EverCrest Message Forums
You are not logged in. Login or Register.
Author
Topic: Important : Please read.
Khyron
Hello, my mushy friend...
posted 08-11-2003 02:47:56 PM
[tech support mode]

okay gang, beeg problems here.

In July, a security group uncovered a serious problem with Windows NT and derivatives (Windows NT, Win2k, WinXP, and Win2k3). They notified MS of it immediately.

On July 16, 2003, MS produced a critical update to fix the problem, that being that people can use the security hole to do ANYTHING with a computer they want.

Today, everyone's being bombarded with said flaw.

If you, or a friends, or anyone's computer is being shut down by NT AUTHORITY/WINDOWS or (System or anyone) and it talks about RPC and DCOM, then you're affected by it. Download that July 16, 2003 patch from windowsupdate.com.

[/tech support mode]

Khyron
Hello, my mushy friend...
posted 08-11-2003 02:53:12 PM
Drys, can we get this stickied? It's a huge problem right now.
Mortious
Gluttonous Overlard
posted 08-11-2003 02:53:41 PM
I manually turned off all RPC functions through the services control panel.
Reynar
Oldest Member
Best Lap
posted 08-11-2003 02:58:00 PM
I would hope that anyone with win2k+ uses the auto windows update feature.

Not a single person here has the problem, but we all have policies set.

"Give me control of a nation's money, and I care not who makes its laws."
-Mayer Rothschild
Khyron
Hello, my mushy friend...
posted 08-11-2003 03:06:12 PM
quote:
Reynar's unholy Backstreet Boys obsession manifested in:
I would hope that anyone with win2k+ uses the auto windows update feature.

Not a single person here has the problem, but we all have policies set.


Willias' brother seems to be affected by it. I bet other EC'ers are, however, seeing as how the system shuts off very soon after connecting, it'd be difficult for them to post here about it. I'm posting here hoping they call a friend or that they get on from another computer

Skaw
posted 08-11-2003 03:09:38 PM
See?

SEE why I use 98?

Nina
posted 08-11-2003 03:15:05 PM
I love perimeter blocking. I love perimeter blocking. Aaaaah.
`Doc
Cold in an Alley
posted 08-11-2003 03:17:18 PM
No problems here at work. We'll see what happens when I get home.

And if they can't stay on long enough to post about it, how will they stay on long enough to download the security update?

Base eight is just like base ten, really... if you're missing two fingers. - Tom Lehrer
There are people in this world who do not love their fellow human beings, and I hate people like that! - Tom Lehrer
I want to be a race car passenger; just a guy who bugs the driver. "Say man, can I turn on the radio? You should slow down. Why do we gotta keep going in circles? Can I put my feet out the window? Man, you really like Tide..." - Mitch Hedberg
Please keep your arms, legs, heads, tails, tentacles, pseudopods, wings, and/or other limb-like structures inside the ride at all times.
Please submit all questions, inquests, and/or inquiries, in triplicate, to the Department of Redundancy Department, Division for the Management of Division Management Divisions.

Khyron
Hello, my mushy friend...
posted 08-11-2003 03:21:57 PM
quote:
This one time, at Ford Prefect camp:
No problems here at work. We'll see what happens when I get home.

And if they can't stay on long enough to post about it, how will they stay on long enough to download the security update?


In most cases, they can't, which is making this bug really, really, really nasty.

Willias
Pancake
posted 08-11-2003 03:27:35 PM
HOORAY FOR ZONEALARM! It blocked stuff from port 135 until I could update windows, now what the hell is MSblast.exe , and theres another file that goes by MSBLAST.EXE-1C3A3376.pf, neither of these popped up on my computer until after I got hit. (Apparently, theres a bunch of guys, or someone who has one hell of a good program to hack whacking people who are connected to my internet service.) So, should I delete this msblast.exe or not? It's trying to use port 135 which I'm pretty sure, is the one I got hit from...
sigeA ihpleD
.raewrednu ruoy tuoba gnihtynA .gnihtyna em ksA .elcaro ehT .thgir s'tahT .ihpleD
posted 08-11-2003 03:30:39 PM
Yay for a hugeass hardware firewall!

Edit: Thanks for making me look at windows update, though, Khy. I had over 30 updates to get.

[ 08-11-2003: Message edited by: sigeA ihpleD ]

.tniop doog ylriaf a edam ihpleD :hteD
.tniop yreve no tcerroc %001 si ihpleD :suiraD
Khyron
Hello, my mushy friend...
posted 08-11-2003 03:30:42 PM
What I'm betting is a combination of security exploit and virus. The security exploit downloads that file and reboots the PC, and from that point on, the customer is infected and tries to spam other IP's with the exploit.

But this is just speculation, as I don't have any proof on it.

Willias
Pancake
posted 08-11-2003 03:31:37 PM
Sooo, should i delete this msblast shit or not?
Suddar
posted 08-11-2003 03:32:56 PM
Not touching me. Seriously, if you don't let automatic Windows Update do its thing, that's kinda asking for trouble, you'd think.
OtakuPenguin
Peels like a tangerine, but is juicy like an orange.
posted 08-11-2003 03:33:47 PM
Patching now, thanks for the heads up
..:: This Is The Sound Of Settling ::..
Suddar
posted 08-11-2003 03:35:04 PM
Besides, my firewall is so anal it doesn't even let me do anything I want with my computer. D;
Willias
Pancake
posted 08-11-2003 03:40:06 PM
Grrrr, I can't delete the msblast.exe file, though i deleted one related to it.
It's in the system32 folder and I can't delete anything there.

Edit: Nevermind, endprocess and delete worked.

[ 08-11-2003: Message edited by: Willias ]

sigeA ihpleD
.raewrednu ruoy tuoba gnihtynA .gnihtyna em ksA .elcaro ehT .thgir s'tahT .ihpleD
posted 08-11-2003 03:40:56 PM
Safe mode boot?
.tniop doog ylriaf a edam ihpleD :hteD
.tniop yreve no tcerroc %001 si ihpleD :suiraD
Willias
Pancake
posted 08-11-2003 03:44:32 PM
Okie dokie. My brother updated windows and all of that stuff, and he went down again. Zone Alarm is protecting my compy right now, but now what...
Lyinar Ka`Bael
Are you looking at my pine tree again?
posted 08-11-2003 03:47:12 PM
Yeah, I was getting that on this laptop a day or two back and I dled the updates from MS. Stopped getting it, thankfully. But it wasn't shutting my system off too soon after startup that I couldn't finish dling.


Lyinar Ka`Bael, Piney Fresh Druidess - Luclin

Willias
Pancake
posted 08-11-2003 03:54:48 PM
Well, I'm going to try and turn off ZoneAlarm now that I've patched, wish me luck.
Majox
Pancake
posted 08-11-2003 04:02:01 PM
Now thats just freaky. I work tech support. I clicked on this thread, then I got a call, so I didn't read the thread. After I finish the call I read the thread and realize that the problem the user was having is exactly the problem described here. My father was also experiencing random reboots yesterday. Is there a site that details this problem, I want to pass it on to my supervisor. I guess they can't complain about me reading Evercrest while at work now.
I just make ideas, I don't make them good. - Me
Khyron
Hello, my mushy friend...
posted 08-11-2003 04:03:01 PM
Ja'Deth Issar Ka'bael
I posted in a title changing thread.
posted 08-11-2003 04:17:45 PM
okay now I can't even get to the windows update page from the main windows site, plus even if I manually enter an alternate page to scan for updates, it doesn't actually get around to scanning.

Essentially I'm screwed, right?

Lyinar's sweetie and don't you forget it!*
"All those moments will be lost in time, like tears in rain. Time to die. -Roy Batty
*Also Lyinar's attack panda

sigpic courtesy of This Guy, original modified by me

Khyron
Hello, my mushy friend...
posted 08-11-2003 04:23:21 PM
quote:
Ja'Deth Issar Ka'bael's fortune cookie read:
okay now I can't even get to the windows update page from the main windows site, plus even if I manually enter an alternate page to scan for updates, it doesn't actually get around to scanning.

Essentially I'm screwed, right?


Go to that support.microsoft.com website I posted just above and follow the directions for Win2k.

Ja'Deth Issar Ka'bael
I posted in a title changing thread.
posted 08-11-2003 04:26:02 PM
I did. It says I need support pack 2 or above to function. When we installed windows on this machine, we updated to SP4.
Lyinar's sweetie and don't you forget it!*
"All those moments will be lost in time, like tears in rain. Time to die. -Roy Batty
*Also Lyinar's attack panda

sigpic courtesy of This Guy, original modified by me

Khyron
Hello, my mushy friend...
posted 08-11-2003 04:27:13 PM
Razor
posted 08-11-2003 04:33:02 PM
This hit me last week.

Hit me twice today. finally unpluged my NIC from network and disabled it.

Astronomy is a passion...
Engineering is a love...
My job isn't a job, it's my career, and I love every minute of it: Observatory Superintendent
Majox
Pancake
posted 08-11-2003 04:34:10 PM
quote:
Ja'Deth Issar Ka'bael stopped beating up furries long enough to write:
I did. It says I need support pack 2 or above to function. When we installed windows on this machine, we updated to SP4.


Unless I read that wrong, wouldn't SP4 be included in SP2 and above?

I just make ideas, I don't make them good. - Me
Lyinar Ka`Bael
Are you looking at my pine tree again?
posted 08-11-2003 04:35:45 PM
When I updated SP4 on the machine, it said it had everything that I would need for SP1 to SP4.


Lyinar Ka`Bael, Piney Fresh Druidess - Luclin

Majox
Pancake
posted 08-11-2003 04:39:29 PM
It gives you that error when you try to run the Updater or the patch?
I just make ideas, I don't make them good. - Me
Lyinar Ka`Bael
Are you looking at my pine tree again?
posted 08-11-2003 04:41:11 PM
When he tries to run what Khy posted


Lyinar Ka`Bael, Piney Fresh Druidess - Luclin

Ja'Deth Issar Ka'bael
I posted in a title changing thread.
posted 08-11-2003 04:51:50 PM
And still no thoughts on what geeks my computer into hating svchost.exe and shutting it down every time I boot up.
Lyinar's sweetie and don't you forget it!*
"All those moments will be lost in time, like tears in rain. Time to die. -Roy Batty
*Also Lyinar's attack panda

sigpic courtesy of This Guy, original modified by me

Trent
Smurfberry Moneyshot
posted 08-11-2003 05:26:17 PM
I had to DL the security fix for Gen and put it on CD so she could install it, her computer was shutting down every minute.

It's okay now, and she is wisely getting the other updates.

Majox
Pancake
posted 08-11-2003 06:02:20 PM
quote:
Khyron thought this was the Ricky Martin Fan Club Forum and wrote:
no clue then =/
I just make ideas, I don't make them good. - Me
diadem
eet bugz
posted 08-11-2003 06:08:06 PM
thank you thank you thank you thank you

this deserves a sticky =)

play da best song in da world or me eet your soul
diadem
eet bugz
posted 08-11-2003 06:09:14 PM
*cowers as the shutdown counter is a few seconds quicker than the patch timer... mocking him*
play da best song in da world or me eet your soul
diadem
eet bugz
posted 08-11-2003 06:17:27 PM
will a netstat or something similar show the ip address of the person that's screwing with you?
play da best song in da world or me eet your soul
Willias
Pancake
posted 08-11-2003 06:25:34 PM
diadem, knowing what IP is hitting won't change anything, apparently there is a file going around that sends itself around by IP address that hits port 135. msblast.exe is what I think it is called. IF YOU HAVE GOTTEN HACKED BY THIS TODAY, LOOK FOR MSBLAST.EXE IN YOUR WINDOWS FOLDER. It uses your computer to further spread the hack and make your compy stop working.

I looked at my ZoneAlarm's log earlier, and msblast.exe kept trying to reach the internet repeatedly every 5 or so seconds, and other people that use Insightbb kept trying to access my compy through port 135.

Nasty, nasty little bugger.

Taeldian
Pancake
posted 08-11-2003 06:27:29 PM
Thanks, Khy. I just barely got hit with this once just about an hour ago.

Downloading everything now.

edit: I just searched for the file and don't see it anywhere, though...

[ 08-11-2003: Message edited by: Taeldian ]

All times are US/Eastern
Hop To: