Re: Another virus outbreak
Posted by Don in Hollister on September 24, 2003 at 03:00:14:

HI EQF. I’m not sure as to what you mean by settings. The antivirus program has one setting and that should be “on.”

The better antivirus programs are able to stop worms, trojans and viruses. They will not stop hackers. To do that you need a firewall. Most, if not all antivirus program makers have computers all over the world that have one purpose. That is to get the virus and send it to the antivirus programmers. This is why and how the virus gets a foot in the door. The antivirus program does not have the blocking program for that specific virus. The antivirus programmers must have the virus before they can make a program that will block it. When that is accomplished they download it into their antivirus program that is in your computer and then install it. This can be done automatically or by advising you that there is an update. A blinking icon on the tool bar does this by some of them.

This is the one most likely to have shut the State Dept. down.

MSBlast does not spread via e-mail. Instead, it scans the Internet on port 135 looking for vulnerable computers. When it finds one, it attempts to exploit the DCOM RPC buffer overflow, create a remote root shell on TCP port 4444, then use FTP to download a file called msblast.exe onto the infected computer.

MSBlast contains a denial-of-service (DoS) attack aimed at Microsoft's windowsupdate.com. The attack will start on August 15 and continues throughout the end of the year. MSBlast updates the system Registry with the following line so that it will run each time the computer is rebooted.

Hkey_local_machine\software\Microsoft\Windows\CurrentVersion\ Run "windows auto update" = msblast.exe I just want to say LOVE YOU SAN!! Bill

Prevention
The best prevention is to install the patch from Microsoft. Users who have not yet patched their Windows 2000, NT, and XP systems should do so.

The future doesn’t look for good when it comes to blocking viruses and what have you. They are getting more sophisticated that a simply antivirus program isn’t going to be enough. The Internet Service Providers are going to have to shore up their systems. The web sites themselves are going to have use a combination of firewalls and antivirus programs along with perimeters to catch the virus or what have you before it reaches the main computers.

However none of this will be any good unless they all update their systems once the virus, worm or trojan is detected. Take Care…Don in creepy town


Follow Ups:
     ● Re: Another virus outbreak - EQF  07:41:24 - 9/24/2003  (19450)  (1)
        ● Re: Another virus outbreak - Don in Hollister  13:19:48 - 9/24/2003  (19453)  (0)