Discussion:
MSBlaster virus reappears - what do I do?
(too old to reply)
Nick FitzGerald
2003-08-21 21:09:39 UTC
Permalink
I used a newly updated AVG to clean the MSBlaster worm off a friend's
Which variant?

Precisely what did AVG report?
computer yesterday. Before doing so, I installed the MS patch,
apparently successfully. ...
"apparently successfully" in the sense that the installation did not throw
up any errors, etc, or "apparently successfully" in the sense of "that after
rebooting the files on the machine match those listed in the file manifest
mentioned in the KnowledgeBase article associated with the MS03-026 patch"

http://support.microsoft.com?kbid=823980

??

Reports from several corporate sources suggest that up to 50% of MS03-026
installations "fail quietly" -- that is, the installer runs to completion
without warning of any errors, adds the Add/Remove entry for the patch, adds
the "the 823980 patch installer has run on this machine" registry value,
etc, etc, etc...
... I restarted the computer several times and
received no message from AVG saying the worm was still on there. (I
had received that message upon initial start-up.) I was getting
memory problem messages but a re-scan with AVG showed no hits at all.
This morning, she started up her computer and says she is getting the
message again from AVG saying the MSBlaster (LovSan) is on her
computer.
This probably means that the machine is still vulnerable and AVG is
detecting the worm's .EXE after it is written to the disk. So long as AVG
is set to deny access (or "stronger") as its "disinfection" action the worm
can't actually be activated.
Do I have to go into the registry or something to eliminate this
virus, or what? ...
No.

The virus is coming in over her Internet conenction _or_ possibly she has
XP and Windows itself is "helpfully" restoring the missing file from the
System Restore _or_ AVG is detecting an archived copy of the virus Windows
"helpfully" stashed in System Restore when the virus first infected.
... Is it the same one I supposedly deleted yesterday, ...
Dunno.

You supplied delightfully few useful details -- certainly too few to answer
questions of this nature with any surety (though if it's XP, I strongly
expect that you'll find the answer in my last two suggestions above).

For starters, impress upon your friend the absolute need for her to note
_exactly_ the full text of any warnings she gets from AVG. There are
several nasties out there that spread via the DCOM RPC flaw as Blaster
does, but there are some that spread via other means as well. If she has
one of the latter and the DCOM RPC hole is plugged on her machine, we need
to know what it is to know where to look for the next security disaster on
the machine that needs to be fixed (that said, a quick check for open file
shares, that she has a decently long admin password with a good mixture of
alpha, numeric and punctuation characters, etc can't hurt; also, if it's
XP, enable the Internet Connection Firewall if she doesn't have a third-
party SFW and if she does, fix its obviously incorrect settings).
... or
has she been reinfected? ...
Due the chronic unreliability of the patch installer, this is a distinct
possibility also.
... (Should I re-install the patch AFTER running
AVG?)
Due the chronic unreliability of the patch installer, this is a distinctly
good idea also, but it would be better to do the installed file version
checks mentioned in the KB article as then you will know for sure whether
the patch has stuck. Once you know for sure the patch has stuck
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.510 / Virus Database: 307 - Release Date: 8/14/03
Disable that stupid feature.

Have you any idea how stupid you will look should one of the dozens of
ways a new, unknown virus (and even in some circumstances, currently know
viruses) could add itself to such a "certified virus free" message? If
you "recommend" AVG to friends, multiply that feeling of stupidity several
times over. I know AVG like you to advertise for them, but this is just
silly and anyone who knows what they're doing disables this egregious and
very misleading advertisement.


--
Nick FitzGerald
David Hough
2003-08-21 22:03:37 UTC
Permalink
Hi Nick
You would make a good writer, if you aren't one already! You
emphasize points that your feel strong about. You are apparently, well
educated.
Terry Johnson
2003-08-21 22:32:25 UTC
Permalink
Post by David Hough
Hi Nick
You would make a good writer, if you aren't one already! You
emphasize points that your feel strong about. You are apparently, well
educated.
Yeah, but his personality SUCKS.

redpenner
FromTheRafters
2003-08-22 01:27:32 UTC
Permalink
Post by David Hough
Hi Nick
You would make a good writer, if you aren't one already! You
emphasize points that your feel strong about. You are apparently, well
educated.
I agree, I think Nick has been very educational as well as
entertaining at times. I like his use of precise language to
explain things ~ he *is* a good writer.

Maybe he could seek employment in that area, ya-think? ;o)

Maybe he could write one of those self-help books.

"How not to be such an idiot ~ for idiots"
"I'm okay, you're an idiot!"
"The mostly yellow art collectors guide"
Nick FitzGerald
2003-08-22 09:01:48 UTC
Permalink
Post by FromTheRafters
Post by David Hough
You would make a good writer, if you aren't one already! You
emphasize points that your feel strong about. You are apparently, well
educated.
I agree, I think Nick has been very educational as well as
entertaining at times. I like his use of precise language to
explain things ~ he *is* a good writer.
Maybe he could seek employment in that area, ya-think? ;o)
Maybe he could write one of those self-help books.
"How not to be such an idiot ~ for idiots"
"I'm okay, you're an idiot!"
"The mostly yellow art collectors guide"
Hey --stop publicizing my titles before I get publishing deals!

If you keep doing that the publishers will not think I'm as original and
bleeding edge as I was telling them...

8-)


--
Nick FitzGerald


P.S. That third one is especially good if you think about the "Dummies"
series of books...
Nick FitzGerald
2003-08-22 09:03:12 UTC
Permalink
Post by David Hough
You would make a good writer, if you aren't one already! You
emphasize points that your feel strong about. You are apparently, well
educated.
As my analyst says "Nick FitzGerald? He's just theees guy..."

Apologies to the dead and long-missed...


--
Nick FitzGerald
Andrew Lee
2003-08-22 11:37:02 UTC
Permalink
Post by Nick FitzGerald
Post by David Hough
You would make a good writer, if you aren't one already! You
emphasize points that your feel strong about. You are apparently, well
educated.
As my analyst says "Nick FitzGerald? He's just theees guy..."
Apologies to the dead and long-missed...
Yeah, you're right about that. "The Salmon of Doubt" is one of the saddest
books I've ever read - I so wished he'd been able to finish it before he
went.


-AJ
Zvi Netiv
2003-08-22 09:48:02 UTC
Permalink
I used a newly updated AVG to clean the MSBlaster worm off a friend's
computer yesterday. Before doing so, I installed the MS patch,
apparently successfully. I restarted the computer several times and
received no message from AVG saying the worm was still on there. (I
had received that message upon initial start-up.) I was getting
memory problem messages but a re-scan with AVG showed no hits at all.
This morning, she started up her computer and says she is getting the
message again from AVG saying the MSBlaster (LovSan) is on her
computer.
Do I have to go into the registry or something to eliminate this
virus, or what? Is it the same one I supposedly deleted yesterday, or
has she been reinfected? (Should I re-install the patch AFTER running
AVG?)
The installation of the patch failed. Most probably because system restore
wasn't turned off (if she runs XP).

For a fail-safe patching procedure, and Blaster blocker (as well as Welchia, and
Sobig.F), go to http://invircible.com/item/76

Regards, Zvi
--
NetZ Computing Ltd. ISRAEL http://invircible.com ***@resq.co.il
InVircible Virus Defense Solutions, ResQ and Data Recovery Utilities
E-mail sent in reply to this post will not be considered private and
will be answered in the newsgroup. Top posting is not appreciated!
redpenner
2003-08-24 03:36:49 UTC
Permalink
Thank you for your help.
Post by Zvi Netiv
I used a newly updated AVG to clean the MSBlaster worm off a
friend's
Post by Zvi Netiv
computer yesterday. Before doing so, I installed the MS patch,
apparently successfully. I restarted the computer several times and
received no message from AVG saying the worm was still on there.
(I
Post by Zvi Netiv
had received that message upon initial start-up.) I was getting
memory problem messages but a re-scan with AVG showed no hits at all.
This morning, she started up her computer and says she is getting the
message again from AVG saying the MSBlaster (LovSan) is on her
computer.
Do I have to go into the registry or something to eliminate this
virus, or what? Is it the same one I supposedly deleted
yesterday, or
Post by Zvi Netiv
has she been reinfected? (Should I re-install the patch AFTER running
AVG?)
The installation of the patch failed. Most probably because system restore
wasn't turned off (if she runs XP).
For a fail-safe patching procedure, and Blaster blocker (as well as Welchia, and
Sobig.F), go to http://invircible.com/item/76
Regards, Zvi
--
InVircible Virus Defense Solutions, ResQ and Data Recovery Utilities
E-mail sent in reply to this post will not be considered private and
will be answered in the newsgroup. Top posting is not appreciated!
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.510 / Virus Database: 307 - Release Date: 8/14/03

Loading...