Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

RPC/Blast worm virus

Thread Tools
 
Search this Thread
 
Old 18th Aug 2003, 06:41
  #21 (permalink)  
 
Join Date: Jul 2000
Location: Earth (just)
Posts: 722
Likes: 0
Received 0 Likes on 0 Posts
ahh.... thanx guys - don't feel so lonely now!
Wing Commander Fowler is offline  
Old 18th Aug 2003, 22:46
  #22 (permalink)  
 
Join Date: Aug 2003
Location: UK
Posts: 35
Likes: 0
Received 0 Likes on 0 Posts
the answer.....

will windows users never learn?

buy a macintosh

no system freezes, no crashes, no viruses
type1 is offline  
Old 19th Aug 2003, 01:42
  #23 (permalink)  

Plastic PPRuNer
 
Join Date: Sep 2000
Location: Cape Town
Posts: 1,898
Received 0 Likes on 0 Posts
will windows users never learn?

switch to a proper O/S

no system freezes, no crashes, no viruses

[Registered Linux User #302442]
Mac the Knife is offline  
Old 19th Aug 2003, 01:52
  #24 (permalink)  
Ecce Homo! Loquitur...
 
Join Date: Jul 2000
Location: Peripatetic
Posts: 17,427
Received 1,594 Likes on 731 Posts
Geez! Haven't you guys ever heard of the fun of living dangerously?
ORAC is offline  
Old 19th Aug 2003, 22:41
  #25 (permalink)  
The Oracle
 
Join Date: Aug 2001
Location: Naples, Florida U.S.A.
Posts: 2,902
Likes: 0
Received 0 Likes on 0 Posts
It did not take long:

There is a new variant of the Worm that is destructive.

The new variant also copies the file TFTPD.EXE to the %System%\Wins folder as SVCHOST.EXE and then creates a service for it with the display name "Network Connections Sharing".

TFTPD.EXE or SVCHOST.EXE is a TFTP (Trivial File Transfer Protocol) server that is used by this worm to set the affected system as a download site for its copy. This worm is then able to propagate by instructing remote systems into downloading it using TFTP.


Looks like this one will be around for a long while,

Richard
Naples Air Center, Inc. is offline  
Old 27th Aug 2003, 02:36
  #26 (permalink)  
 
Join Date: May 2002
Location: West Sussex, UK
Posts: 220
Likes: 0
Received 0 Likes on 0 Posts
That might explain alot...
SVCHOST.EXE



I enclose an image of my task manager..seems to be more than one SVCHOST.EXE running,one of them pretty phat too?.I got rid of the blaster,using Sophos with all the upto date definitions...yet my computer continually crashes out,cannot use flight sim,paint shop pro, etc as they will not load up or crash when loading...EXCEPT..on my mums login..and thats pretty unstable too!

Is this a knackered hard drive or likley to be the worm?

Thanks,
ETOPS773
ETOPS773 is offline  
Old 27th Aug 2003, 03:31
  #27 (permalink)  
The Oracle
 
Join Date: Aug 2001
Location: Naples, Florida U.S.A.
Posts: 2,902
Likes: 0
Received 0 Likes on 0 Posts
ETOPS773,

I cannot access the page you linked so I cannot see your Task Manager. It is normal t have two svchost.exe's. You will see one for Local Service and the second for Network Service.

If you can link your picture again, I will give it another shot at opening it.

Which Operating System are you running and do you know the specs on your hardware? (It would help if you could list it.)

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 27th Aug 2003, 04:01
  #28 (permalink)  
 
Join Date: May 2002
Location: West Sussex, UK
Posts: 220
Likes: 0
Received 0 Likes on 0 Posts
hmm..try

http://uk.f1.pg.briefcase.yahoo.com/...?.dir=/Friends

then goto the only pic there..should work

K,using windows XP home (all updated etc) ,2.4 ghz P4,60GB HDD,512MB RAM, 512KPS ADSL connection.

What alarmed me is that I had 4 SVCHOST.EXEs running..2 listed as system,1 under network service,and 1 under local service.With only me logged on...

Cheers.
ETOPS773 is offline  
Old 27th Aug 2003, 05:07
  #29 (permalink)  
The Oracle
 
Join Date: Aug 2001
Location: Naples, Florida U.S.A.
Posts: 2,902
Likes: 0
Received 0 Likes on 0 Posts
ETOPS773,

Here are a couple of things you can check for:

Known variants create the following entries under the described registry key:

”windows auto update" = MSBLAST.EXE (variant A)

”windows auto update" = PENIS32.EXE (variant B)

”Microsoft Inet xp.." = TEEKIDS.EXE (variant C)

In C:\Windows\System32, known variants use the the following file names for their copy:

MSBLAST.EXE (variant A)
PENIS32.EXE (variant B)
TEEKIDS.EXE (variant C)

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 29th Aug 2003, 23:14
  #30 (permalink)  
 
Join Date: May 2000
Location: South East
Posts: 184
Likes: 0
Received 0 Likes on 0 Posts
Hi Naples, I was infected with the new variant (nachi), within about 60 secs of logging on the internet with a new computer (it has somewhat soured the experience ) anyway...

I've spent all day putting things right, downloaded patch, symantec fix etc. and all now seems to be in order. However the task manager still shows four SVCHOST running.

Local service 3,316k
Network service 1,928k

both of which I assume are ok, it also has

System 17,872k
System 3,004k

What I'd like to know is should I delete these via windows\system32\wins file, or are they best left alone?

Any help much appreciated.
Super Stall is offline  
Old 29th Aug 2003, 23:36
  #31 (permalink)  
The Oracle
 
Join Date: Aug 2001
Location: Naples, Florida U.S.A.
Posts: 2,902
Likes: 0
Received 0 Likes on 0 Posts
Super Stall,

If you removed the virus with the patches while running your affected Operating System, you are fine. (If you had pulled the hard drive out of the computer and used it as a slave on another computer, it would not have removed the virus properly.)

I am currently running 4 instances svchost.exe, two system, one local service, and one network service. The size of the memory usage will change. That is normal.

If you see any other problems with your computer, please report back. Otherwise, just monitor it.

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 30th Aug 2003, 00:01
  #32 (permalink)  
 
Join Date: May 2000
Location: South East
Posts: 184
Likes: 0
Received 0 Likes on 0 Posts
Crikey, that was quick, question to answer in 22 mins !!

Thanks for your help.

ss.
Super Stall is offline  
Old 30th Aug 2003, 01:22
  #33 (permalink)  

'nough said
 
Join Date: Sep 2002
Location: Raynes Park
Age: 58
Posts: 1,025
Likes: 0
Received 0 Likes on 0 Posts
The BBC reports that the FBI has identified one of the people who developed a variant of MSBlast.

You can't dig yourself a much bigger hole than he has for himself. me thinks.
amanoffewwords is offline  
Old 30th Aug 2003, 05:41
  #34 (permalink)  
 
Join Date: Jul 2003
Location: Scotland
Posts: 151
Likes: 0
Received 0 Likes on 0 Posts
This may be a little late for most but if you go here and download the Stinger it will check your machines for various viruses and trojans including the ones mentioned in this thread. I am still getting machines with blaster/lovsan and this tool has cleaned it off the systems.

However YMMV.

Last edited by Front_Seat_Dreamer; 30th Aug 2003 at 17:08.
Front_Seat_Dreamer is offline  
Old 30th Aug 2003, 07:22
  #35 (permalink)  
Dop
Registered User
 
Join Date: Oct 2002
Location: Croydon (but really from Barnsley)
Age: 64
Posts: 262
Likes: 0
Received 0 Likes on 0 Posts
amanoffewwords: Just read that BBC article, complete with mugshot of person involved.
Hey look! It's a big fat b'stard!!! Who'd have thought!!!
I bet he has no real friends, too...
Dop is offline  
Old 30th Aug 2003, 17:04
  #36 (permalink)  

'nough said
 
Join Date: Sep 2002
Location: Raynes Park
Age: 58
Posts: 1,025
Likes: 0
Received 0 Likes on 0 Posts
LOL dop!

Anyway, I was thinking it's about time they brought back medieval stoning practices for these guys, one stone for each person that was affected by the virus. Then we can bury the crums. That should put them off.

amofw
amanoffewwords is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.