VIRUS ALERT!!!! W32/BLASTER WORM - PLEASE READ

This is the main lobby for Vanessa-Mae related discussions.

Moderator: zeta

Arioch
**VMF Guru**
Posts: 1013
Joined: Sat Dec 14, 2002 3:08 pm
Location: Birmingham (UK)
Contact:

Post by Arioch »

WARNING!!!

there is a NEW VIRUS in town so please take precautions...

If you have not done so already Please do so NOW!

the W32/BLASTER WORM VIRUS searches the WEB until
it finds an O.S that is vunerable,
It infects by using a hole in the programming, This virus Can Not
be recognised by AV software, the viruses code is the same has Windows so that it ca not be found it will also alter the registry
to make any AV think that it is a part of windows.

Symptoms are...
SYSTEM WILL REBOOT EVERY 5 MINUTES when connected to
to the WEB.

When system is not connected it will reboot randamly

Here is a link for you to Download a Windows Patch to prevent the VIRUS

>>WINDOWS PATCH<<

ONLY USE the corresponding patch for your software!!

If you get infected by the VIRUS use this program AVAILABLE at..

>>Resolve W32/Blaster-A self-extractor<<

ONLY USE your OS version..

If infected make sure your system is not connected to the WEB, run resolve software (follow the Blastera.txt instructions) then run the Windows Patch!

Good Luck!
-----Arioch------
(Lord of Chaos)
------Image-----
www.vanessa-mae.co.uk
Xanthippe

Post by Xanthippe »

Thanks Arioch for the warning.

Norton has it already in its virus protection list.
Street_Rat
VMF Elite
Posts: 379
Joined: Tue Jul 16, 2002 11:05 am
Location: Adelaide

Post by Street_Rat »

Its times like this im glad linux isnt very popular. because it so different to windows, normal windows virus dont work under it. :)
for that matter, there arnt any virus that work under linux that i know of.
hope none of u get infected by this virus
Street_Rat
--> a simple man with a simple wish
Arioch
**VMF Guru**
Posts: 1013
Joined: Sat Dec 14, 2002 3:08 pm
Location: Birmingham (UK)
Contact:

Post by Arioch »

Both of my machines got hit,My Norton AV never stood a chance!

This Virus apparently uses a back door so that AV software
doesn't detect it if it does it's to late, before the AV software can scan it your System is shutting down.

My Advice is to install the Windows Patch to to be on the safe side.
Although it is fairly easy to get rid of just has long as you have
access to a 2nd computer or even a 3rd :user:
-----Arioch------
(Lord of Chaos)
------Image-----
www.vanessa-mae.co.uk
Street_Rat
VMF Elite
Posts: 379
Joined: Tue Jul 16, 2002 11:05 am
Location: Adelaide

Post by Street_Rat »

i posted this in one of the other threads, but it may be better here.

i heard roumour that there was another one goin around that effects MSN some how, i havent heard anything about it, so cant give any exact details or even say if it exists or not

anyone else heard of this? it may be the same virus, just the person i was talking to got confused as to what the virus was.
Street_Rat
--> a simple man with a simple wish
Arioch
**VMF Guru**
Posts: 1013
Joined: Sat Dec 14, 2002 3:08 pm
Location: Birmingham (UK)
Contact:

Post by Arioch »

The chap who wrote the virus has released the code on the net, so people are now writing their own variants.

The real damage will start today (Sat' 16) when the virus starts a denial of service attack on windowsupdate.com and at the same time tells the registry to access windows auto update on start-up

In the virus code their is a message saying "Billy gates why do you make this possible? stop making money and fix your software!"

The rebooting of the users system was a programming error
the user was not supposed to have been aware that there is
a virus on his/her system
-----Arioch------
(Lord of Chaos)
------Image-----
www.vanessa-mae.co.uk
Xanthippe

Post by Xanthippe »

Well it is in Nortons most recent virus list, so they should now recognize it. I have the windows patch too. I guess I should be safe.
losthk
Active Member
Posts: 60
Joined: Sat Oct 19, 2002 10:11 pm
Location: California, USA
Contact:

Post by losthk »

for me= hopeless, so i m gonna reformat. I can;t fidn the worm anywhere... i used norton.. useless... i guess i really have to reformat
§ÚªÎ¦º°Õ*sniff sniff*<=vic
User avatar
Glenn
VMF Elite
Posts: 365
Joined: Thu Jul 25, 2002 6:37 am
Contact:

Post by Glenn »

Eh.!! Don't do that,.. Just fix it.

See my detailed instructions (the link below) to see if it is running on your PC, how to detect - remove and patch.
http://vm.on-d.net/MSBlast_fix.htm
Select Ctrl-Alt-Del, Select "Task Manager". If you do not see the file msblast.exe running under the "Processes" tab, then you are OK. If you do, single click select/highlight it and click "End Process".
So if it is on your PC,.. print & follow the instruction on my above link. Regardless,.. you should patch your PC asap.
Glenn
losthk
Active Member
Posts: 60
Joined: Sat Oct 19, 2002 10:11 pm
Location: California, USA
Contact:

Post by losthk »

glenn... my comp is relai hopeless.. + my XP si relai F#$%^&*( cuz i tried the patch from miscrosoft... doesnt operate.... and liek i tried worm removal... useless.. said cant fidn it.. but my theat detector shwo sum trace of msbalster.exe.... i m seriously confuse wut to do...

edit-
my comp do shut off liek every 5-10 minutes.. sumtimes operate longer.. ono.. depend on luck.. sumtiems i cant c java if i typed in shutdown -a so tht the comp woudltn shut off
§ÚªÎ¦º°Õ*sniff sniff*<=vic
User avatar
haboek
VMF Elite
Posts: 292
Joined: Sun Jul 28, 2002 7:34 am
Location: Gouda Netherlands

Post by haboek »

Lucky for me I am still running W98 SE.
Not being effected.
So sometimes the oldiest are not to bad :D
Haboek :smokin:
changing worlds
Site Admin
Posts: 664
Joined: Fri Jul 12, 2002 12:39 pm
Contact:

Post by changing worlds »

I don't think that anyone will be able to write a virus that causes Windows 98 to shut down. Windows 98 never seems to shut down.

:cool:

FWIW, Sometimes reloading is good. I have to reload my Windows XP some day. I've had major sound issues for the past one to two years. I've recently reloaded on a temporary partition, and do not have the issues (I also do not have any security updates :O ). I think the only thing different is that I didn't install the updated chipset drivers.
Arioch
**VMF Guru**
Posts: 1013
Joined: Sat Dec 14, 2002 3:08 pm
Location: Birmingham (UK)
Contact:

Post by Arioch »

losthk,

The Bad news is if the resolve file cannot find the virus,
then it sounds like that you have picked up one of the
varients (a cloned version of the MS Blaster virus)

If you cannot find out which version of of the virus you
have then you will need to re-format your drive, or re-boot
your System into dos using your start-up disk and just
delete your windows files that way you do not lose your
valuable saved files.

You can even (in DOS)
If you have partitioned your drive copy your saved files to
the second drive then format the C: drive

All the best of luck to you.
-----Arioch------
(Lord of Chaos)
------Image-----
www.vanessa-mae.co.uk
User avatar
Glenn
VMF Elite
Posts: 365
Joined: Thu Jul 25, 2002 6:37 am
Contact:

Post by Glenn »

Arioch idea is a good one,
That is to delete your windows folder, Or at least rename it "ZZZ" so it won't accidently try to run. But even better then partitioning is to reload your OS on a new hard drive and keep the old drive (still with the Windows folder disabled) for back-up & storage.

Once the new drive is up and running. Create a folder and copy all your important files from the old drive into the new folder on the new drive. Reformate the old drive. And move what you'd like to it. Two separate drives is always a good and safe back-up arrangement. Also a good idea is once you get your OS all set and all your applications in place but befor you put much data on, is to take an image of this Drive/Partition and place it on your second drive,.. that way if it gets hosed again you can recover quite well. (your data and OS should/recommended be on different partitions or drives)
Glenn
losthk
Active Member
Posts: 60
Joined: Sat Oct 19, 2002 10:11 pm
Location: California, USA
Contact:

Post by losthk »

danz glenn and Arioch
§ÚªÎ¦º°Õ*sniff sniff*<=vic
Post Reply