Welcome to Welcome to DNF.com™ - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars

If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the largest domain name community on the internet and continues to grow every day. There are over 105,000 domainers on DNForum doing everything from buying domains, selling domains, learning about domains and discussing domains. Take a minute and Register.

Register Today on DNForum IT'S FREE!

Results 1 to 15 of 15
  1. #1
    Cool Member

    Join Date
    Apr 2002
    Posts
    1,869
    DNF$
    1,647
    Bank
    0
    Total DNF$
    1,647
    Donate  

    Exclamation New computer worm found !

    Hi,

    apparently since 2 days there is a new worm circulating which basically causes your computer to shut down a few minutes after you have connected to the internet by manipulating the RPC.

    More info on the worm here:

    http://securityresponse.symantec.com...ster.worm.html

    Removal tool that kills the sucker can be found here:

    http://www.sarc.com/avcenter/venc/da...oval.tool.html

    Note: Read the instructions for the tool *very* carefully, especially the part about temporarily switching off the System restore option, otherwise the tool wont work.

    After having removed the worm you should immediately install the Micrsosoft security patch to avoid especially that worm:

    http://www.microsoft.com/technet/tre...n/MS03-026.asp

    Make sure you download the correct version for your specific system/OS.

    I'm really not a friend of MS updates but in this case i downloaded it immediately as this worm caused to shut down my system every other 4 minutes since 2 days.

    After you have done everything as mentioned, check if this registry entry is still there (it shouldn't) :

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run "windows auto update" = msblast.exe

    If it's still there, just manually delete it.

    Btw, as you can see the sucker is called "msblast.exe" which hides in WINDOWS\system32; but i really recommend to only manually delete it in case the above instructions and the removal tool should for some reason not have worked.


    Now everything should be fine again
    Last edited by beatz; 08-12-2003 at 04:29 AM.

  2. #2
    Exclusive Lifetime Member
    Sharpy's Avatar
    Join Date
    Dec 2002
    Posts
    1,774
    DNF$
    1,135
    Bank
    0
    Total DNF$
    1,135
    Donate  
    Thanks
    nosig @ this time

  3. #3
    Platinum Lifetime Member
    Steen's Avatar
    Join Date
    Mar 2003
    Location
    White Rock, BC
    Posts
    4,895
    DNF$
    2,480
    Bank
    0
    Total DNF$
    2,480
    Donate  
    How od i get worms?

    Get an eNom resellers account free and instantly,
    click here - Automated Signup!

  4. #4
    DomainNameIndustry.com
    Prosperous's Avatar
    Join Date
    Feb 2003
    Location
    US of Euphoria
    Posts
    3,283
    DNF$
    1,962
    Bank
    0
    Total DNF$
    1,962
    Donate  

    .
    Great American City names? Get Yours CHEAP! [INSTANT download]

  5. #5
    DNF Addict
    GT Web's Avatar
    Join Date
    Feb 2003
    Location
    Vancouver, Cana
    Posts
    6,895
    DNF$
    10,037
    Bank
    0
    Total DNF$
    10,037
    Donate  
    :-D

    I thought about relating that post to chicken as well

  6. #6
    Platinum Lifetime Member
    .biz's Avatar
    Join Date
    Dec 2002
    Location
    U.S.
    Posts
    1,065
    DNF$
    10,968
    Bank
    0
    Total DNF$
    10,968
    Donate  
    Just got a phone call from a friend today about her computer shutting down every few minutes and I suspected that it's virus.

    Thanks for the info, just in time.

  7. #7
    Platinum Lifetime Member
    Keith's Avatar
    Join Date
    Apr 2003
    Location
    Houston, TX
    Posts
    766
    DNF$
    661
    Bank
    0
    Total DNF$
    661
    Donate  
    Keith J. Kacin
    Kacin LLC -Website Maintenance and Development

  8. #8
    Cool Member

    Join Date
    Apr 2002
    Posts
    1,869
    DNF$
    1,647
    Bank
    0
    Total DNF$
    1,647
    Donate  
    The patches alone won't kill the worm.
    You have to use the mentioned tool or at least delete the files manually in addition to the MS patch.

  9. #9
    Platinum Lifetime Member

    Join Date
    Jul 2002
    Posts
    95
    DNF$
    776
    Bank
    0
    Total DNF$
    776
    Donate  

    windows 98?

    I guess this patch is not needed for windows 98 right?

  10. #10
    Platinum Lifetime Member
    .com.net.org's Avatar
    Join Date
    Oct 2002
    Posts
    1,976
    DNF$
    1,823
    Bank
    0
    Total DNF$
    1,823
    Donate  
    easy steps.

    1. terminate running msblast.exe process.
    2. Go to Windows/system32 or winnt/system32 and find msblast.exe, delete it. Empty your recycle bin too.
    Unlimited Domain Hosting - $20/mo
    Dedicated Server - $99/mo

  11. #11
    DNF Addict

    Join Date
    Nov 2002
    Posts
    1,560
    DNF$
    3,057
    Bank
    0
    Total DNF$
    3,057
    Donate  
    Ouch! It got me. Back up and running after almost two days with my computer expert trying to work out what the problem was.

    In the easy steps above, don't forget that it is also necessary to apply the Microsoft patch, other wise, I assume, your computer can easily be infected again.

  12. #12
    Platinum Lifetime Member
    .com.net.org's Avatar
    Join Date
    Oct 2002
    Posts
    1,976
    DNF$
    1,823
    Bank
    0
    Total DNF$
    1,823
    Donate  
    better quick if you guys still need to access windowsupdate.microsoft.com.

    The worm will DDOS that site on 15 Aug.
    Unlimited Domain Hosting - $20/mo
    Dedicated Server - $99/mo

  13. #13
    Cool Member

    Join Date
    Apr 2002
    Posts
    1,869
    DNF$
    1,647
    Bank
    0
    Total DNF$
    1,647
    Donate  
    It's NOT enough to delete the msblast.exe
    You also have to delete the above mentioned registry entry as well as a third file that i believe ends in .pf or something like that.
    That's why the best to do is to use that removal tool plus the patch of course.

    And yes, a DOS attack on the update server is expected for the 15./16.

  14. #14
    Platinum Lifetime Member
    Steen's Avatar
    Join Date
    Mar 2003
    Location
    White Rock, BC
    Posts
    4,895
    DNF$
    2,480
    Bank
    0
    Total DNF$
    2,480
    Donate  
    Someone is going to hack Microsoft?


    What do i do?

    Why do people hack?

    This is dumb.

    I dont understand


    ******Consused********

    Get an eNom resellers account free and instantly,
    click here - Automated Signup!

  15. #15
    Platinum Lifetime Member
    .com.net.org's Avatar
    Join Date
    Oct 2002
    Posts
    1,976
    DNF$
    1,823
    Bank
    0
    Total DNF$
    1,823
    Donate  
    I just got a news that microsoft sites are infected. (don't confirm it)

    Therefore it's not wise to download patch from the server if the news is true.
    Unlimited Domain Hosting - $20/mo
    Dedicated Server - $99/mo

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Domain name forum recommended by Domaining.com