Notices
928 Forum 1978-1995
Sponsored by:
Sponsored by: 928 Specialists

New Virus "WIN32.KLEZ

Thread Tools
 
Search this Thread
 
Old Aug 13, 2003 | 12:02 AM
  #1  
V-Fib's Avatar
V-Fib
Thread Starter
We had a choice?
Rennlist Member
20 Year Member
 
Joined: Feb 2002
Posts: 18,952
Likes: 459
From: Texas
Default New Virus "WIN32.KLEZ

Trouble started last night as I was logging on to RennList.
Call me stupid, but I had never installed anti virus software. Tonight my son was watching Tech TV and guess what virus they were alerting everyone to. It doesn't really affect the computer until you are connected to the internet, after a few minutes or just a couple in my case, you get a warning that you have lost contact and your system (computer) will shut down in 60 seconds (timer displayed) then it shuts off completely. He said the warning they showed was just like the one we were getting along with the other symptoms. Went to Wal-Mart, bought Norton, installed it and found the 5 infected files with the "WIN32.KLEZ" virus. Don't know how it is spread, but it is out there. Thought I would let you know.




Anthony Tate
79/928 Silver Metallic
(Virus Free)
Reply
Old Aug 13, 2003 | 12:14 AM
  #2  
Big Dave's Avatar
Big Dave
928 Engine Re-Re-Rebuild Specialist
Rennlist Member
20 Year Member
 
Joined: Oct 2001
Posts: 7,972
Likes: 34
From: Brighton, MI
Default

It's actually called WORM_MSBLAST. You may still need to do some work to exorcise this demon. I suspect the WIN32.KLEZ was another virus on your system.

Go to www.trendmicro.com to get the free fix. The virus is listed on their front page.

By the way....don't feel too bad. I have anti-virus software installed and it got right through and nailed my laptop last evening, plus one of my firm's satellite offices also got hit. The virus slips in through holes in Microsoft (through an open port) which require a service update patch to close. The patch is free at Microsoft's website.

You don't have to download anything to get it. The virus causes infected computers to constantly scan the internet for random IP addresses, looking for computers that still have the open port (i.e., those that haven't updated with the Microsoft patch).
Reply
Old Aug 13, 2003 | 12:26 AM
  #3  
Shane's Avatar
Shane
Sharkaholic
Lifetime Rennlist
Member
20 Year Member
 
Joined: May 2002
Posts: 5,162
Likes: 2
From: Rochester, WA
Default

Thanks Dave! I got hit with that too.
Reply
Old Aug 13, 2003 | 12:51 AM
  #4  
John Struthers's Avatar
John Struthers
User
 
Joined: Jul 2001
Posts: 3,291
Likes: 2
From: Midland, Texas
Default

I suppose I shouldn't complain...
Although I have XP loaded, I haven't "installed it" if you know what I mean. Especially since the last attack -was told it was a weakness in XP- I have 98 with the 2000 upgrade running. Unfortunately, the restore feature is imbedded and somewhat inaccessable. All of the patches are foiled because of the scrambled registry files, and associated dll's.
Then again, Texas Department of Transportation was hit but our Automation people spent most of the day sorting things out.
The Maryland State Police were shut down at least thru early morning.
I'm pissed because I saved virtually every picture of 928's, modifications sites, pictoral repairs, and Ebay sales. All gone!!!
Goes to disc from now on as a back-up.
Reply
Old Aug 13, 2003 | 01:53 AM
  #5  
V-Fib's Avatar
V-Fib
Thread Starter
We had a choice?
Rennlist Member
20 Year Member
 
Joined: Feb 2002
Posts: 18,952
Likes: 459
From: Texas
Default

Thanks Dave, I downloaded the Windows XP Security Patch too. Set up two firewalls and can't believe I got WORMED!



Anthony Tate
79/928 Silver Metallic
Reply
Old Aug 13, 2003 | 02:03 AM
  #6  
Bernie's Avatar
Bernie
Burning Brakes
 
Joined: May 2002
Posts: 1,208
Likes: 4
From: Las Vegas, Nevada
Default

Yep,
Got me too!

W32.Blaster.Worm

I downloaded the fix from Symantic but for some reason it fails to complete?
I run Nortan and had bypassed the auto-protect feature.

Also tried the fix in Safe mode - still nogo?

Any ideas?
Reply
Old Aug 13, 2003 | 02:11 AM
  #7  
Jack '84 928s's Avatar
Jack '84 928s
Drifting
 
Joined: Apr 2002
Posts: 2,162
Likes: 0
From: Hobbs, NM (or lovington)
Default

We got it at work yesterday. God it sucked. I spent like 4 hours playing with the computers untill microsh_t released a patch. My win2k machince corrupted from it so i installed redhat 9. The new redhat rules it found out IMB laser printer connected to a win98 machine with a usb port lol.
Reply
Old Aug 13, 2003 | 02:17 AM
  #8  
Jack '84 928s's Avatar
Jack '84 928s
Drifting
 
Joined: Apr 2002
Posts: 2,162
Likes: 0
From: Hobbs, NM (or lovington)
Default

Its a denial of service attack. It attacks microsofts computers. It has a message in it that tells bill gates to stop making money and fix his software. lol or something like that
Reply
Old Aug 13, 2003 | 03:40 PM
  #9  
bergstsm's Avatar
bergstsm
Racer
 
Joined: Nov 2001
Posts: 263
Likes: 0
From: Denver, Colorado
Default

Actually, Microsoft released the patch and the security notice on July 16, 2003 in response to a tip they received from some Polish software geeks. in addition the Department of Homeland Security advised that admins around the globe patch the machines before this vunerability was exploited. Unfortunately, business admins didn't listen and home users generally do not patch their machines frequently enough.

Want proof? Go to Windows Update and see how many Service packs, patches and critical updates you don't have . Bet its more than 20 in most instances.

For those of you with broadband connections, even if you fix this worm and patch the machine, you may still have issues with any functions that require certain services called RPC's. Things like cut and paste may not work from time to time. The cure for this is to set up a firewall (hardware or software) that filters what comes in from outside your local machine. In fact, that is a GREAT idea anyway, not just to fix this problem.

Most of this kind of stuff is preventable.
PPPPPPP(Proper Prior Preparation Prevents P*ss Poor Performance)
Reply
Old Aug 13, 2003 | 05:18 PM
  #10  
Big Dave's Avatar
Big Dave
928 Engine Re-Re-Rebuild Specialist
Rennlist Member
20 Year Member
 
Joined: Oct 2001
Posts: 7,972
Likes: 34
From: Brighton, MI
Default

Shawn:

Good idea about the firewall. You can set mine up next time you're over my place!
Reply




All times are GMT -3. The time now is 12:10 PM.