Thread Tools
Old August 12, 2003, 15:29   #31
Whaleboy
NationStatesAlpha Centauri Democracy GameACDG The Cybernetic ConsciousnessMac
Prince
 
Whaleboy's Avatar
 
Local Time: 07:14
Local Date: November 2, 2010
Join Date: Jan 2003
Location: Please make all cheques payable to Whaleboy
Posts: 853
Oh I use mozilla... no matter!
__________________
"I work in IT so I'd be buggered without a computer" - Words of wisdom from Provost Harrison
"You can be wrong AND jewish" - Wiglaf :love:
Whaleboy is offline  
Old August 12, 2003, 15:33   #32
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:14
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
If Mozilla decided to support ActiveX, you could use that too.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 12, 2003, 16:23   #33
Alex
Emperor
 
Alex's Avatar
 
Local Time: 04:14
Local Date: November 2, 2010
Join Date: Mar 1999
Location: Brasil
Posts: 3,958
How serious is that thing? I mean, I read something about a Lovsan virus that is spreading like fire, but I don't know if it is the same thing.
__________________
'Yep, I've been drinking again.'
Alex is offline  
Old August 12, 2003, 16:28   #34
Zopperoni
Age of Nations TeamApolyCon 06 Participants
Emperor
 
Zopperoni's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Dec 2000
Posts: 5,045
Yes, this is the same as the lovsan virus.
__________________
Blog: www.kennethlim.net // Twitter: @kennethlim
Zopperoni is offline  
Old August 12, 2003, 16:29   #35
Zopperoni
Age of Nations TeamApolyCon 06 Participants
Emperor
 
Zopperoni's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Dec 2000
Posts: 5,045
O, and as for seriousness:

Symantec rates it a level-4 virus, which is high.
__________________
Blog: www.kennethlim.net // Twitter: @kennethlim
Zopperoni is offline  
Old August 12, 2003, 16:43   #36
Zopperoni
Age of Nations TeamApolyCon 06 Participants
Emperor
 
Zopperoni's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Dec 2000
Posts: 5,045
Here's the security bulletin addressing the issue:

http://www.microsoft.com/technet/tre...n/MS03-026.asp

On the page are also links to the patches.

Cinch, I hope you can get the patches through this page.
__________________
Blog: www.kennethlim.net // Twitter: @kennethlim
Zopperoni is offline  
Old August 12, 2003, 16:47   #37
DanS
Apolytoners Hall of FameApolyCon 06 Participants
Deity
 
DanS's Avatar
 
Local Time: 03:14
Local Date: November 2, 2010
Join Date: Dec 1969
Location: Not your daddy's Benjamins
Posts: 10,737
My mom caught this. She called me last night complaining that her laptop kept rebooting.

Here's a pretty simple fix (although it's a process, not an application)...

http://www.washingtonpost.com/wp-dyn...2003Aug12.html
__________________
I came upon a barroom full of bad Salon pictures in which men with hats on the backs of their heads were wolfing food from a counter. It was the institution of the "free lunch" I had struck. You paid for a drink and got as much as you wanted to eat. For something less than a rupee a day a man can feed himself sumptuously in San Francisco, even though he be a bankrupt. Remember this if ever you are stranded in these parts. ~ Rudyard Kipling, 1891
DanS is offline  
Old August 12, 2003, 17:04   #38
ixnay
Civilization II Democracy GamePtWDG Lux InvictaPtWDG Gathering StormInterSite Democracy Game: Apolyton TeamPtWDG2 Cake or Death?C3C IDG: Apolyton TeamApolytoners Hall of FameCivilization IV CreatorsAge of Nations Team
Emperor
 
ixnay's Avatar
 
Local Time: 01:14
Local Date: November 2, 2010
Join Date: Dec 1998
Posts: 3,215
I patched as soon as I heard about this last week. Some nasty-sounding stuff.
ixnay is offline  
Old August 12, 2003, 17:11   #39
Asher
Apolytoners Hall of Fame
President of the OT
 
Asher's Avatar
 
Local Time: 01:14
Local Date: November 2, 2010
Join Date: Nov 1999
Location: Calgary, Alberta
Posts: 40,843
The end-user security bulletin is here: http://www.microsoft.com/security/se...s/ms03-026.asp

The other one from MS TechNet is aimed towards sysadmins and computer geeks. Though the end-user one just says use Windows Update basically with a very dumbed-down description of why it's important.
__________________
"I'll never doubt you again when it comes to hockey, [Prince] Asher." - Guynemer
Asher is offline  
Old August 12, 2003, 17:20   #40
mrmitchell
Civilization III Democracy GamePtWDG RoleplayCall to Power Democracy GameInterSite Democracy Game: Apolyton TeamNationStatesPtWDG2 Tabemono
King
 
mrmitchell's Avatar
 
Local Time: 01:14
Local Date: November 2, 2010
Join Date: Sep 2002
Posts: 2,394
Used windowsupdate.com on another person's machine, and it is at least for me very slow for the moment. At least it means one thing--people are downloading patches, in droves. (Or the computer I'm using for it is a piece of ****. Either way... )
__________________
meet the new boss, same as the old boss
mrmitchell is offline  
Old August 12, 2003, 17:30   #41
Panag
MacCivilization II Democracy Game: ExodusC4BtSDG Rabbits of Caerbannog
Emperor
 
Panag's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Oct 2000
Location: MY WORDS ARE BACKED WITH BIO-CHEMICAL WEAPONS
Posts: 8,117
Finjan Software Proactively Protects Against Lovson Worm
August 12, 2003


Infection Level: Very High
Payload Threat Level: Medium
-----------------------------

OVERVIEW
"Lovsan" is the first DCOM RPC worm. Lovsan, which can spread via a direct network attack, downloads an executable and launches it automatically. It may cause a restart of Windows every time Windows starts up. If you are experiencing this problem, start Windows in 'Safe Mode' and delete the Msblast.exe from Windows System folder. Remote Procedure Call (RPC) is a protocol used by the Windows operating system. DCOM is Windows Distributed Component Object Model. DCOM RPC provides an inter-process communication mechanism that allows a program running on one computer to seamlessly execute code on a remote system. DCOM RPC uses port 135 which may be an open port. Finjan Software products do not monitor port 135. You can block this worm by closing port 135 in your firewall until you deploy the Windows 2000 / XP patch. The patch can be found at: http://www.microsoft.com/technet/tre...n/MS03-026.asp
Finjan SurfinShield Corporate and SurfinGuard Pro can be configured to provide proactive protection from Lovsan and similar RPC worms. After upgrading the configuration file, no further actions are necessary to be protected including updating your virus signature database. The Window Of Vulnerability will not exist in your organization.
Finjan Software customers are already protected from this worm.

TECHNICAL OVERVIEW
Aliases: W32.Blaster.Worm, Win32.Poza, WORM_MSBLAST.A
"The name of the downloaded executable is msblast.exe. It is packed with UPX and will self extract. The size of the binary is about 11kBytes unpacked, and 6kBytes packed.
The worm may launch a SYN flood against windowsupdate.com on the 16th. It has the ability to infect Windows NT, 2000, XP and potentially Windows Server 2003.

CERT has issued a detailed advisory that can be found at:
http://www.cert.org/advisories/CA-2003-20.html

TEST YOUR SECURITY
General Security Demos can be found at Finjan's Malicious Code Research Center: http://www.finjan.com/mcrc/sec_test.cfm .


PROTECTION
1. Update your anti-virus software often.
2. Install security patches issued by your software vendors.
3. Deploy proactive content security solutions to defend against both new and yet unknown attacks. (See below for details)


FINJAN PROACTIVE SOLUTIONS
Finjan is the only company that proactively protects you from new viruses, worms, Trojans and other attacks. Anti-virus solutions protect you only after you or someone else has been hit. It's like getting a flu shot after you've been infected. Finjan's proactive solutions provide enterprises with complete protection from both known and unknown attacks with the best performance and management capabilities. Even if you have deployed firewalls, intrusion detection, and updated anti-virus software, you are still not protected from the new generation of attacks coming via e-mail and from the web. Don't trust your mission-critical data and system security to luck.
Prevention is the best cure!
Finjan Software products are available at: http://www.finjan.com/store.cfm .




************************************************** *


Finjan Software
http://www.finjan.com
Panag is offline  
Old August 12, 2003, 17:58   #42
Hueij
Emperor
 
Hueij's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: May 1999
Location: Kokonino Kounty
Posts: 4,263
Quote:
Originally posted by Asher
or go to windowsupdate.microsoft.com (needs to use IE)
Needs to use IE to update Windows? What kind of bullshit is that?
__________________
Within weeks they'll be re-opening the shipyards
And notifying the next of kin
Once again...
Hueij is offline  
Old August 12, 2003, 18:01   #43
Panag
MacCivilization II Democracy Game: ExodusC4BtSDG Rabbits of Caerbannog
Emperor
 
Panag's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Oct 2000
Location: MY WORDS ARE BACKED WITH BIO-CHEMICAL WEAPONS
Posts: 8,117
Quote:
Originally posted by Hueij

Needs to use IE to update Windows? What kind of bullshit is that?
hi ,

just follow the link above , ......

have a nice day
Panag is offline  
Old August 12, 2003, 18:04   #44
Hueij
Emperor
 
Hueij's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: May 1999
Location: Kokonino Kounty
Posts: 4,263
The Finjan thing? But why can't I get the MS updates straight from their site? Are they afraid of my browser?
__________________
Within weeks they'll be re-opening the shipyards
And notifying the next of kin
Once again...
Hueij is offline  
Old August 12, 2003, 18:20   #45
Panag
MacCivilization II Democracy Game: ExodusC4BtSDG Rabbits of Caerbannog
Emperor
 
Panag's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Oct 2000
Location: MY WORDS ARE BACKED WITH BIO-CHEMICAL WEAPONS
Posts: 8,117
Quote:
Originally posted by Hueij
The Finjan thing? But why can't I get the MS updates straight from their site? Are they afraid of my browser?

hi ,

panag points out the link from above , .....

>>>> http://www.microsoft.com/technet/tr...in/MS03-026.asp


have a nice day
Panag is offline  
Old August 12, 2003, 18:28   #46
Hueij
Emperor
 
Hueij's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: May 1999
Location: Kokonino Kounty
Posts: 4,263
Quote:
Originally posted by panag
hi ,

panag points out the link from above , .....

>>>> http://www.microsoft.com/technet/tr...in/MS03-026.asp


have a nice day
Well, this is what I get from your link. So my question still stands...
Attached Thumbnails:
Click image for larger version

Name:	ms.gif
Views:	102
Size:	21.8 KB
ID:	51368  
__________________
Within weeks they'll be re-opening the shipyards
And notifying the next of kin
Once again...
Hueij is offline  
Old August 12, 2003, 19:01   #47
Zopperoni
Age of Nations TeamApolyCon 06 Participants
Emperor
 
Zopperoni's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Dec 2000
Posts: 5,045
Odd, the link still works for me.

Edit: I see the error now. Panag just copied the text of the link, instead of the link itself.

Click here, H, and you can read the page: http://www.microsoft.com/technet/tre...n/MS03-026.asp
__________________
Blog: www.kennethlim.net // Twitter: @kennethlim
Zopperoni is offline  
Old August 12, 2003, 19:22   #48
Whaleboy
NationStatesAlpha Centauri Democracy GameACDG The Cybernetic ConsciousnessMac
Prince
 
Whaleboy's Avatar
 
Local Time: 07:14
Local Date: November 2, 2010
Join Date: Jan 2003
Location: Please make all cheques payable to Whaleboy
Posts: 853
I think the virus does something like a DDoS attack on the fixing thing, this error might be it, I dont know.
__________________
"I work in IT so I'd be buggered without a computer" - Words of wisdom from Provost Harrison
"You can be wrong AND jewish" - Wiglaf :love:
Whaleboy is offline  
Old August 12, 2003, 19:32   #49
Zopperoni
Age of Nations TeamApolyCon 06 Participants
Emperor
 
Zopperoni's Avatar
 
Local Time: 09:14
Local Date: November 2, 2010
Join Date: Dec 2000
Posts: 5,045
No, click on the link that Panag gave Hueij and then look at the address bar of your browser.

And about the worm being a DoS, yes, that is true, it blocks the update site, which is why Cinch wasn't able to patch earlier.
__________________
Blog: www.kennethlim.net // Twitter: @kennethlim
Zopperoni is offline  
Old August 12, 2003, 19:35   #50
cinch
Warlord
 
Local Time: 00:14
Local Date: November 2, 2010
Join Date: Jul 2002
Location: Edmonton, Alberta, Canada
Posts: 131
Well, I seem to have it contained.

Just running fixblast.exe was not enough. I had to kill the trojan first (ctl alt del and all that), and then that bought me some time to download the updates & patches.

I had to disable system restore, too. That was very important. It was keeping the thing alive.

After all that, I just disconnected the internet, ran fixblast again, and deleted the files it found. Then, I reconnected and rebooted, and it seems to have half-disappeared. I still get weird 'cannot open such and such a file' notices when I start up windows, but msblast.exe itself (the thing that makes my computer automatically reboot) does not seem to have survived.

I think it's still dwelling in here somewhere, and it could return, but at least I have it under control now.

Thanks to everyone who posted info and such in this thread!
__________________
"I wrote a song about dental floss but did anyone's teeth get cleaner?" -Frank Zappa
"A thing moderately good is not so good as it ought to be. Moderation in temper is always a virtue, but moderation in principle is always a vice."- Thomas Paine
"I'll let you be in my dream if I can be in yours." -Bob Dylan
cinch is offline  
Old August 12, 2003, 19:38   #51
TCO
Apolytoners Hall of Fame
Emperor
 
TCO's Avatar
 
Local Time: 21:14
Local Date: November 1, 2010
Join Date: Mar 2006
Location: Richmond, VA
Posts: 8,057
Heeeeeelp mee!!!!!
TCO is offline  
Old August 12, 2003, 19:41   #52
TCO
Apolytoners Hall of Fame
Emperor
 
TCO's Avatar
 
Local Time: 21:14
Local Date: November 1, 2010
Join Date: Mar 2006
Location: Richmond, VA
Posts: 8,057
1. Ashie. I am on the sysadmin page. Do I have 32bit or 64bit XP. I have XP home. The Washington Post process sends me to that same page.

2. The Washington Post thing is good. But it lies. The msblast is a process not an application. You have to go to applications to kill it.

3. I'm scared to do the Firewall part so I'm blowing that off.

4. I tried (before Washington Post) going to windows update but that doesn 't work. If anything it triggers the shutdown.
TCO is offline  
Old August 12, 2003, 19:43   #53
TCO
Apolytoners Hall of Fame
Emperor
 
TCO's Avatar
 
Local Time: 21:14
Local Date: November 1, 2010
Join Date: Mar 2006
Location: Richmond, VA
Posts: 8,057
Ok...to simplify is windows XP home a 32 bit or 64 bit XP?
TCO is offline  
Old August 12, 2003, 19:45   #54
mrmitchell
Civilization III Democracy GamePtWDG RoleplayCall to Power Democracy GameInterSite Democracy Game: Apolyton TeamNationStatesPtWDG2 Tabemono
King
 
mrmitchell's Avatar
 
Local Time: 01:14
Local Date: November 2, 2010
Join Date: Sep 2002
Posts: 2,394
You've probably got 32bit. Unless you're running on some server or something. I'm sure Ash knows the obscure dialogue that tells you exactly your version, build, shoe size, and whatnot.

IIRC the trojan kills the Windows Update program that automatically downloads these things for you. Try going to the technet page or something.
__________________
meet the new boss, same as the old boss
mrmitchell is offline  
Old August 12, 2003, 20:07   #55
TCO
Apolytoners Hall of Fame
Emperor
 
TCO's Avatar
 
Local Time: 21:14
Local Date: November 1, 2010
Join Date: Mar 2006
Location: Richmond, VA
Posts: 8,057
crap I am still infected. Frigging windows.
TCO is offline  
Old August 12, 2003, 20:21   #56
TCO
Apolytoners Hall of Fame
Emperor
 
TCO's Avatar
 
Local Time: 21:14
Local Date: November 1, 2010
Join Date: Mar 2006
Location: Richmond, VA
Posts: 8,057
I'm dying in here.
TCO is offline  
Old August 12, 2003, 20:23   #57
Q Classic
Emperor
 
Q Classic's Avatar
 
Local Time: 02:14
Local Date: November 2, 2010
Join Date: Apr 1999
Location: The cities of Orly and Nowai
Posts: 4,228
windows xp home and professional, including the volume license versions, are the 32-bit versions of windows.

the 64bit version is used only in datacenters and for niche applications, and isn't sold preinstalled or at any computer store...

go to the symantec website to clean it off.
http://securityresponse.symantec.com...r/FixBlast.exe

then download the patch from microsoft
__________________
B♭3
Q Classic is offline  
Old August 12, 2003, 20:31   #58
TCO
Apolytoners Hall of Fame
Emperor
 
TCO's Avatar
 
Local Time: 21:14
Local Date: November 1, 2010
Join Date: Mar 2006
Location: Richmond, VA
Posts: 8,057
crap, the symantec thing shut down. And what is the Windows patch? Which specific thing are you reffering to? I've been directed to download a Xp32 bit file. But also to run Windows update.
TCO is offline  
Old August 12, 2003, 20:33   #59
TCO
Apolytoners Hall of Fame
Emperor
 
TCO's Avatar
 
Local Time: 21:14
Local Date: November 1, 2010
Join Date: Mar 2006
Location: Richmond, VA
Posts: 8,057
No joy. The symantec thing shuts down in the damn middle.
TCO is offline  
Old August 12, 2003, 20:36   #60
Q Classic
Emperor
 
Q Classic's Avatar
 
Local Time: 02:14
Local Date: November 2, 2010
Join Date: Apr 1999
Location: The cities of Orly and Nowai
Posts: 4,228
the symantec thing shut down as it stopped working?

hmm... ok.

download the symantec file to your root c: folder.
then, download this patch from microsoft.
then, right click on the "My Computer" icon, whether it's on your desktop or in your start menu, and choose "properties". go to the system restore tab, and click the check box that says "turn off system restore for all drives".

reboot the computer, and right before the windows xp boot screen comes up, mash f8 repeatedly, and select "safe mode", and then run the program again.

allow it to clean everything out, and then reboot the computer and go back into the full windows; run the patch.

turn system restore on again.
__________________
B♭3
Q Classic is offline  
 

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -4. The time now is 03:14.


Design by Vjacheslav Trushkin, color scheme by ColorizeIt!.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Apolyton Civilization Site | Copyright © The Apolyton Team