blaster worm virus
- Lyndon
- Site Admin
- Posts: 5416
- Joined: Mon Nov 12, 2001 1:00 am
- Location: Notts,England
microsoft have issued a patch for XP (yet again) to cure/fix the fault/bug that the virus uses -
http://www.microsoft.com/downloads/deta ... laylang=en
http://www.microsoft.com/downloads/deta ... laylang=en
-
stephen T
- Posts: 1828
- Joined: Wed May 22, 2002 1:00 am
some more nice info LOL.
Creates a hidden Cmd.exe remote shell that will listen on TCP port 4444, allowing an attacker to issue remote commands on the infected system.
Listens on UDP port 69. When the worm receives a request from a computer it was able to connect to using the DCOM RPC exploit, it will send that computer Msblast.exe and tell it to execute the worm.
If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on Windows Update. The worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.
Creates a hidden Cmd.exe remote shell that will listen on TCP port 4444, allowing an attacker to issue remote commands on the infected system.
Listens on UDP port 69. When the worm receives a request from a computer it was able to connect to using the DCOM RPC exploit, it will send that computer Msblast.exe and tell it to execute the worm.
If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on Windows Update. The worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.
- Lyndon
- Site Admin
- Posts: 5416
- Joined: Mon Nov 12, 2001 1:00 am
- Location: Notts,England
-
tiranova
- Posts: 1511
- Joined: Fri May 16, 2003 4:34 pm
- Location: Bristol, UK
And just what does all that mean in non IT language?some more nice info LOL.
Creates a hidden Cmd.exe remote shell that will listen on TCP port 4444, allowing an attacker to issue remote commands on the infected system.
Listens on UDP port 69. When the worm receives a request from a computer it was able to connect to using the DCOM RPC exploit, it will send that computer Msblast.exe and tell it to execute the worm.
If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on Windows Update. The worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.
Liz
[url=http://www.peugeot206cc.co.uk/newowners?id=468]Ex-Owner 468[/url]
Now driving Mercedes SLK280
[url=http://www.peugeot206cc.co.uk/newowners?id=468]Ex-Owner 468[/url]
Now driving Mercedes SLK280
-
stephen T
- Posts: 1828
- Joined: Wed May 22, 2002 1:00 am
also updatenorton ppl. even tho that cant get rid of it i have heard. mine didnt find it i know that much. bastards i had to do mine manually.thats why i posted the link so people can be patched b4 they get the virus or so much as a sniff of itif u have the virus it stops u downloading the fuking patch.
- Lyndon
- Site Admin
- Posts: 5416
- Joined: Mon Nov 12, 2001 1:00 am
- Location: Notts,England
or when the virus is active they can shut down your machine
from a mates website -
http://www.bl0g.co.uk/
message timed 18:28 is one your after
from a mates website -
http://www.bl0g.co.uk/
message timed 18:28 is one your after
- Lyndon
- Site Admin
- Posts: 5416
- Joined: Mon Nov 12, 2001 1:00 am
- Location: Notts,England
-
rob
- Posts: 2232
- Joined: Sat Dec 01, 2001 1:00 am
- Location: Belper, England
we have been aware of this one for a couple of weeks already.
Thats why I am working nights and trying to patch approx 480 servers.
Keep posting during the night - its gonna help me stay awake. Only getting 3 hours sleep a day at present Zzzzzzzzzzzzzzzzzzzzz
Thats why I am working nights and trying to patch approx 480 servers.
Keep posting during the night - its gonna help me stay awake. Only getting 3 hours sleep a day at present Zzzzzzzzzzzzzzzzzzzzz
Rob
Smart Brabus Roadster - exactly what it says on the badge
Smart Brabus Roadster - exactly what it says on the badge
-
nuttyslack
- Posts: 28
- Joined: Sun Dec 02, 2001 1:00 am
Stephen T,
if you have checked your machine then you havent got the worm,there is a removal tool on the link below.
http://securityresponse.symantec.com/av ... .tool.html
if you have checked your machine then you havent got the worm,there is a removal tool on the link below.
http://securityresponse.symantec.com/av ... .tool.html
