Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | I'm under attack!

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

I'm under attack!
Reply
 
Thread Tools
Old 22-08-2003, 10:57   #16
SMHarman
Inactive
 
Join Date: Jun 2003
Services: Cablevision
Posts: 8,305
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
Quote:
Originally posted by homealone
<snip>

- anyone had sobig.f yet?
I can proudly say I got it on Tuesday. The Missus opened a copy of it. Then went Oh poo I've been duped. Virus patterns updated that morning, still was not stopped.

Had to lock down zone alarm and track down the rogue program. Luckily it was not an essential ms file (like blast).

Put the file on a disk and then got restarted.

Its a powerful mailer. My 600k connection and AMD2400 managed to send about 150mails in the 2 minutes it was running.

Bit worried about this trojan thing. Is that killed off once the file is deleted and the registary updated?

I've run the Norton cleaner, and PCCillin says I'm clean, but when I start up I get some strange message still.
SMHarman is offline   Reply With Quote
Advertisement
Old 22-08-2003, 11:07   #17
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Care to elaborate on the strange bootup messages? I may be able to help
Lord Nikon is offline   Reply With Quote
Old 22-08-2003, 11:39   #18
SMHarman
Inactive
 
Join Date: Jun 2003
Services: Cablevision
Posts: 8,305
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
Quote:
Originally posted by Lord Nikon
Care to elaborate on the strange bootup messages? I may be able to help
It looks like a PCCillin message once XP is open and the profile loaded.

A message box about 2in square - no title.

Foreign chars then w32.sobig.f.exe or something like that.

An OK box.

Press OK and it goes away.

Parts of PCCillin are also displaying in foreign chars at the mo also. I'm running the comp copy that came with my ASUS mobo. Properly registered and free updates for a year. Even with the POP2Trap it still missed it as I was an early adopter.

PCCillin and Norton say I don't have the virus, but as you can see I did a bit of a manual removal.

Dare I say I should close my internet connection, reinstall the virus and then remove it again?

Would give you a screen shot with the ox, but I am not on that PC.
SMHarman is offline   Reply With Quote
Old 22-08-2003, 11:48   #19
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
not a chance

Take a look in the registry though in the sections
HKey_Current_User/Software/Microsoft/Windows/Currentversion/Run

and any other Run keys in the registry, also search for w32.sobig.f.exe in the registry

assuming you are on Windows XP disable System Restore and then delete the contents of the c:\windows\prefetch folder too
Lord Nikon is offline   Reply With Quote
Old 22-08-2003, 11:52   #20
SMHarman
Inactive
 
Join Date: Jun 2003
Services: Cablevision
Posts: 8,305
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
Was nothing in the reigistarywhen I did the manual removal - will recheck tonight.

Where do you disable system restore. I've been fortunate enough not to need to use it so far so have not seen how restore / roll back works.
SMHarman is offline   Reply With Quote
Old 22-08-2003, 11:54   #21
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Right click on My Computer, click on Properties then on the System Restore tab

The reason being that if the virus was there when the system created a restore point then the virus may have been backed up along with the system files
Lord Nikon is offline   Reply With Quote
Old 22-08-2003, 12:02   #22
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
SMHarman I just found something for you

http://securityresponse.symantec.com...oval.tool.html

Its a removal tool that should sort out the damage caused by the worm as well

More info on the site.
Lord Nikon is offline   Reply With Quote
Old 22-08-2003, 12:06   #23
SMHarman
Inactive
 
Join Date: Jun 2003
Services: Cablevision
Posts: 8,305
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
See Post 16. I've run that. It says I don't have the virus.

Which I don't I can see that there is no / limited traffic on my connection when I am not doing anything and its all inbound not outbound.

With Sobig running the red bar on ZA is maxed out permanently.
SMHarman is offline   Reply With Quote
Old 24-08-2003, 22:59   #24
Z4pp4
Inactive
 
Join Date: Jun 2003
Posts: 22
Z4pp4 is an unknown quantity at this point
Am I paying for ignorant userâ₠¬Ã¢â€žÂ¢s using up our bandwidth ?

Is NTL doing anything about it ?

Can I name and shame ignorant userâ₠¬Ã¢â€žÂ¢s ?

Originally posted on guess who

Sorry about this: but is the issue is being addressed.

I think NOT !

Fr4nk
Z4pp4 is offline   Reply With Quote
Old 25-08-2003, 00:27   #25
Maggy
The Invisible Woman
Cable Forum Mod
 
Maggy's Avatar
 
Join Date: Jun 2003
Location: between Portsmouth and Southampton.
Age: 73
Services: VM XL TV,50 MB VM BB,VM landline, Tivo
Posts: 40,365
Maggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden aura
Maggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden aura
Quote:
Originally posted by Z4pp4
Am I paying for ignorant userâ₠¬Ã¢â€žÂ¢s using up our bandwidth ?

Is NTL doing anything about it ?

Can I name and shame ignorant userâ₠¬Ã¢â€žÂ¢s ?

Originally posted on guess who

Sorry about this: but is the issue is being addressed.

I think NOT !

Fr4nk
Apparently it is.It would seem at the other site there is a thread (Do Ntl Turn you off because of BLASTER ? )about how those NTL customers still infected by Blaster are being denied connection until they sort out their PC and remove it.

Incog.
__________________
Hell is empty and all the devils are here. Shakespeare..
Maggy is offline   Reply With Quote
Old 25-08-2003, 10:22   #26
Xaccers
Inactive
 
Join Date: Jun 2003
Location: Milling around Milton Keynes
Age: 48
Posts: 12,969
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Hmm, NTL could do a network scan for the vulnerable PC's, then force them to be redirected to a page (like they do with autoreg) informing the customers that they are vulnerable and giving links/instructions on what to do about it
Xaccers is offline   Reply With Quote
Old 25-08-2003, 18:07   #27
Maggy
The Invisible Woman
Cable Forum Mod
 
Maggy's Avatar
 
Join Date: Jun 2003
Location: between Portsmouth and Southampton.
Age: 73
Services: VM XL TV,50 MB VM BB,VM landline, Tivo
Posts: 40,365
Maggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden aura
Maggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden aura
Apparently that is what is happening.

Incog.
__________________
Hell is empty and all the devils are here. Shakespeare..
Maggy is offline   Reply With Quote
Old 29-08-2003, 21:41   #28
Z4pp4
Inactive
 
Join Date: Jun 2003
Posts: 22
Z4pp4 is an unknown quantity at this point
Still getting hammered on port 135
see records on log1.zip & log2.zip
Fr4nk
Z4pp4 is offline   Reply With Quote
Old 29-08-2003, 21:42   #29
Z4pp4
Inactive
 
Join Date: Jun 2003
Posts: 22
Z4pp4 is an unknown quantity at this point
log2.zip
Z4pp4 is offline   Reply With Quote
Old 29-08-2003, 22:14   #30
Steve H
Inactive
 
Join Date: Jun 2003
Location: Stoke-On-Heaven
Age: 39
Services: Freeview, 512k Pipex.
Posts: 1,758
Steve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of QuadsSteve H has a fine set of Quads
Send a message via ICQ to Steve H Send a message via MSN to Steve H Send a message via Yahoo to Steve H
Getting hammered here, Causing CI's (Connection inturuptions) in games (I presume).. One every 2-3 seconds or so.
Steve H is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 23:03.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum