Re[2]: Virus Alert - W32.Blaster.Worm

From: badger (badger@pongo.org)
Date: Wed Aug 13 2003 - 10:16:38 GMT-3


Hello Charles,

Tuesday, August 12, 2003, 11:37:04 AM, you wrote:

CC> Not meaning to flame anyone, but why the hell are you only installing W2K
CC> SP3 now? It's been out a year. With all the security holes that MS
CC> products have, whether you're responsible for 1 machine or 1000, you really
CC> need to be checking for (and installing) critical updates once a week at a
CC> minimum. There's really no excuse. Us Cisco people shouldn't have to put
CC> up with this crap because the server and workstation people aren't keeping
CC> up on security holes. Sorry. Rant over.

CC> Chuck Church
CC> CCIE #8776, MCNE, MCSE
CC> Wam!Net Government Services
CC> 13665 Dulles Technology Dr. Ste 250
CC> Herndon, VA 20171
CC> Office: 703-480-2569
CC> Cell: 703-819-3495
CC> cchurch@wamnet.com
CC> PGP key: http://pgp.mit.edu:11371/pks/lookup?search=chuck+church&op=index

CC> -----Original Message-----
CC> From: nobody@groupstudy.com [mailto:nobody@groupstudy.com]On Behalf Of
CC> John Smith
CC> Sent: Tuesday, August 12, 2003 12:10 PM
CC> To: MADMAN; Snow, Tim
CC> Cc: 'ccielab@groupstudy.com'
CC> Subject: Re: Virus Alert - W32.Blaster.Worm

CC> I got hit with it as well. I was wondering what this msblaster.exe was doing
CC> in the taskmgr.... a google search brought me to realize it was a worm.

CC> I updated Win 2K Pro to service pack 3 added the MS fix, then went to
CC> symantec, got the latest virus sig file ( which started to tell me 30 times
CC> I had the worm... ) and used their exe to fix the problem. They got rid of
CC> the worm, the msblaster.exe, fixed the registry settings.

CC> Now all I need to do is get my taskmgr working again, cause I can't see my
CC> the buttons to change to view the utilization and can't shut it down without
CC> killing the taskmgr process (luckily the only screen available)

CC> MADMAN <dave@interprise.com> wrote:
CC> Yes I was fortunate enough to get paged yesterday evening regarding
CC> this. Here is some more info for those so inclined:

CC> Dave

CC> Snow, Tim wrote:
>> Anyone else going through the W32.Blaster.Worm?
>>
>>
CC> http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.htm
>> l
>>
>> Big pain in the ....
>>
>> Tim
>>
>>
>> Timothy Snow
>> CCIE #12042
>> EDS - Network Operations
>> MS 3B
>> 1075 W. Entrance Drive
>> Auburn Hills, MI 48326
>>
>> * phone: +01-248-754-7900
>> * mailto:timothy.snow@eds.com
>> pager: 888-351-4584
>> www.eds.com
>>
>>
>> _______________________________________________________________________
>> You are subscribed to the GroupStudy.com CCIE R&S Discussion Group.
>>
>> Subscription information may be found at:
>> http://www.groupstudy.com/list/CCIELab.html
>>

CC> --
CC> David Madland
CC> CCIE# 2016
CC> Sr. Network Engineer
CC> Qwest Communications
CC> 612-664-3367

CC> "Government can do something for the people only in proportion as it
CC> can do something to the people." -- Thomas Jefferson

CC> _______________________________________________________________________
CC> You are subscribed to the GroupStudy.com CCIE R&S Discussion Group.

CC> Subscription information may be found at:
CC> http://www.groupstudy.com/list/CCIELab.html

CC> ---------------------------------
CC> Do you Yahoo!?
CC> Yahoo! SiteBuilder - Free, easy-to-use web site design software

CC> _______________________________________________________________________
CC> You are subscribed to the GroupStudy.com CCIE R&S Discussion Group.

CC> Subscription information may be found at:
CC> http://www.groupstudy.com/list/CCIELab.html

CC> _______________________________________________________________________
CC> You are subscribed to the GroupStudy.com CCIE R&S Discussion Group.

CC> Subscription information may be found at:
CC> http://www.groupstudy.com/list/CCIELab.html

I ue a corporate pc and the IS department controls policy on the
machine - they're up to Win2K SP1 8-) . They're scrambling this
morning cuz they got bit.

-- 
Best regards,
 badger                            mailto:badger@pongo.org


This archive was generated by hypermail 2.1.4 : Tue Sep 02 2003 - 18:53:58 GMT-3