.com.unity Forums
  The Official e-Store of Shrapnel Games

This Month's Specials

Raging Tiger- Save $9.00
winSPMBT: Main Battle Tank- Save $5.00

   







Go Back   .com.unity Forums > Shrapnel Community > Space Empires: IV & V

Reply
 
Thread Tools Display Modes
  #1  
Old August 12th, 2003, 05:49 PM

tesco samoa tesco samoa is offline
General
 
Join Date: Jul 2001
Location: Canada
Posts: 4,603
Thanks: 0
Thanked 0 Times in 0 Posts
tesco samoa is on a distinguished road
Default Re: OT - Ding Dong, the Wicked Worm is dead...

I suggest that you read the info on the virus and apply the patches and update your virus/os patches etc...

If your lucky that is all you will have to do.

But you must follow the instructions exactly.

Then you should look at automaticly updating your virus software daily and automaticly updating your windows software.

I know it is not very proactive. But at least you will be doing something.

Rebuild is a Last resort.

I am recommending you to follow this approach. This is the current approach I use at work.
__________________
RRRRRRRRRRAAAAAGGGGGGGGGHHHHH
old avatar = http://www.shrapnelgames.com/cgi-bin...1051567998.jpg

Hey GUTB where did you go...???

He is still driving his mighty armada at 3 miles per month along the interstellar highway bypass and will be arriving shortly
Reply With Quote
  #2  
Old August 12th, 2003, 07:08 PM
Suicide Junkie's Avatar
Suicide Junkie Suicide Junkie is offline
Shrapnel Fanatic
 
Join Date: Feb 2001
Location: Waterloo, Ontario, Canada
Posts: 11,451
Thanks: 1
Thanked 4 Times in 4 Posts
Suicide Junkie is on a distinguished road
Default Re: OT - Ding Dong, the Wicked Worm is dead...

Quote:
Originally posted by General Woundwort:
I'm probably going to be getting a new system anyways...

if only because the current system (the infected one) does NOT have a CD-RW - just a stinking 100MB zipdrive.

At least I can salvage the text and image files for SEIV, and my school work...
CD-RW drives are actually quite cheap these days. $40-$60 is all you should spend on one.

BTW, unless your computer is very old, its probably not worth getting a new one.
500Mhz is overkill for any everyday task, and meets the requirements for Starfury.

Microsoft dosen't need your money for a new tweak of windows.

Harddrives are dirt cheap ($1 per gigabyte) and easy to add. Memory and CD drives too.

[ August 12, 2003, 18:09: Message edited by: Suicide Junkie ]
Reply With Quote
  #3  
Old August 13th, 2003, 12:36 PM
General Woundwort's Avatar

General Woundwort General Woundwort is offline
Lieutenant Colonel
 
Join Date: Nov 2001
Location: Virginia
Posts: 1,311
Thanks: 0
Thanked 0 Times in 0 Posts
General Woundwort is on a distinguished road
Default Re: OT - Ding Dong, the Wicked Worm is dead...

Well, I think it's quite obvious by now what happened. I got the BLaster worm.

I've downloaded the patches and such onto a zipdisc at work, and I'm going to begin treating the patient this evening. WAL, I'll be back up and running by tonight.

Thanks to all who replied.

I may get a new computer anyways, but if I can lick this thing I'll probably settle for an external CD-RW (I desperately need some real backup power - this much has become obvious).
Reply With Quote
  #4  
Old August 14th, 2003, 01:12 AM
minipol's Avatar

minipol minipol is offline
Second Lieutenant
 
Join Date: Jul 2002
Location: Belgium
Posts: 558
Thanks: 0
Thanked 0 Times in 0 Posts
minipol is on a distinguished road
Default Re: OT - Ding Dong, the Wicked Worm is dead...

for this virus, you just need to install the microsoft patch, and preferably update your virus definitions. that's all case closed. no need to rebuilt the system.
you might want to install a firewall system as well for instance i use zonealarm. the basic Version is free.
next check once for spyware. 2 great free products: adaware and spybot.
next, relax and drink a beer
__________________
A Se++ GdY $++ Fr+ C++++ Csc Sf++ Ai** AuO M MpT MpSk MpFd S--- Ss- RV Pw Fq Nd- Rp- G Mm++ Bb++ Tcp+ L++
Reply With Quote
  #5  
Old August 14th, 2003, 01:45 AM
Thermodyne's Avatar

Thermodyne Thermodyne is offline
Lieutenant Colonel
 
Join Date: Dec 2000
Location: DC Burbs USA
Posts: 1,460
Thanks: 0
Thanked 1 Time in 1 Post
Thermodyne is on a distinguished road
Default Re: OT - Ding Dong, the Wicked Worm is dead...

Don't reload your system, the worm is easy to kill. First you kill it then you lock it out.

Here is how to kill it:



--------------------------------------------------------------------------------


If your system is continually rebooting (randomly powering off) please follow the steps outlined below

Please execute the following steps to start your system in safe mode:

Shut down your computer. Turn it back on again, and hold down the F8 key while your system starts.

When prompted, select Safe Mode and press enter (do not select Safe Mode With Networking)

If prompted, select the Operating System displayed (default Operating System should be highlighted).

Next, determine which operating system you are using. Since Microsoft has different patches to protect each operating system, you will need to know which one you have.

Click on the Start button, go up to Settings and select Control Panel. From there, double-click the System icon.

The window displayed will indicate which system is being used (Windows 2000, Windows XP, etc.)

Please execute the following steps to disable the worm from starting:

Click on the Start button and select Run

In the Run prompt, type regedit and press enter

Click on the plus sign (+) next to HKEY_LOCAL_MACHINE. Then, click on the plus sign next to Software. Click on the plus sign next to Microsoft. Again, click on the plus sign next to Windows. Click on the plus sign next to CurrentVersion. In the CurrentVersion list, click on the word Run.

Look for msbLast.exe, so that it is highlighted, and hit the delete key on your keyboard.

Select Yes to confirm deletion choice.

Exit the Registry editor (click the X in the upper right hand corner).

Restart your computer (but this time in "normal" mode - not Safe Mode).

Click this link and save the file to your desktop.

After the file has saved to your desktop, select Open on the Download Complete window. This will launch the Symantec W32.BLaster.Worm.Fix Tool

Click the Start button displayed on the Symantec W32.BLaster.Worm.Fix Tool. The tool will begin analyzing your files and folders for the worm and may take several minutes to complete.

When it has finished, you will be prompted with a window to install a patch that will protect your system from this and similar vulnerabilities. Click Yes to go to the Microsoft site directly.

Download the Microsoft patch

If not automatically redirected, please navigate to http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp"

Click on the link for your installed Operating System

Click download on the right side of the page

Choose Run from this location

Confirm security warning pop-up by clicking Yes

Follow pop-up instructions and reboot by clicking Finish

--------------------------------------------------------------------------------


If your system is not currently rebooting, however you believe you have the worm, please follow these steps:

First you need to determine which operating system you are using. Since Microsoft has different patches to protect each operating system, you will need to know which one you have.

Click on the Startbutton, go up to Settings and select Control Panel. From there, double-click the System icon.

The window displayed will indicate which system is being used (Windows 2000, Windows XP, etc.)

Next, you need to identify and terminate the worm running on your system. To do this,

Press and hold down the following keys: Control, Alt and Delete

Click the Task Manager button

Select the Processes tab

Click the Image Name column to sort the list in alphabetical order

Look for msbLast.exe under the Image Name column

Select the msbLast.exe file by clicking on itonce. Then, click the End Process button.

Now you can close the Windows Task Manager screen by clicking the X in the upper right hand corner.

Click this link and save the file to your desktop.

After the file has saved to your desktop, select Open on the Download Complete window. This will launch the Symantec W32.BLaster.Worm.Fix Tool

Click the Start button displayed on the Symantec W32.BLaster.Worm.Fix Tool. The tool will begin analyzing your files and folders for the worm and may take several minutes to complete.

When it has finished, you will be prompted with a window to install a patch that will protect your system from this and similar vulnerabilitys. Click Yes to go to the Microsoft site directly.

Download the Microsoft patch

If not automatically redirected, please Navigate to http://www.microsoft.com/technet/tre...n/MS03-026.asp

Click on the link for your installed Operating System

Click download on the right side of the page

Choose Run from this location

Confirm security warning pop-up by clicking Yes

Follow pop-up instructions and reboot by clicking Finish

Please note: Editing your system registry can cause problems with your Operating System if done incorrectly. While Comcast is providing this information to help repair the MSBLast Worm, Comcast is not responsible for any damage that the contents of this document may cause to your computer.
__________________





Think about it
Reply With Quote
  #6  
Old August 14th, 2003, 01:47 AM
Thermodyne's Avatar

Thermodyne Thermodyne is offline
Lieutenant Colonel
 
Join Date: Dec 2000
Location: DC Burbs USA
Posts: 1,460
Thanks: 0
Thanked 1 Time in 1 Post
Thermodyne is on a distinguished road
Default Re: OT - Ding Dong, the Wicked Worm is dead...

Hm..Symantec link didn't work. Here it is in plain text.

http://securityresponse.symantec.com...r/FixBLast.exe
__________________





Think about it
Reply With Quote
  #7  
Old August 13th, 2003, 06:17 PM
Richard's Avatar

Richard Richard is offline
Brigadier General
 
Join Date: Dec 1999
Location: Lancaster, OH 43130
Posts: 1,997
Thanks: 5
Thanked 9 Times in 8 Posts
Richard is on a distinguished road
Default Re: OT - Ding Dong, the Wicked Worm is dead...

Yes that will fix this known issue, but I always advise my clients to rebuild. Why? Because almost every worm has other payloads attached to it that people don't find out for quite a bit later. Plus there are usually other exploits that sneak in the exploited system that are also not picked up until later.

It's up to you, but in my experience once a box is infected it's best to start over to be sure.

Just my 2 cents worth, from doing security consulting for some time now.
__________________
Change is inevitable, how you handle change is controllable - J. Strong
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -4. The time now is 01:48 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright ©1999 - 2025, Shrapnel Games, Inc. - All Rights Reserved.