blaster worm virus

Anything related to the 206CC
stephen T
Posts: 1828
Joined: Wed May 22, 2002 1:00 am

Post by stephen T »

well that was fun last nite lol.

get all your updates asap ppl.

User avatar
Lyndon
Site Admin
Posts: 5416
Joined: Mon Nov 12, 2001 1:00 am
Location: Notts,England

Post by Lyndon »

microsoft have issued a patch for XP (yet again) to cure/fix the fault/bug that the virus uses -

http://www.microsoft.com/downloads/deta ... laylang=en
Webmaster and Admin - http://www.peugeot206cc.co.uk

Image

stephen T
Posts: 1828
Joined: Wed May 22, 2002 1:00 am

Post by stephen T »

if u have the virus it stops u downloading the fuking patch.

its gunna all kick of on the 15th LOL. microsoft beware.

stephen T
Posts: 1828
Joined: Wed May 22, 2002 1:00 am

Post by stephen T »

some more nice info LOL.

Creates a hidden Cmd.exe remote shell that will listen on TCP port 4444, allowing an attacker to issue remote commands on the infected system.


Listens on UDP port 69. When the worm receives a request from a computer it was able to connect to using the DCOM RPC exploit, it will send that computer Msblast.exe and tell it to execute the worm.


If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on Windows Update. The worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.

User avatar
Lyndon
Site Admin
Posts: 5416
Joined: Mon Nov 12, 2001 1:00 am
Location: Notts,England

Post by Lyndon »

if u have the virus it stops u downloading the fuking patch.
thats why i posted the link so people can be patched b4 they get the virus or so much as a sniff of it :D
Webmaster and Admin - http://www.peugeot206cc.co.uk

Image

tiranova
Posts: 1511
Joined: Fri May 16, 2003 4:34 pm
Location: Bristol, UK

Post by tiranova »

some more nice info LOL.

Creates a hidden Cmd.exe remote shell that will listen on TCP port 4444, allowing an attacker to issue remote commands on the infected system.


Listens on UDP port 69. When the worm receives a request from a computer it was able to connect to using the DCOM RPC exploit, it will send that computer Msblast.exe and tell it to execute the worm.


If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on Windows Update. The worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.
And just what does all that mean in non IT language?
Liz


[url=http://www.peugeot206cc.co.uk/newowners?id=468]Ex-Owner 468[/url]

Now driving Mercedes SLK280

stephen T
Posts: 1828
Joined: Wed May 22, 2002 1:00 am

Post by stephen T »

its gunna stop u from being able to visit microsoft.com

stephen T
Posts: 1828
Joined: Wed May 22, 2002 1:00 am

Post by stephen T »

if u have the virus it stops u downloading the fuking patch.
thats why i posted the link so people can be patched b4 they get the virus or so much as a sniff of it :D
also updatenorton ppl. even tho that cant get rid of it i have heard. mine didnt find it i know that much. bastards i had to do mine manually.

User avatar
Lyndon
Site Admin
Posts: 5416
Joined: Mon Nov 12, 2001 1:00 am
Location: Notts,England

Post by Lyndon »

or when the virus is active they can shut down your machine :shock:

from a mates website -

http://www.bl0g.co.uk/

message timed 18:28 is one your after :D
Webmaster and Admin - http://www.peugeot206cc.co.uk

Image

User avatar
Lyndon
Site Admin
Posts: 5416
Joined: Mon Nov 12, 2001 1:00 am
Location: Notts,England

Post by Lyndon »

Webmaster and Admin - http://www.peugeot206cc.co.uk

Image

stephen T
Posts: 1828
Joined: Wed May 22, 2002 1:00 am

Post by stephen T »

yes norton has an update but didnt find shit on my machine.

rob
Posts: 2232
Joined: Sat Dec 01, 2001 1:00 am
Location: Belper, England

Post by rob »

we have been aware of this one for a couple of weeks already.

Thats why I am working nights and trying to patch approx 480 servers.

Keep posting during the night - its gonna help me stay awake. Only getting 3 hours sleep a day at present Zzzzzzzzzzzzzzzzzzzzz
Rob

Smart Brabus Roadster - exactly what it says on the badge

nuttyslack
Posts: 28
Joined: Sun Dec 02, 2001 1:00 am

Post by nuttyslack »

Stephen T,

if you have checked your machine then you havent got the worm,there is a removal tool on the link below.

http://securityresponse.symantec.com/av ... .tool.html

MattB
Site Admin
Posts: 1609
Joined: Fri Dec 27, 2002 8:07 pm
Location: Leeds

Post by MattB »

If you have a decent firewall then you shouldn't get this virus in the first place.

Now I'm not one to say I told you so.... :P

stephen T
Posts: 1828
Joined: Wed May 22, 2002 1:00 am

Post by stephen T »

i got norton firewall but i dont run it while i am sat at the comp.

i removed the virus manually so i dont need the tool thanks :)

but i defo had the worm as i seen it wriggling for myself LOL.