MLUG: Re: [MLUG - DISCUSSION] RPC DCOM Worm
Re: [MLUG - DISCUSSION] RPC DCOM Worm
Email address obfuscation in effect -- please click here to turn it off.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
NO,
People, no offense, but virus's, worms, etc. are no laughing matter.   
Yes, MS produces crap, but it's people who I count as criminals who  
create this stuff (virus's/trojans/worms/etc.), and generate a LOT of  
work for everyone else, cause damage, etc.  This is in no way shape or  
form appropriate, good, etc.  We may not like MS, but it's out there, a  
lot of people use it however bad it may be, and as such keep in mind  
that people also look at this list for info.  As such, try and look  
before immediately judging what is going on.  Not saying that people  
aren't, but I wanted to remind everyone of this.

Anyways, here's the info (from the LANMAN and other sources).

The virus/trojan in question affects Win NT, 2000, XP.  Pretty much all  
versions that have not installed the latest patches (July 16th, SP4 for  
2000, etc.).  This is a fairly major trojan that hits and affects  
things such as file sharing, print services, anything based on RPC  
(i.e. drag and drop copy/pasting in winblows).
For any network admin, check your machines, fix, patch them.
Information on WinShell50 worm:                 

             
http://securityresponse.symantec.com/avcenter/venc/data/ 
backdoor.winshell.50.html

Removal of  WinShell50 worm :

http://securityresponse.symantec.com/avcenter/venc/data/ 
backdoor.winshell.50.removal.tool.html  

Removal of MSBLASTER worm :

W32.Blaster:  
http://www.symantec.com/avcenter/venc/data/w32.blaster.worm.html
Remember to patch your systems with the Microsoft 026  patch after  
cleaning infected systems to prevent further  infections.
 
http://www.microsoft.com/technet/security/bulletin/MS03-026.asp
 
Regards,
Jason

/--------------------------------------|---------------------------\
| Jason McIntosh                       | CELL: 573-424-7612        |
| Webmaster, thinker, Programmer, etc. | WORK: 573-884-3865        |
| http://poetshome.com/                |                           |
|------------------------------------------------------------------|
|"How should I know if it works?  That's what beta testers are     |
|for.  I only coded it."                                           |
|(Attributed to Linus Torvalds, somewhere in a posting)            |
\--------------------------------------|---------------------------/
GnuPG Key:  http://poetshome.com/pubkey.asc
On Tuesday, August 12, 2003, at 12:06 PM, Ross, Matthew wrote:

>> My impression from the numerous security postings on the
>> topic have been
>> that it infects Windows Server but just confusses and breaks
>> XP boxes it
>> touches. That could be completely wrong but that was how I
>> read the alerts.
>
> Normal use was what confuses and breaks XP boxes. :-)
>
> _______________________________________________
> discussion mailing list
> EMAIL:PROTECTED
> http://mlug.missouri.edu/mailman/listinfo/discussion


_______________________________________________
discussion mailing list
EMAIL:PROTECTED
http://mlug.missouri.edu/mailman/listinfo/discussion