Larian Banner: Baldur's Gate Patch 9
Previous Thread
Next Thread
Print Thread
Page 3 of 10 1 2 3 4 5 9 10
Joined: Mar 2003
veteran
Offline
veteran
Joined: Mar 2003
Quote
It (the blaster worm) hit us really hard at work today! I have two computers on my desk and both got hit by the worm. One of the computers couldn't find it by doing a search either. I had to go to C:\WINNT\System32\ to find it so it was trying to hide. - Weird! <img src="/ubbthreads/images/graemlins/eek.gif" alt="" />


Here too.
I got a lot of calls from freinds, colleagues, ppl I know, ... about it.

And yes. It does hide. You have to turn everything else off and also check restore files and things like that.


~Setharmon~ >>[halfelven]<<
Joined: Mar 2003
veteran
Offline
veteran
Joined: Mar 2003
Quote
@DQueene:

A fix that could perfectly block the worm has been online on the Microsoft Update site for over a month.

It so stupid that most people just don't keep theirs systems up-to-date. If the computers at work were infected by this worm, it's basically the fault of the companies sytem-administrator.
Also, a solid firewall could have spared you alot of throubles.
(Here @ work we have a double Linux firewall <img src="/ubbthreads/images/graemlins/winkwink.gif" alt="" /> )




I agree.
And that might be why I didn't got it. I recieve security updates from microsoft regularly. Same for my antivirus and firewall.


~Setharmon~ >>[halfelven]<<
Joined: Mar 2003
Location: sailing around
veteran
Offline
veteran
Joined: Mar 2003
Location: sailing around
ok, something weird happened: i was online, and all of a sudden the screen turned white but i still had my cursor, the something said i had been infected?? so i rebooted, and went to get that removal tool that viper posted, and i was reading about the worm and it said it doesn't affect windows ME which is what i'm running. anybody know if this is the same worm or something else?? i'm scanning with norton right now.

[color:"orange"] edit: [/color] norton scan came up clean... <img src="/ubbthreads/images/graemlins/confused.gif" alt="" /> what's going on? <img src="/ubbthreads/images/graemlins/cry.gif" alt="" />

Last edited by faile; 13/08/03 06:27 PM.

Joined: Jun 2003
Location: Visible
old hand
Offline
old hand
Joined: Jun 2003
Location: Visible
Quote
ok, something weird happened: i was online, and all of a sudden the screen turned white but i still had my cursor, the something said i had been infected?? so i rebooted, and went to get that removal tool that viper posted, and i was reading about the worm and it said it doesn't affect windows ME which is what i'm running. anybody know if this is the same worm or something else?? i'm scanning with norton right now.

[color:"orange"] edit: [/color] norton scan came up clean... <img src="/ubbthreads/images/graemlins/confused.gif" alt="" /> what's going on? <img src="/ubbthreads/images/graemlins/cry.gif" alt="" />


Full scan? (i.e. - not just the removal tool?)

Have you tried running AdAware or SpyBot (both free downloads, and will check for malware, spyware and other nasties that aren't technically viruses)? Might also be something in the web page you were on at the time... ?

Just some ideas until the experts show up! <img src="/ubbthreads/images/graemlins/smile.gif" alt="" />




Joined: Mar 2003
Location: sailing around
veteran
Offline
veteran
Joined: Mar 2003
Location: sailing around
yes, a full norton scan, i haven't done anything with the removal tool but download it. i'll try adaware, i have that.

the page i was looking at was some article on msn.

[color:"orange"] edit:[/color] adaware came up fine.

Last edited by faile; 13/08/03 07:01 PM.

Joined: Jun 2003
Location: Visible
old hand
Offline
old hand
Joined: Jun 2003
Location: Visible
Quote
yes, a full norton scan, i haven't done anything with the removal tool but download it. i'll try adaware, i have that.

the page i was looking at was some article on msn.

[color:"orange"] edit:[/color] adaware came up fine.


If your definitions on both AdAware and Norton are current, I'm as baffled as you are! May have been a prank by some hacker (MSN site, after all), but I'm sure our forum tech-types will have some other good ideas.

Any residual problems with your system, or was it working ok after the re-boot?

Joined: Mar 2003
Location: Brasil
old hand
Offline
old hand
Joined: Mar 2003
Location: Brasil
Hi faile, if your Norton is atualized you can use it for scan, but i think this is nothing to warn about, depending of what you did at this time of course.


Who's gonna show you how to fly!
Joined: Aug 2003
Location: north ontario
apprentice
Offline
apprentice
Joined: Aug 2003
Location: north ontario
Download a new virus program (freebie) and run it, it may have just been a script kiddie doing remote admin (like someone else said its MSN)or it could be a legit virii and "tweaked" norton not to recognize it.
www.vcatch.com version 5.0 should do. Try this.
If you still notice problems, use some intrusion detection software:
http://www.fidelissec.com/mudpit.html (never heard of this one just came across it recently though)
www.snort.org (decent though this mudpit thing above is supposed to be better)
http://www.javaspot.net/cids/
If its someone remote admining your comp then you have numerous options to "rectify" their bad behaviour.

Dunyain

Edit: You should try the removal tool also, don't know if you have, you just stated you've downloaded it and thats it. I was under the impression that this new "worm" went into *higher* (couldn't think of the correct word) level microsoft programs

2nd EDIT: Do you have any experience with PCAnywhere or any other remote admin program?? That's kinda what it sounds like, when you connect from a remote location, some programs do that (aforementioned one specifically) so that you know that there is a remote admin. did your Background CHANGE?? If so, it sounds like someone was/is trying to remote admin your computer.

Last edited by dunyain; 13/08/03 07:30 PM.
Joined: Mar 2003
Location: sailing around
veteran
Offline
veteran
Joined: Mar 2003
Location: sailing around
everything seems to be running okay now, i ran the removal tool for the blaster worm and it didn't find anything, either. but while i was reading, it said the worm can cause crashes while attempting to enter the system. maybe that is what happened. i will try one of those links, thanks, dunyain.


Joined: Aug 2003
Location: north ontario
apprentice
Offline
apprentice
Joined: Aug 2003
Location: north ontario
Read the second edit on that post above too. Hopefully it was just that worm trying to access your computer and faile-ing (sorry that was corny). Hope your computer runs smoothly and nothings wrong with it. Glad to have offered alittle advice, no thanks needed.

Joined: Mar 2003
Location: sailing around
veteran
Offline
veteran
Joined: Mar 2003
Location: sailing around
Quote

2nd EDIT: Do you have any experience with PCAnywhere or any other remote admin program?? That's kinda what it sounds like, when you connect from a remote location, some programs do that (aforementioned one specifically) so that you know that there is a remote admin. did your Background CHANGE?? If so, it sounds like someone was/is trying to remote admin your computer.


no experience with pc anywhere. background didn't change, the screen just turned blank and white.

Quote
faile-ing (sorry that was corny).
\
hee hee!! <img src="/ubbthreads/images/graemlins/delight.gif" alt="" /> <img src="/ubbthreads/images/graemlins/delight.gif" alt="" />

Last edited by faile; 13/08/03 07:41 PM.

Joined: Aug 2003
Location: north ontario
apprentice
Offline
apprentice
Joined: Aug 2003
Location: north ontario
Hmm, makes me think of a remote admin tool, with the way your screen went (that and an infection notice coming up). Maybe try one or two more freebie virus checkers as someone could have trojan'd you with that tool. If nothing comes up check your quarentine logs in Norton, noticed it will sometimes sequester a virus automatically then *hide* it, very frustrating though only has happened once, thought I was seeing things. If you still find nothing, then your probably good and it *could* have just been the worm trying to infect your comp and you have no worries. Though if it happens again (hopefully not) then post here and I can point you to some more intrusion detection, packet sniffers, etc etc that will at least source what's happening by logging it.

dunyain

PS. don't worry bout the pcanywhere, was just using it for a reference/example to see if it was like that.

Joined: Mar 2003
Location: sailing around
veteran
Offline
veteran
Joined: Mar 2003
Location: sailing around
ok, i will try more virus checks. thanks!


Joined: Aug 2003
Location: north ontario
apprentice
Offline
apprentice
Joined: Aug 2003
Location: north ontario
<img src="/ubbthreads/images/graemlins/wave.gif" alt="" /> closest I could find to a hat tip

Joined: Mar 2003
A
veteran
OP Offline
veteran
A
Joined: Mar 2003
Haven't I posted that seems to be already a second worm "going on" ? Could it be this one ? (It's in one of my above postings.)


When you find a big kettle of crazy, it's best not to stir it.
--Dilbert cartoon

"Interplay.some zombiefied unlife thing going on there" - skavenhorde at RPGWatch
Joined: Mar 2003
Location: sailing around
veteran
Offline
veteran
Joined: Mar 2003
Location: sailing around
you did??


Joined: Mar 2003
Location: Canada
veteran
Offline
veteran
Joined: Mar 2003
Location: Canada
Quote
I agree that - as usual - the home users are the loosers.

Companies have Hardware Firewalls, Intrusion Detection Systems and advanced stuff, but the home user hasn't.

And currently Blaster is spreading mostly because of home users.


And now for something different ...

It seems, there's a new kid on the block :

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RPCSDBOT.A

Technical details :

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RPCSDBOT.A&VSect=T


Here darlin

Joined: Mar 2003
Location: sailing around
veteran
Offline
veteran
Joined: Mar 2003
Location: sailing around
oh yeah... <img src="/ubbthreads/images/graemlins/ouch.gif" alt="" /> <img src="/ubbthreads/images/graemlins/rolleyes.gif" alt="" />


Joined: Apr 2003
veteran
Offline
veteran
Joined: Apr 2003
actually ther's 3 viruses going round! <img src="/ubbthreads/images/graemlins/ouch.gif" alt="" />

look here:........ virus info


[color:"#33cc3"]Jurak'sRunDownShack!
Third Member of Off-Topic Posters
Defender of the [color:"green"]PIF.
[/color] Das Grosse Grüne Ogre!!! [/color]
Joined: Aug 2003
Location: north ontario
apprentice
Offline
apprentice
Joined: Aug 2003
Location: north ontario
Hmmm people are having their fun with this one while they can it looks like.

Page 3 of 10 1 2 3 4 5 9 10

Moderated by  ForkTong, Larian_QA, Lynn, Macbeth 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.5