RE: [Full-Disclosure] what to do

From: gml (gml_at_phrick.net)
Date: 08/12/03

  • Next message: Arian J. Evans: "RE: [Full-Disclosure] what to do"
    To: "'Calvyn'" <Calvyn@stny.rr.com>, <full-disclosure@lists.netsys.com>
    Date: Tue, 12 Aug 2003 02:05:50 -0400
    
    

    I've been doing this:

    1. patch the machine
    2. remove registry entries containing "msblast.exe"
    3. reboot
    4. remove msblast.exe

    It's worked out so far. Yes I agree I wish people would listen when you
    tell them to patch. I have it on good authority that firewalls can't stop
    stupidity, I guess we're lucky this one wasn't also a mass mailing worm.

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Calvyn
    Sent: Tuesday, August 12, 2003 1:16 AM
    To: full-disclosure@lists.netsys.com
    Subject: RE: [Full-Disclosure] what to do

    I'm was just working with my 15 year old niece in NJ, through IM, to
    help her keep her WinXP PC from rebooting every minute. She had 2 copies
    of msblast.e x e on her PC. One was delete-able the other we had to
    reboot into safe mode to delete. After deleting the last e x e her unit
    is NOT rebooting. I have since had her update her unit and disable DCom.

    Amazing how kids never listen to you when you ask them to update their
    PCs..

    -Calvyn-

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of akbara
    Sent: Tuesday, August 12, 2003 1:52 AM
    To: Gabe Arnold; full-disclosure@lists.netsys.com
    Subject: Re: [Full-Disclosure] what to do

    has she tried booting into safe mode ?
    then removing the msblast or what not program ?

    -akbara

    ----- Original Message -----
    From: "Gabe Arnold" <f0x@squirrelsoup.net>
    To: <full-disclosure@lists.netsys.com>
    Sent: Monday, August 11, 2003 7:57 PM
    Subject: Re: [Full-Disclosure] what to do

    > Don't use windose sounds like a solution to me...
    > * Justin Shin (zorkshin@tampabay.rr.com) wrote:
    > > Hi All --
    > >
    > > My cousin recently got a nasty RPC/DCOM worm and she cannot use
    > > Windows
    update because when the RPC is shutdown, SYSTEM automatically initiates
    a shutdown of the computer as you are all aware of. What is the best
    solution to keep data files intact while removing this worm? I have
    tried going to the Registry Run, no entries ar ethere besides legitimate
    startup stuff. Any suggestions?
    > >
    > > -- Justin
    > >
    > > _______________________________________________
    > > Full-Disclosure - We believe in it.
    > > Charter: http://lists.netsys.com/full-disclosure-charter.html
    > >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Arian J. Evans: "RE: [Full-Disclosure] what to do"

    Relevant Pages

    • Re: sms 2003 patch management is brutal!
      ... SMS client computer to run this taks. ... >> You don't re-select it when running the Distribute Software Updates>> Wizard. ... SMS patch management is>>>> extremely ... >>>>> requires a reboot is installed without rebooting the patch isn't ...
      (microsoft.public.sms.admin)
    • Re: RPC security error is restarting my comp
      ... or reboot, quickly go to: ... > Is the original problem actually the worm which I have ... >>install the patch mentioned above. ... >>It is suggested that you first download the patch to your ...
      (microsoft.public.windowsxp.security_admin)
    • The patch killed my system!
      ... prompts for a reboot, I say "Yes"...boom! ... that reason more often than any other on a server. ... when a patch appears to cause a problem with your server its more likely ... Now I'm not saying this to discourage reports of problems with patches, ...
      (NT-Bugtraq)
    • Re: [Full-Disclosure] Windoze almost managed to 200x repeat 9/11
      ... > not to patch and to make the tech do a reboot every 30 days. ... > Does Microsoft have crappy coding in Windows 95? ... > Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: [Total OT] Trying to improve some numbers ...
      ... But patch frequency means what exactly? ... Thus making only, say, a driver or some kernel component reboot, ... Actually it means advertising an unpatched machine running unpatched services not available to the outside. ... a lot of work-arounds for security patches amount to "lock the front door." ...
      (freebsd-questions)