Just spent the last 30 mins racing some cracker script loser

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

There's no need to yell.
User avatar
Rye
To Mega Therion
Posts: 12493
Joined: 2003-03-08 07:48am
Location: Uighur, please!

Post by Rye »

phongn wrote:
Rye wrote:Where the fuck does it come from originally? It comes back if you delete it. It's located in windows/system32 iirc, and has an accompanying .pn file. there's also a weird file called "wowpost.exe" in system. It didn't say it was made by microsoft so i deleted that too.
It's a worm that automatically replicates itself.

WOWPOST is an ASPI driver. If you experience things like CD burning or ripping applications failing, figure out a way to get it back in.
Nuts! I'll ask people on msn if they have it :|[/dumbass]
EBC|Fucking Metal|Artist|Androgynous Sexfiend|Gozer Kvltist|
Listen to my music! http://www.soundclick.com/nihilanth
"America is, now, the most powerful and economically prosperous nation in the country." - Master of Ossus
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

You also need to match publisher and version numbers, you can't just mix and match them.
User avatar
lukexcom
Padawan Learner
Posts: 365
Joined: 2003-01-04 03:49am
Location: Ah, Northern Virginia. The lone island of stability in an ocean of recession.
Contact:

Post by lukexcom »

phongn wrote:There's no need to yell.
Hehe, just thought it would add character to my post, maybe make it a bit more dramatic, eh? :)
-Luke
User avatar
Alan Bolte
Sith Devotee
Posts: 2611
Joined: 2002-07-05 12:17am
Location: Columbus, OH

Post by Alan Bolte »

Yeah, I just had to deal with that. Fuckers. Did you guys see the newspost on Penny Arcade? Funny shit.
Any job worth doing with a laser is worth doing with many, many lasers. -Khrima
There's just no arguing with some people once they've made their minds up about something, and I accept that. That's why I kill them. -Othar
Avatar credit
User avatar
lukexcom
Padawan Learner
Posts: 365
Joined: 2003-01-04 03:49am
Location: Ah, Northern Virginia. The lone island of stability in an ocean of recession.
Contact:

Post by lukexcom »

Lol! Good shit they posted. :lol:

Well, the stuff I posted about earlier up in this thread worked for me, so my comp had a total downtime of maybe 15 minutes. I wonder if Something Awfull will feature a column related to this worm/virus thing.
-Luke
User avatar
lukexcom
Padawan Learner
Posts: 365
Joined: 2003-01-04 03:49am
Location: Ah, Northern Virginia. The lone island of stability in an ocean of recession.
Contact:

Post by lukexcom »

Removal instructions of the W32.Blaster.Worm :
http://securityresponse.symantec.com/av ... assessment

Do what they say and you'll be fine.
-Luke
Axis Kast
Vympel's Bitch
Posts: 3893
Joined: 2003-03-02 10:45am
Location: Pretoria, South Africa
Contact:

Post by Axis Kast »

I have Zone Alarm up and running. That should keep me covered, no?
User avatar
MKSheppard
Ruthless Genocidal Warmonger
Ruthless Genocidal Warmonger
Posts: 29842
Joined: 2002-07-06 06:34pm

Post by MKSheppard »

http://securityresponse.symantec.com/av ... .worm.html

W32.Blaster.Worm is a worm that will exploit the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. It will attempt to download and run the file Msblast.exe.

You should block access to TCP port 4444 at the firewall level, and block the following ports, if they do not use the applicaitons listed:

TCP Port 135, "DCOM RPC"
UDP Port 69, "TFTP"

The worm also attempts to perform a Denial of Service on windowsupdate.com. This is an attempt to disable your ability to patch you computer against the DCOM RPC vulnerability.
"If scientists and inventors who develop disease cures and useful technologies don't get lifetime royalties, I'd like to know what fucking rationale you have for some guy getting lifetime royalties for writing an episode of Full House." - Mike Wong

"The present air situation in the Pacific is entirely the result of fighting a fifth rate air power." - U.S. Navy Memo - 24 July 1944
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Axis Kast wrote:I have Zone Alarm up and running. That should keep me covered, no?
:roll:
READ THE DAMN THREAD!

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

lukexcom wrote:HERE is the SOURCE to ALL of our problems:
http://www.msnbc.com/news/951168.asp?0dm=B12PT
At least they used proper terminology. My local NBC station called it a "virus" :roll:

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Axis Kast wrote:I have Zone Alarm up and running. That should keep me covered, no?
Axis, read the entire thread. You must have your machine patched and your firewall properly configured in order to block this attack.
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

MKSheppard wrote:The worm also attempts to perform a Denial of Service on windowsupdate.com. This is an attempt to disable your ability to patch you computer against the DCOM RPC vulnerability.
The first DDOS attack will not occur until the 16th, but it would be good to fix your box first.
Axis Kast
Vympel's Bitch
Posts: 3893
Joined: 2003-03-02 10:45am
Location: Pretoria, South Africa
Contact:

Post by Axis Kast »

Can anybody tell me how to use Zone Alarm to do what needs to be done?
User avatar
Keevan_Colton
Emperor's Hand
Posts: 10355
Joined: 2002-12-30 08:57pm
Location: In the Land of Logic and Reason, two doors down from Lilliput and across the road from Atlantis...
Contact:

Post by Keevan_Colton »

I got hit by this the other day....my little brother fucked up the firewall while I was away and I came home to a slowly dying computer.....

Fortunately its all better now.....
:D
"Prodesse Non Nocere."
"It's all about popularity really, if your invisible friend that tells you to invade places is called Napoleon, you're a loony, if he's called Jesus then you're the president."
"I'd drive more people insane, but I'd have to double back and pick them up first..."
"All it takes for bullshit to thrive is for rational men to do nothing." - Kevin Farrell, B.A. Journalism.
BOTM - EBC - Horseman - G&C - Vampire
User avatar
Vendetta
Emperor's Hand
Posts: 10895
Joined: 2002-07-07 04:57pm
Location: Sheffield, UK

Post by Vendetta »

BE aware that running the removal tool does not guarantee that you won't see this again.

For best practise removal:

1. Disconnect from internet - you won't get RPC errors when not connected.
2. Go to My Computer -> MAnage - Services - RPC - Recovery and set all three fields at the top to 'take no action'. This stops the reboots.
3. Turn off System Restore (if using XP)
4. Download and install security patch 823980
5. Run the removal tool.
6. Reverse steps 2 & 3.

Earlier today the infection rate was so high that a vulnerable system could be infected within 30 seconds of connecting to the internet
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

You shouldn't need to install System Restore, IIRC. It recognizes new patches as legitimate.
User avatar
Vendetta
Emperor's Hand
Posts: 10895
Joined: 2002-07-07 04:57pm
Location: Sheffield, UK

Post by Vendetta »

You disable it because if the computer has made a system checkpoint (or other restore point) whilst infected, it will considerately back up the virus for you as well.

Returning to that restore point will re-infect.

Disabling System Restore in Windows XP will delete all the restore points it's created, circumventing this problem.

Turning system restore off is good practise when dealing with any virus infection.

(All you need to do is go to System Properties -> System Restore, and click Turn off system restore for all drives)
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Umm guys, I have Kerio running, and I automatically set it to block 135, 137, 138, and 139.

I forgot to apply the patch.

Result: Nothing. It couldn't hit me. And my ping to my favorite Quake servers isn't sky-high either. Thanks Kerio. :D
Image Image
Axis Kast
Vympel's Bitch
Posts: 3893
Joined: 2003-03-02 10:45am
Location: Pretoria, South Africa
Contact:

Post by Axis Kast »

Where do I get the patch? And how do I configure Zone Alarm to defend my computer?
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Alas, not many people here use ZoneAlarm, but Windows Networking should be blocked if you don't use it (I'm assuming you're at home and on a standalone computer).

The patch is available from Windows Update.
User avatar
Vendetta
Emperor's Hand
Posts: 10895
Joined: 2002-07-07 04:57pm
Location: Sheffield, UK

Post by Vendetta »

The patch is from Microsoft.

You can't configure port blocking on bog standard Zonealarm, you can only use the default configuration for what type of packet is allowed to communicate to what port. (which basically only incudes HTTP to port 80, and mail/news protocols to the respective ports)

This is overridden if the packet is part of an active communication session with a program that's secured as a server program on your system.
Axis Kast
Vympel's Bitch
Posts: 3893
Joined: 2003-03-02 10:45am
Location: Pretoria, South Africa
Contact:

Post by Axis Kast »

I got a bunch of critical updates last night. I should be all right then?
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Axis Kast wrote:I got a bunch of critical updates last night. I should be all right then?
Until the next bug comes out into the open, supposedly.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
Axis Kast
Vympel's Bitch
Posts: 3893
Joined: 2003-03-02 10:45am
Location: Pretoria, South Africa
Contact:

Post by Axis Kast »

What's the risk of infection by BLAST?
Post Reply