Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

bartcop has worm virus

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
protect freedom impeach bush now Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 01:23 PM
Original message
bartcop has worm virus
Note from Bartcop (e-scribed by MicheleK - BartCook):

Computer problems - was Bart hacked!?!?!! -- the next issue should be up tomorrow.
In the meantime, the 'BartGeek' has been called, and they await his wisdom at the Bart Mansion.
Send email to xxxxxxx for now, he'll try to get back to you asap!!

Note from Marc Perkel - Actually - Bartcop wasn't hacked - he has that new msblast.exe worm. This is a serious virus unlike anything I've seen before. This virus has nothing to do with email and you can be infected by just being connected to the internet. This message applies to EVERYONE running ANY version of WINDOWS - DO THIS! If you are running windows you should do the following:

Start Task Manager. Click the process tab. Look for a program called msblast.exe. If you see it - kill the process.

Go to Microsoft's Windows Update and install all the critacal updates. It is extremely important that you do this. If you do not install these updates - you will get invected!!!!

If you can't connect to Microsoft - here's part of a self fix. Select RUN and type in regedit. Walk through the tree looking for this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Which will contain - "windows auto update"="msblast.exe" - DELETE THIS KEY!


You will find a file called c:\windows\system32\msblast.exe - DELETE THIS FILE!

Don't wait till you're already infected to fix this. You need to deal with this before it happens if you are not infected already. Until you apply these patches - your computer is vulnerable to all kinds of attacks.

Tell all your friends who are running Windows to do the same - spread the word!

For more information - check out the Norton Anti-virus site.

A public service announcement brought to you by your friends at Bartcop.com.

Printer Friendly | Permalink |  | Top
Liberal_Andy Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 01:31 PM
Response to Original message
1. Our company's computers were infected, but only those...
running Windows XP & Windows 2000, earlier versions are ok, according to our IT people.

LA
Printer Friendly | Permalink |  | Top
 
Classical_Liberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 06:31 PM
Response to Reply #1
20. Get your computers updated before the 15th. This virus has a DoS attack
on the windows update website that kicks in then.

according to cnet

http://reviews.cnet.com/4520-6600_7-5062389.html?tag=cnetfd.sd

"MSBlast contains a denial-of-service (DoS) attack aimed at Microsoft's windowsupdate.com. The attack will start on August 15 and continues throughout the end of the year. MSBlast updates the system Registry with the following line so that it will run each time the computer is rebooted."

Here is the windows update address

http://v4.windowsupdate.microsoft.com/en/default.asp
Printer Friendly | Permalink |  | Top
 
bookman Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 01:41 PM
Response to Original message
2. Tough Fix
I spent several hours into the early am working on this. The fix is on gateway's support site as well as symantec.

I might add you need to disable System Restore before scanning for virus, deleting the files, deleting registry value, empty trash, enable system restore.

I'd also suggest getting the critical updates from Microsoft.

If you have this..it's fixable.

If you don't, It's worth checking it.
Printer Friendly | Permalink |  | Top
 
EarlG ADMIN Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 01:44 PM
Response to Original message
3. This is not a virus
It's a worm which does not affect Windows 95/98/ME. Other versions (including XP) have patches available here:

http://www.microsoft.com/technet/treeview/?url=/technet/security/bulletin/MS03-026.asp

Everyone running XP or NT should get this patch immediately.

More information is available here:

http://www.informationweek.com/story/showArticle.jhtml?articleID=13100032

Still more info:

http://www.microsoft.com/security/incident/blast.asp



Printer Friendly | Permalink |  | Top
 
Trek234 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 02:13 PM
Response to Reply #3
9. Earl
Edited on Tue Aug-12-03 02:19 PM by Trek234
Be aware the Microsoft patch you point to does NOT fully resolve the exploit. (I'm not saying not to get the patch to anyone - by all means get it)

However, you are still vulnerable to this exploit. It is simply carried out in a different manner.

If you have an effective firewall though you're ok.
Printer Friendly | Permalink |  | Top
 
EarlG ADMIN Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 03:45 PM
Response to Reply #9
11. Ah
Thanks for the heads up.
Printer Friendly | Permalink |  | Top
 
graham67 Donating Member (732 posts) Send PM | Profile | Ignore Tue Aug-12-03 02:25 PM
Response to Reply #3
10. WTF??
I downloaded the patch and now I'm getting a run.dll error on startup. What's it mean?
Printer Friendly | Permalink |  | Top
 
goobergunch Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 06:07 PM
Response to Reply #3
18. I never thought I'd be glad that I have an old (98) system (n/t)
Printer Friendly | Permalink |  | Top
 
Classical_Liberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 06:16 PM
Response to Reply #18
19. I have Win 98, and something is still massively trying to scan port 135
Edited on Tue Aug-12-03 06:17 PM by Classical_Liberal
according to my firewall.
Printer Friendly | Permalink |  | Top
 
Brian Sweat Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 01:45 PM
Response to Original message
4. I told him to swallow a penny,
but he wouldn't listen to me.
Printer Friendly | Permalink |  | Top
 
charlie Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 01:47 PM
Response to Original message
5. If you've got a decent firewall
with your ports locked down, you shouldn't have problems. For the past two days or so, I've been getting 5-20 probes to port 135 an hour -- must be a ton of infected PCs out there.
Printer Friendly | Permalink |  | Top
 
Classical_Liberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 06:04 PM
Response to Reply #5
17. I just looked at my log on my "Tiny Personal Firewall"
and there have been about 400 scans turned down on 135 today.
Printer Friendly | Permalink |  | Top
 
atldem Donating Member (202 posts) Send PM | Profile | Ignore Tue Aug-12-03 02:02 PM
Response to Original message
6. I've been getting these weird pop up messages
lately that say "Win32 has failed" or something like that. Is that the virus? I set up my firewall and am downloading the patch. Is there anything else I need to do?
Printer Friendly | Permalink |  | Top
 
NewYorkerfromMass Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 02:04 PM
Response to Original message
7. my quarantine pops up every day now
for over a week.
Printer Friendly | Permalink |  | Top
 
BigMcLargehuge Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 02:07 PM
Response to Original message
8. ended up with it on my work laptop
it took two days to diagnose and fix... no fun there. Whomever writes these pieces of malicious code, if caught, should be sent to minister to ebola victims for 6 months at a stretch.
Printer Friendly | Permalink |  | Top
 
stopbush Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 04:15 PM
Response to Original message
12. Surefire way to eliminate virus threats
1. Disconnect Windows machine from outlet

2. Disconnect hard drive from all monitors, periphs etc

3. Carry Windows HD to 2nd-floor window

4. Drop Window HD out of 2nd-floor window, preferrably a window above a concrete driveway

5. Pick up phone

6. Call Apple and order a new Mac!


:think:
Printer Friendly | Permalink |  | Top
 
retread Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 04:29 PM
Response to Reply #12
13. Oh Please!!! If Macs had a user base of 50% of winblows
they would be subject to all manner of threats. ANY operating system that exposes itself to the outside world can be compromised.
Printer Friendly | Permalink |  | Top
 
stopbush Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 04:44 PM
Response to Reply #13
15. Of course, you're correct
and Mac will probably never have more than 5% of the market so virus writers will never really bother themselves with the Mac platform.

So, my attempt-at-humor solution still stands.

BTW - I've had viruses on my Mac before, just alot fewer chances at getting them than I've experienced on PCs I also use.
Printer Friendly | Permalink |  | Top
 
ParanoidPat Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 04:37 PM
Response to Reply #12
14. Perhaps you should read through this thread.....
.....started by Will Pitt. Can someone recommend a good firewall? :evilgrin:

Post #28 has a few links Apple owners really should visit! :)
Printer Friendly | Permalink |  | Top
 
LTR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-12-03 05:20 PM
Response to Original message
16. Bartcop has a new update
Doing it on his laptop.

http://www.bartcop.com
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sat May 11th 2024, 06:22 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC