BlameThePixel!

BTForum » BlameTheOffTopic Forums » BlameTheGeneralOffTopic » Blaster Virus

Poll: Do you have an Anti-Virus Program.
Yes 4 users
No 2 users
Atichooooo! 3 users
Abstain 0 votes
(0 votes have been cast so far)Can't Vote While Logged Out!

Page: [1] [] [3]
[]The Pope
Decisive
Send PM
An Avatar
Posts: 5183
Threads: 123
Mood: Refreshed
Money: £201.52 (D)
(+ Friend)
Not online within the last half an hour
ok. maybe a small donation of 0.0.25?

________________
Learn to look, look to learn.
17.08.03 11:38
Post #31
[Hide Sig (14)] [Profile] [Quote]
[G]meiapaul
Statusless
Send PM
Posts:
Threads:
Money: £0.00 (D)
(+ Friend)
Not online within the last half an hour
donated. spend it wisely :P
17.08.03 11:48
Post #32
[Hide Sig (0)] [Profile] [Quote]
[]The Pope
Decisive
Send PM
An Avatar
Posts: 5183
Threads: 123
Mood: Refreshed
Money: £201.52 (D)
(+ Friend)
Not online within the last half an hour
:lol::lol::lol:

________________
Learn to look, look to learn.
17.08.03 11:50
Post #33
[Hide Sig (14)] [Profile] [Quote]
[G]jay
Statusless
Send PM
Posts:
Threads:
Money: £0.00 (D)
(+ Friend)
Not online within the last half an hour
how do you know if ye got that blaster virus hingy?
17.08.03 20:19
Post #34
[Hide Sig (0)] [Profile] [Quote]
[]routine_error
Statusless
Send PM
Posts: 1081
Threads: 25
Money: £6.36 (D)
(+ Friend)
Not online within the last half an hour
"How can I tell if the worm is affecting my computer?

Some customers whose computers have been infected may not notice the presence of the worm at all, while others who are not infected may experience problems because the worm is attempting to attack their computer. Typical symptoms may include Windows XP and Windows Server 2003 systems rebooting every few minutes without user input, or Windows NT 4.0 and Windows 2000 systems becoming unresponsive. Whether you are experiencing these symptoms or not, Microsoft recommends that you take the following action immediately:

If you're running Windows Server 2003 or Windows NT 4.0, follow Steps 1–3 for home users on this page.
If you're running Windows XP or Windows 2000, follow all Steps 1–4 for home users on this page.
"

  - http://www.microsoft.com/security/incident/blast_faq.asp
17.08.03 20:43
Post #35
[Hide Sig (1)] [Profile] [Quote]
[]The Pope
Decisive
Send PM
An Avatar
Posts: 5183
Threads: 123
Mood: Refreshed
Money: £201.52 (D)
(+ Friend)
Not online within the last half an hour
In terms for you to understand. The virus makes your computer restart every few minutes. This might not always happen if you have it though. Best to get latest AV updates and scan for it.

________________
Learn to look, look to learn.
18.08.03 07:06
Post #36
[Hide Sig (14)] [Profile] [Quote]
[G]jay
Statusless
Send PM
Posts:
Threads:
Money: £0.00 (D)
(+ Friend)
Not online within the last half an hour
i got the update scanned with the remover tool from symantec and..........

"the blaster virus was not found ount ure computer"

:mrgreen:

hurrah
18.08.03 13:12
Post #37
[Hide Sig (0)] [Profile] [Quote]
[]routine_error
Statusless
Send PM
Posts: 1081
Threads: 25
Money: £6.36 (D)
(+ Friend)
Not online within the last half an hour
this is confusing... that Remote Procedure Call (RPC) thing was remotely transmitted over the net to a vulnerable (open) port on one's computer, overflowing the RPC buffer, causing it to shut your computer down with a custom made packet. If this is the same as this 'Blaster Virus', then it is not a virus at all. I would have said so earlier, but found it odd that Microsoft would call it a virus as well. I suppose for the 60 seconds that your computer is staring you in the face like a showdown and who's going to turn her off first, it could be like a virus. However nothing that I'm aware would stay on the computer, causing it to crash again, the attacker would simply send another custom (duplicate, i'd imagine) packet through your open system, crashing it once again. I'm fairly sure this is the case, as once I put up a firewall (here and at my mother's place of business) the crashing came to a hault. I then instald patches and turned off the firewalls, everything was fine. If the patch was only to stop the exploit (that's what it is, an exploit, not a virus), then it would have no capabilities of removing a virus from your system, however, I have had no problems since with the affected computers. I still find it odd, though, that everyone seems to like to call it a virus. Well, maybe everyone is wrong.
18.08.03 18:42
Post #38
[Hide Sig (1)] [Profile] [Quote]
[S]Zogger!
Looking For Status
Send PM
Posts: 3954
Threads: 62
Money: £93.82 (D)
(+ Friend)
Not online within the last half an hour
I thought it was also set up to perform DDOS attacks on the microsoft website... who knows. There is also an Anti Virus Virus now. :)

________________
You know I'm a dancing machine
18.08.03 18:48
Post #39
[Hide Sig (8)] [Profile] [Quote]
[]routine_error
Statusless
Send PM
Posts: 1081
Threads: 25
Money: £6.36 (D)
(+ Friend)
Not online within the last half an hour
oh, I see. that should work, actually. odd.
18.08.03 18:50
Post #40
[Hide Sig (1)] [Profile] [Quote]
[B]C1
Looking For Status
Send PM
Posts: 0
Threads: 0
Money: £0.18 (D)
(+ Friend)
Not online within the last half an hour
ya here cause i read the news paper on my tv ill tell u all. Mind u i might get messed up cause i read about a lot of stuff. Anyways ya zogger is right it was supposed to attack microsoft but they used the redirectory link to get all the infected folks that were still infected at 1:01 saturday or some date like that. to all go to microsoft and crash it. But microsoft got smart and disconnected the redirectory link and ppl were still able to come to microsoft to download the update to stop this virus. Also another virus was like a good sumaritain and it makes u download the patch from microsoft. But errors still happen from it. Also some obig virus(i forgot the name) made a list of about 10000 emails and use those to send the viruses to others. And im on that list cause i got an email sayint the virus could not be sent to Billy Joe. and this was the virus update from C1. I would know more but my news paper updates everyday so i forgot some stuff.


Edit: and also the msblaster also said as a joke stupid bill gates why not make ur programs better and all this wouldnt happen
20.08.03 23:44
Post #41
[Hide Sig (2)] [Profile] [Quote]
[]routine_error
Statusless
Send PM
Posts: 1081
Threads: 25
Money: £6.36 (D)
(+ Friend)
Not online within the last half an hour

Quoted :: C1

Edit: and also the msblaster also said as a joke stupid bill gates why not make ur programs better and all this wouldnt happen


lol

well, i heard 'SOBIG' on TechTV, they said a bunch of crap about it, but it's all the same old shit, 'go to symantic for more information, we don't know a damn thing!'... or the same shit that you've already heard before someplace else.
21.08.03 00:57
Post #42
[Hide Sig (1)] [Profile] [Quote]
[]The Pope
Decisive
Send PM
An Avatar
Posts: 5183
Threads: 123
Mood: Refreshed
Money: £201.52 (D)
(+ Friend)
Not online within the last half an hour
I-Worm.Sobig.f, W32/Sobig.F-mm, W32/Sobig.f@MM, WORM_SOBIG.F W32/Sobig-F is a worm that spreads via email and network shares.

W32/Sobig-F copies itself to the Windows folder as winppr32.exe and sets one of the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
= \winppr32.exe /sinc

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
=
The worm sends itself, using its own SMTP engine, as an attachment to email addresses collected from various files on the victim's computer. When it distributes itself via email it forges the sender's email address, making it difficult to know who is truly infected.

The email has the following format:

Subject line: Chosen from -
Re: That movie
Re: Wicked screensaver
Re: Your application
Re: Approved
Re: Re: My details
Re: Details
Your details
Thank you!

Message text: Chosen from -
Please see the attached file for details.
See the attached file for details

Attached file: Chosen from -
movie0045.pif
wicked_scr.scr
application.pif
document_9446.pif
details.pif
your_details.pif
thank_you.pif
document_all.pif
your_document.pif

W32/Sobig-F also attempts to spread by copying itself to Windows network shares and uses the Network Time Protocol to one of several servers in order to determine the current date and time. If the date is September 10 2003 or later the worm stops working

________________
Learn to look, look to learn.
21.08.03 07:02
Post #43
[Hide Sig (14)] [Profile] [Quote]
[B]C1
Looking For Status
Send PM
Posts: 0
Threads: 0
Money: £0.18 (D)
(+ Friend)
Not online within the last half an hour
hmm my tv said it also took like 500 email addys and use those to send it. Or maybe i have a virus that doesnt do one damn thing on my computer.
21.08.03 18:13
Post #44
[Hide Sig (2)] [Profile] [Quote]
Page: [1] [] [3]

Post Reply

Jump To:


Your Comments:

Donate to BlameThePixel:
Donate to BTP Via PayPal


[22 Queries, Page Loaded in 0.290109 Seconds]

ShoutMeUp

Xmas Greetings from waka waka waka waka []Unvalidated EmailChristmasRiddle MERRY CHRISTMAS EVERYONE! []Spleet Except for Spleet. []TheAbdBoy Always bummin' a brother out. []Spleet Happy New Year everyone! But Spleet. []TheAbdBoy

Word Association

All

-10 Ago-

MiddleEastern []AlphaWolf camel [S]Bloopy toe []TheAbdBoy moose knuckle [S]Bloopy MeatLoaf []Spleet IdDoAnything4Lo ve []AlphaWolf rub n tug []TheAbdBoy tugboat []The Pope rope [S]Bloopy race []TheAbdBoy

-Latest-


Must be logged in to add new words

FictoLeague

You have to be logged in to vote...

Member Stats

Date: 15.05.24.
Members: 4731.
Latest: []Unvalidated Emailsdsakldsaldklasdsdsa
Active:
0 user(s)
1 guest(s)

On chat:
Lots of people

Files: 3330

Bloopy's Site
Get Firefox Get Opera Donate to BTP Via PayPal