on my server had it and I would
expect the real number was much higher than that.



  #14   Report Post  
Old 12-08-2003, 10:16 PM
Kelly E Jones
 
Posts: n/a
Default OT virus

In article ,
Wilson wrote:

Unfortunately, one of the effects of this bug is that it can
crash/reboot your system before you're able to download ZA, or an
update to your virus cleaning software, etc. (This prevented me from
being able to fix my system last night.)

I found this standalone blaster remover from Symantec. It's small
enough I should be able to download it before my system reboots, so
hopefully this will work:


http://securityresponse.symantec.com...aster.worm.rem
oval.tool.html

Kelly


One thing that you MUST have on your computer besides Zone Alarm is Download
Accelerator with resume supported


Yes, I thought of this as well. Unfortunately, I didn't have it yet,
and I couldn't download it because of the da*n worm! (My computer is
relatively new, and I haven't had a chance yet to download ZA, or a
download manager, or update my virus defs, etc. I'll be doing all
that as soon as get the system cleaned up.)

  #15   Report Post  
Old 12-08-2003, 11:17 PM
FBCS
 
Posts: n/a
Default OT virus

My DH has a computer repair business, his phones are ringing off the hook.
It''s going around virus dectectors.
"KenCo" wrote in message
...



a new nasty virus started today and you dont
even have to open an attachment to get it

open windows "task manager" and see if "msblast.exe" is there,
your infected if it is.

most virus scanners cant find it because its so new

also, if you know how to use regedit
kill these
HKLM/software/microsoft/windows/current ver/run
windowsupdate/msblast.exe
system32/msblast.exe

MS fix is here for Win2000

http://microsoft.com/downloads/detai...F541-4C15-8C9F
-220354449117&displaylang=en

info here
http://isc.sans.org/diary.html?date=2003-08-11
or

http://www.trendmicro.com/vinfo/viru...e=WORM_MSBLAST
..A


--
http://www.kencofish.com Ken Arnold,
401-781-9642 cell 401-225-0556
Importer/Exporter of Goldfish,Koi,rare Predators
Shipping to legal states/countries only!
Permalon liners, Oase & Supreme Pondmaster pumps


Please Note: No trees or animals were harmed in the
sending of this contaminant free message We do concede
that a signicant number of electrons may have been
inconvenienced



Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules

Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Are there virus resistant squash seeds? Virus killing my squash! goldtech Gardening 10 12-04-2013 01:16 PM
West Nile Virus and mosquitoes. Don Gardening 11 31-05-2003 10:56 AM
Advice needed on Plant Virus on a quince Helena Handbasket Bonsai 1 10-04-2003 03:56 PM
[IBC] Advice needed on Plant Virus on a quince Jim Lewis Bonsai 2 10-04-2003 02:56 PM
Tomato wilt/virus??? Ian Mitchell Australia 0 05-04-2003 06:33 AM


All times are GMT +1. The time now is 09:35 PM.

Powered by vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 GardenBanter.co.uk.
The comments are property of their posters.
 

About Us

"It's about Gardening"

 

Copyright © 2017