Results 1 to 12 of 12

Thread: Viruses....GRRRR!

  1. #1
    Senior Member da.Guvna's Avatar
    Join Date
    Aug 2004
    Posts
    609
    Thanks
    39
    Thanked
    1 time in 1 post

    Angry Viruses....GRRRR!

    Anyone else's company been hit by the latest Zotob worm?

    I've spent the last two working days patching machines against it, and I'm FED UP!

    >800 machines + manual patching = very unhappy IT dude

  2. #2
    Senior Member ajbrun's Avatar
    Join Date
    Apr 2004
    Location
    York, England
    Posts
    4,840
    Thanks
    4
    Thanked
    25 times in 13 posts
    What does it do? How would you know if you had it? All I've heard about it is its name, and that it doesn't have to be opened like a normal virus - it spreads itself.

  3. #3
    TiG
    TiG is offline
    Walk a mile in other peoples shoes...
    Join Date
    Jul 2003
    Location
    Questioning it all
    Posts
    6,213
    Thanks
    45
    Thanked
    48 times in 43 posts
    Any reason why you patching it manually with that amount of machines?

    Nope, no viruses here. Last time i've worked at a company that got a virus was 2002 when nimda hit and that was the last time i felt that kinda pain heh.

    TiG
    -- Hexus Meets Rock! --

  4. #4
    Ah, Mrs. Peel! mike_w's Avatar
    Join Date
    Oct 2003
    Location
    Hertfordshire, England
    Posts
    3,326
    Thanks
    3
    Thanked
    9 times in 7 posts
    I think it causes restarting (or at least some variants do). I think it behaves like Blaster in that it spreads itself so long as there's an internet connection. If you want, you can wait for the other variants to arrive and try and kill the other variants.

    http://news.bbc.co.uk/1/hi/technology/4162124.stm
    http://www.f-secure.com/weblog/

    The last and only virus I got was Wazoo (I think that's its name), back in the days of Windows 3.1. No need for firewalls back then! (Well, no internet back then!) I remember installing Office using about thirty floppy disks... and hoping that one didn't decide to break suddenly.
    Last edited by mike_w; 18-08-2005 at 03:32 PM.
    "Well, there was your Uncle Tiberius who died wrapped in cabbage leaves but we assumed that was a freak accident."

  5. #5
    Senior Member da.Guvna's Avatar
    Join Date
    Aug 2004
    Posts
    609
    Thanks
    39
    Thanked
    1 time in 1 post
    http://securityresponse.symantec.com...2.zotob.e.html

    We do actually have an Altiris system in place that allows us to deploy the updates automatically over the network, but the guys in the technical services group are taking their sweet time over getting it ready for deployment, so in the interim we're having to do it by hand. We're running win2k primarily (upgrading to XP as of next week, hilariously), and over the years the base build for these machines has had SO many security updates applied to it that it's just stupidly slow. It hasn't actually infected many, but it's been incubating on a fair amount of systems so we're having to make sure it's eradicated.

  6. #6
    Hexus.net Troll Dougal's Avatar
    Join Date
    Jun 2005
    Location
    In your eyeball.
    Posts
    2,750
    Thanks
    0
    Thanked
    0 times in 0 posts
    Ah, shame it doesn't hit here.

    5 council office sites.

    God knows how many machines but there's about 1 per person.
    Quote Originally Posted by Errr...me
    I MSN offline people
    6014 3DMk 05

  7. #7
    Senior Member ajbrun's Avatar
    Join Date
    Apr 2004
    Location
    York, England
    Posts
    4,840
    Thanks
    4
    Thanked
    25 times in 13 posts
    Quote Originally Posted by mike_w
    The last and only virus I got was Wazoo (I think that's its name), back in the days of Windows 3.1. No need for firewalls back then! (Well, no internet back then!) I remember installing Office using about thirty floppy disks... and hoping that one didn't decide to break suddenly.
    How did you get a virus without the internet? Was it a dogey floppy or something?

  8. #8
    Ah, Mrs. Peel! mike_w's Avatar
    Join Date
    Oct 2003
    Location
    Hertfordshire, England
    Posts
    3,326
    Thanks
    3
    Thanked
    9 times in 7 posts
    Quote Originally Posted by ajbrun
    How did you get a virus without the internet? Was it a dogey floppy or something?
    Yup, someone gave me a floppy with the virus on. It was quite annoying though - it affected Word if memory serves.
    "Well, there was your Uncle Tiberius who died wrapped in cabbage leaves but we assumed that was a freak accident."

  9. #9
    Senior Members' Member Matt1eD's Avatar
    Join Date
    Feb 2005
    Location
    London
    Posts
    2,462
    Thanks
    0
    Thanked
    0 times in 0 posts
    • Matt1eD's system
      • Motherboard:
      • MSI K9N6SGM-V GeForce 6100
      • CPU:
      • Athlon 64 LE-1620 2.41GHz
      • Memory:
      • 2 GB DDR2
      • Storage:
      • 1.25 TB
      • Graphics card(s):
      • Onboard
      • PSU:
      • eBuyer Extra Value 500W!
      • Operating System:
      • XP Pro
    Quote Originally Posted by mike_w
    I think it causes restarting (or at least some variants do). I think it behaves like Blaster in that it spreads itself so long as there's an internet connection. If you want, you can wait for the other variants to arrive and try and kill the other variants.

    http://news.bbc.co.uk/1/hi/technology/4162124.stm
    http://www.f-secure.com/weblog/

    The last and only virus I got was Wazoo (I think that's its name), back in the days of Windows 3.1. No need for firewalls back then! (Well, no internet back then!) I remember installing Office using about thirty floppy disks... and hoping that one didn't decide to break suddenly.
    Ooh, days of floppy deaths. I found them to be really unreliable. However before I started using CDs and DVDs modern floppies aren't like they used to be!

    Win 3.1 + DOS 6 disks, just hoping on a clean install a disk doesn't go corrupt.... that was fun computing.

    Quote Originally Posted by da.Guvna
    nd over the years the base build for these machines has had SO many security updates applied to it
    Why not do a streamline install?

    Never heard of Altaris..... SUS server.

  10. #10
    Senior Member
    Join Date
    Jan 2004
    Location
    Cambridge
    Posts
    283
    Thanks
    13
    Thanked
    24 times in 23 posts
    • timread's system
      • Motherboard:
      • MSI B450 Tomahawk Max
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • 16GB (2x8GB) Corsair DDR4 Vengeance LPX
      • Storage:
      • 1x WD Blue SN550 500GB M.2 NVMe SSD, , 1x Crucial MX500 1TB SSD, 2x WD 1TB HDD in RAID1
      • Graphics card(s):
      • Gigabyte GeForce GTX 1660 Ti WINDFORCE OC 6G
      • PSU:
      • EVGA SuperNOVA 750W Gold Gen2
      • Case:
      • Fractal Design Define R3 Arctic White
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC 2590 G4, Dell U2412M
      • Internet:
      • VirginMedia
    Hey Guvna - any reason why your network/firewall admin can't block TCP Port 445? That's how Zotob is spreading... and it'd save your bacon from patching 800+ systems

    Most decent (hardware/corporate level) firewalls have released updates that can detect & block this worm.

  11. #11
    Senior Member da.Guvna's Avatar
    Join Date
    Aug 2004
    Posts
    609
    Thanks
    39
    Thanked
    1 time in 1 post
    Quote Originally Posted by timread
    Hey Guvna - any reason why your network/firewall admin can't block TCP Port 445? That's how Zotob is spreading... and it'd save your bacon from patching 800+ systems

    Most decent (hardware/corporate level) firewalls have released updates that can detect & block this worm.
    I work for a large multi-national company that is in a highly regulated industry (can't really tell you much more than that). Basically, all software and configurations of that software have to be thoroughly tested, approved, then have it's exact installation parameters documented and signed off by about 6 very busy people before we can even think about putting it on a workstation.
    We have a dedicated team that handles all the firewalls, anti-virus, etc. in the server centre, and anything else to do with IT security in Europe/Middle East/Africa.
    Before they're allowed to block any ports, or change any configurations, they have to perform a risk assessment on the possible impacts it could have on business systems, including a 'back-out' path should things go awry.
    We run a LOT of really bizarre software packages, not just your average Microsoft Office rubbish.

    So basically, it is entriely possible that they could block those ports off, but until they've had time to check through every last bit of documentation to find out which software is using which ports, and then do the relevant testing, those ports will remain open.

    ....you have no idea how frustrating it is working for this company, haha!

  12. #12
    Senior Member da.Guvna's Avatar
    Join Date
    Aug 2004
    Posts
    609
    Thanks
    39
    Thanked
    1 time in 1 post
    Quote Originally Posted by dew1911©
    Virus, don't get me started. I tried scanning last night.

    Norton Found: 26 (Not quickly, or economically, but it got the job done)
    Ad-Aware Found: 15 (Quckly).

    Now, that's an advert to check regular.
    Haha, actually, I'd say it's more of an advert to install something that scans on-access, like AVG.....although, unless your PC reasonably recent (say 2 years old) it'd probably just annoy you.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Oh no! Viruses and cars!
    By rajagra in forum Automotive
    Replies: 3
    Last Post: 14-05-2005, 12:49 AM
  2. Web graphics used to spread viruses through IE
    By Dave_07 in forum General Discussion
    Replies: 11
    Last Post: 27-06-2004, 09:46 PM
  3. damn viruses
    By da_ging in forum General Discussion
    Replies: 10
    Last Post: 28-04-2004, 04:59 PM
  4. having loads of fun with viruses...
    By scottyman in forum Software
    Replies: 17
    Last Post: 23-08-2003, 03:27 PM
  5. Inbox hit by MANY viruses
    By Lowe in forum Software
    Replies: 5
    Last Post: 22-08-2003, 10:59 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •