I long ago opted for a hardware-based firewall/router (see: How to get rid of all these messages? and Dream System) because of its added protection from such things. No one on the internet side of my firewall even knows my computer exists - it is difficult to target what apparently isn't there. Software firewalls work but are sometimes less robust in certain situations. I also keep my O/S updated on an irregular but at least monthly basis and my A/V updates are totally automated; so, I've not had a problem.
~ GaySatyr
[Link]
DenverDon Benevolent
Firmly Embedded in Depravity 5914 Posts 7/02
Posted - Aug 13 2003 : 6:25PM
Yeah, I had it.
Spent some time purging it, and missed chat last night.
Also had to purge something that wrote things into the registry, not the worm.
People, if you have a broadband connection, USE A FIREWALL!!! (software-based Zone Alarm is free if you can't afford $65 for the US Robotics model!) And, keep your A/V and O/S software up to date!
I spent all day at work disinfecting this fuckin' Worm! Whoever created it should DIE! hehe
Yes you have to manually delete a few keys/values in the registry.
Heard the creators of this Blaster Worm wants to take down the Micosoft website by Saturday & continue to infect all systems running Windows XP, 2000, ME, & NT.
You are correct only in that Macs are seldom targeted (they are equally vulnerable); however, as the Apple O/S approaches true UNIX (which it is doing rapidly) Mac, too, shall fall. I recommend a firewall (preferably hardware-based) and regular A/V & O/S updates for everyone.
Yep, I got it on Monday and had a hard time figuring out what it was at first. It was rather hard with my computer constantly shutting down. I ended up having to use my room mate's computer that ended up becoming infected just as I finished getting the fix from Symantec. I got his computer cleaned up late late Monday night and I got my machine cleaned up late last night. Bloody pain that worm is.
Patience is a virtue, but who wants to be virtuous? 4283 Posts 4/00
Posted - Aug 13 2003 : 11:24PM
I don't have it on any of my computers, but I just visited my mom and her computer had gotten infected the day before. I spent awhile trying to get rid of it, with no luck, but I just called her and told her to look at the Norton and Mcafee websites.
The creator of the worm shouldnt die, he's a freakin genius. I didnt get the worm, but from reading all the reports its very interesting. I helped a few friends clean it up, and I thought the whole thing was great. I cant wait to see what happens Saturday.
I didn't realise this was quite so widespread. I'm safely firewalled in but I know of 5 people already at the fire station where I work who have succumbed to this. My ISP has warnings and alerts on their homepage which I've never known before (although admittedly I only visit their site infrequently).
We were out of town when this one started to spread. Thankfully we're firewalled and have the latest patches in place that fix the hole this worm exploits.
I've never been infected with a computer virus or worm - knock on wood (man, is this the right website for that superstition) - and, hopefully, I never will. However, as I've pointed out before in this thread and others, I take proper precautions so as not to get infected.
As a gay male, it would be near suicidal for me to have unprotected sex with a stranger; as a broadband interr, should I be any less protected?
The cost of a top-quality firewall/router/switch with the NAT feature (the USR8000A [wired] and the FM114P [802.11b wireless] are better than most and are inexpensive compared to most of their competition) is minor compared to the cost in time and money for the cure - especially as some of these nasties are getting lethal!
The whole point of a hardware firewall with NAT is that you can see the internet, but the internet cannot see you. Thus, a worm broadcast looking for likely destinations passes you by; because, as far as it knows, you are not even there. The use of a software-based firewall does not accomplish quite the same thing: with it, you ARE visible on the internet but you are seen "wearing armor," so to speak.
The combination of a good, self-updating anti-virus program (Norton, McAfee, etc), regular operating system updates (check once a month - it takes about 5 to 10 minutes, maximum - and with W2K and XP, it is semi-automated), and a hardware firewall will make your system nearly invincible.
Spent another long day removing this ultra-nasty worm from our servers & workstations! It also fucks up your Microsoft Office programs. It appears a full re-install of Office does the trick.
"Popups" are a whole different problem mostly associated with Internet Explorer and the way it runs java scripts. There are also applets called "spyware." These have nothing to do with viruses or worms. They are, however, invasive intrusions on your time and privacy. Some are just annoying while others gather information and report back to marketing groups as to your web-surfing habits.
There are two tools which do an excellent job of cleaning up the garbage sent you by the popup and spyware source companies and two more which effectively protect you from their reappearing:
I got the damn worm on my machine, took about two hours to figure out what was wrong and fix it. Kill the worm first, then patch (I tried the reverse). BTW I have heard that there is a messenger popup that mimics the worm's system shutdown message.
GaySatyr, does the NetGear FM114P have any other advatages over the US Robotics 8000A other then being wireless? Ive been meaning to setup my three boxes on a lan (been transfering files between them via archos jukebox (Im so ashamed ) and cdrws)
The netgear is 3x the cost of the robotics, where does that money go?
The only difference is the addition of the wireless function. The NetGear model is one of the best 802.11b wireless models on the market (its competitors for wireless capability are the near-similar Linksys and the USR 802.11b add-on unit for the US Robotics model). Unless you need wireless, go with the much less expensive USR8000A.
Last week was one of the worst weeks at the workplace! Fuckin viruses everywhere! Was able to contain & prevent further damage but we did get hit pretty good! Should of taken vacation last week! Let's see what the "Weekly Worm" will be tomorrow! Nuts!
At my job, we've had virutally no problems with SoBig, but we're still getting our ass kicked by MSBlaster. We learned a lot about patching this worm, including:
* The Symantec tool did not effectively detect Blaster until sometime late in the week before last. We had a lot of divisions that used FixBlast and then couldn't figure out why they were still spewing crap out on the network. We've had good success with the NAI/McAfee Stinger scanner.
* Some groups didn't understand that simply patching a machine and rebooting it doesn't kill the worm. You need to patch AND remove the worm.
* Others killed the worm but left the PC's connected to the network while patching and got reinfected in the time between disinfecting and patching.
* We have a number of WinXP machines with System Restore enabled, and if you don't disable this functionality, there's a good possiblity that Windows will "roll back" to a previous, worm-infected state.
* The biggest gotcha we've seen is that if you don't cold boot (i.e. shutdown, power-off, then power-on) after disinfecting, the worm still stays memory-resident.
In other words, we had IT professionals who were in such a hurry to fix this worm that they cut corners or didn't read the documentation that our security organization provided to them.
I have some kind of virus. I really don't know what it is. it is not the sobig virus, I used the fix tool for that one and it did not work it said "no virus found"? Let me tell you what is going on, in my outlook it shows that I am sending mass e-mails to yahoo people, then I get the pop up window that says the mail was rejected. This thing is sending out hundreds of e-mail's and the Symantec window keeps popping up for the "outgoing scan of message". What I did to so call fix it was went to my norton anti-virus and went to options and turned off "scan all outgoing e-mail messages". If anyone can help me with this I would greatly appreciate it. Thanks in advance.
I'm having all kind of weird problems with XP all the sudden on my home systems.
This is the most annoying one and I am wondering if I have some kind of virus or worm?
Programs are terminating suddenly without any warning or error message - usually shortly after they load. I cannot even run my firewall anymore because it terminates. My task bar also seems hosed, as several programs are no longer appearing on it. Worse, I cannot even install many programs now because the installation routines are terminating suddenly in the middle of the install process. The entire computer does not shut down, just some programs.
Does this sound like the worm? My antivirus software (Trendmicro) is not picking it up.
Thanks for your suggestion SyberScott. Since you did think it sounded like a virus, I investigated further and indeed Norton found some serious problems!
C:\magic .exe is infected with Backdoor.OptixPro.13 C:\WINDOWS\SYSTEM32\msiexec16 .exe is infected with Backdoor.OptixPro.13
What's worse, the msiexec16 .exe was actually loading and referenced to run automatically in the registry! I followed Symantec's instructions on how to remove it and the trojan seems to be gone now.
The system seems to be working better now, but I haven't tested everything. At least I was able to load my firewall again and so far, no programs have terminated early.
I'm very disappointed the Trendmicro anti-virus engine did not pick this up. I was using the AV engine they support in System Suite (which is similar to Norton Utilities). I tested it again right before removing the virus, and it doesn't flag this trojan at all. :-(
since i got internet, i had a firewall AND virus program, that i regually update. als o i update Windows quite often so i am pretty confident it hasent got through
------------------ Regards and Thanks ShiWarrior - - Minka Fan - -