The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.
Turns out there's been a major security alert with NT based OS's and a virus has been spread to those who are vunrable. Luckily Zonealarm picked up 204 attempted "outgoing" connections from the application "msblast.exe" and told me to block the connection and download a patch from MS's site.
This is a warning to all XP user's - Check the "processes" list in task manager and see if ms blast is there.
****
"This worm spreads by exploiting a vulnerability in the RPC service for DCOM. This is described along with the fix for it in Microsoft Security Bulletin MS03-026. This affects the following systems; Windows NT 4, Windows 2000, Windows XP and Windows Server 2003. The worm also performs a Denial of Service (DoS) attack on the windowsupdate.com server.
The worm exploits vulnerability in DCOM RPC. It subsequently searches IP addresses and when it finds a vulnerable computer it uses the exploit to remotely run a shell which issues a command for downloading a copy of itself by TFTP. The copy of the worm is lunched directly after download.
When the worm is lunched it copies itself as a file named msblast.exe to the SYSTEM32 folder and registers msblast.exe as a windows auto update item in the following registry key
If your computer is infected by this virus, you will have to apply the Microsoft security patch available from this link:
microsoft.com/technet/security/bulletin/MS03-026.asp
Symptoms of the worms existence within a network (LAN):
- increased traffic on UDP port 69 (TFTP used by worm for downloading
- increased traffic on port 135 or 593 (worm sending data to try and exploit RPC for DCCOM)
- sudden system crashes reporting fault in RPC
Recommendation for network administrators is to disable outward access on ports 135 and 593 used by worm.
Virus also contains these texts:
I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ?
Stop making money and fix your software!!"
************
Heh. Clever - Yet scary.
I also dont know which version of windows xp I am running 32 bit edition or 64 bit edition so I cannot download the relevant patch to help me.
ARGHHHH I really need someones help on this!
Then do ctrl Alt Delete and check for msblast in processes. If it's not their then the problem is maybe something else.
Regarding the windows patch, if in doubt go for 32bit, you always have system restore if you screw up right ?
msblast wasnt on my processes list but I have zone alarm firewall running at "high" now and only a few programmes secured for the internet.
The virus infects your computer through a vunrability with windows - In other words it's able to download sneakily onto the comp without you knowing.
Note to do with downloading a file yourself :\
And Kyz - Check in the "programs" list in ZoneAlarm - See if msblast is there.
I blame the Irish. And the French. And you.
If you don't have a firewall it's seriously good to get one... Just one porn site and you get hacked hundreds of times.
If I look in windows/system32 there are a few files that have blue writing and are semi-transparent...