<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lester Chan's Website &#187; Virus</title>
	<atom:link href="http://lesterchan.net/blog/category/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://lesterchan.net</link>
	<description>Lester Chan's Website &#124; lesterchan.net</description>
	<lastBuildDate>Wed, 23 May 2012 00:49:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Removing Sasser Worm</title>
		<link>http://lesterchan.net/blog/2004/05/04/removing-sasser-worm/</link>
		<comments>http://lesterchan.net/blog/2004/05/04/removing-sasser-worm/#comments</comments>
		<pubDate>Tue, 04 May 2004 14:42:22 +0000</pubDate>
		<dc:creator>Lester Chan</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.lesterchan.net/blogs/archives/2004/05/04/removing-sasser-worm/</guid>
		<description><![CDATA[First, to make sure you computer don&#8217;t get restarted automatically, go to Run, then type &#8221; shutdown -a&#8221; without the quotes. This will prevent it from restarting automatically. Download the patch from Microsoft site. Here are the links: Windows XP or Windows 2000/2003. Install the patch, then download Symantec&#8217;s Sasser Removal Tool. The tool will: [...]]]></description>
			<content:encoded><![CDATA[<p>First, to make sure you computer don&#8217;t get restarted automatically, go to Run, then type &#8221; shutdown -a&#8221; without the quotes. This will prevent it from restarting automatically.</p>
<p>Download the patch from Microsoft site. Here are the links: <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=3549EA9E-DA3F-43B9-A4F1-AF243B6168F3&#038;displaylang=en" target="_blank">Windows XP</a> or <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0692C27E-F63A-414C-B3EB-D2342FBB6C00&#038;displaylang=en" target="_blank">Windows 2000/2003</a>.</p>
<p>Install the patch, then download <a href="http://securityresponse.symantec.com/avcenter/FxSasser.exe" target="_blank">Symantec&#8217;s Sasser Removal Tool</a>.</p>
<p>The tool will:</p>
<blockquote><p>
1. Terminates the W32.Sasser viral processes.<br />
2. Deletes the W32.Sasser files.<br />
3. Deletes the registry values that the worm adds.
</p></blockquote>
<p>Restart your computer in safe mode, run FxSasser.exe. After that boot up normally and run the tool again to ensure that the virus is totally gone.</p>
<p>Note: I did not tried the above steps because I do not have an infected PC to try on. But based on logic and common sense, it should work.</p>
]]></content:encoded>
			<wfw:commentRss>http://lesterchan.net/blog/2004/05/04/removing-sasser-worm/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>W32.Sasser.worm</title>
		<link>http://lesterchan.net/blog/2004/05/02/w32sasserworm/</link>
		<comments>http://lesterchan.net/blog/2004/05/02/w32sasserworm/#comments</comments>
		<pubDate>Sat, 01 May 2004 19:20:29 +0000</pubDate>
		<dc:creator>Lester Chan</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.lesterchan.net/blogs/archives/2004/05/02/w32sasserworm/</guid>
		<description><![CDATA[A few of my friends had already been infected by this virus. It is a very wide spread virus. The patch had already been released weeks ago. If you got infected, you deserved it. For god&#8217;s sake, be a responsible user and keep your Windows up to date. How to Tell If Your Computer Is [...]]]></description>
			<content:encoded><![CDATA[<p>A few of my friends had already been infected by this virus. It is a very wide spread virus. The patch had already been released weeks ago. If you got infected, you deserved it. For god&#8217;s sake, be a responsible user and keep your Windows up to date.</p>
<p><b>How to Tell If Your Computer Is Infected</b><br />
If your computer is infected with W32.Sasser.worm, you may see a dialog box with text that refers to LSASS.exe. Some customers whose computers have been infected may not notice the presence of the worm at all, while others who are not infected may experience problems because the worm is attempting to attack their computer. Typical symptoms may include systems rebooting every few minutes without user input. </p>
<p>For more information on this virus and how to remove/prevent it, <a href="http://www.microsoft.com/security/incident/sasser.asp" target="_blank">visit this Microsoft site</a>.</p>
<p>To have enough time to do so, you need to disable the shutdown of Windows by any application. Go to Run, type &#8220;shutdown -a&#8221; without the quotes.</p>
]]></content:encoded>
			<wfw:commentRss>http://lesterchan.net/blog/2004/05/02/w32sasserworm/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>SoBig Virus</title>
		<link>http://lesterchan.net/blog/2003/08/21/sobig-virus/</link>
		<comments>http://lesterchan.net/blog/2003/08/21/sobig-virus/#comments</comments>
		<pubDate>Wed, 20 Aug 2003 16:55:11 +0000</pubDate>
		<dc:creator>Lester Chan</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.lesterchan.net/blogs/archives/2003/08/21/sobig-virus/</guid>
		<description><![CDATA[Hard on the heels of the Blaster worm outbreak , yet another version of the resilient and ever-popular SoBig virus began spreading rapidly on the Internet Tuesday morning. Known as SoBig.F, the new variant behaves much like its older siblings, infecting Windows machines via e-mail and sending out dozens of copies of itself. The variant [...]]]></description>
			<content:encoded><![CDATA[<p>Hard on the heels of the Blaster worm outbreak , yet another version of the resilient and ever-popular SoBig virus began spreading rapidly on the Internet Tuesday morning. Known as SoBig.F, the new variant behaves much like its older siblings, infecting Windows machines via e-mail and sending out dozens of copies of itself. </p>
<p>The variant began spreading early Tuesday Eastern time, and by 9 a.m. Tuesday, MessageLabs Inc. had stopped more than 10,000 copies. The virus size is approximately 73 KB, and the attachment that actually contains the malicious code can carry any one of a number of names, according to iDefense Inc., a security company based in Reston, Va. Among the file names seen so far are:<br />
<blockquote><b>Â»</b> application.pif<br />
<b>Â»</b> document_all.pif<br />
<b>Â»</b> details.pif<br />
<b>Â»</b> document_9446.pif<br />
<b>Â»</b> movie0045.pif<br />
<b>Â»</b> thank_you.pif<br />
<b>Â»</b> your_details.pif<br />
<b>Â»</b> your_document.pif<br />
<b>Â»</b> wicked_scr.scr</p></blockquote>
<p>The subject line of the e-mail message that carries the attachment is also randomized, and many of the subjects are similar to previous SoBig variants. They include:<br />
<blockquote><b>Â»</b> <b>Â»</b> Re: Details<br />
<b>Â»</b> Re: Approved<br />
<b>Â»</b> Re: Re: My details<br />
<b>Â»</b> Re: That movie<br />
<b>Â»</b> Re: Thank you!<br />
<b>Â»</b> Re: Your application<br />
<b>Â»</b> Re: Wicked screensaver<br />
<b>Â»</b> Thank you!<br />
<b>Â»</b> Your details</p></blockquote>
<p>SoBig.F installs a copy of itself in the Windows registry, in a file named &#8220;winppr32.exe.&#8221; MessageLabs lists the worm as originating in the Netherlands, and its statistics show that SoBig.F has spread mainly in that country and Norway at this point. However, that is likely to change as workers in North America begin checking their e-mail Tuesday.</p>
<p>Some facts:<br />
<blockquote><b>Â»</b> &#8220;This is local clogging as opposed to worldwide Internet clogging,&#8221; Kuo said. &#8220;There are many areas of local pain.&#8221;<br />
<b>Â»</b> The MSBlast variant, Nachia, infects computers using the same widespread vulnerability in Microsoft Windows that previous versions of the worm exploited. The program then downloads a patch to protect systems against future infections of the MSBlast worm.<br />
<b>Â»</b> While the intentions of the unknown worm writer seem to have been good, its aggressive spread has clogged many networks.<br />
<b>Â»</b> &#8220;It&#8217;s faster,&#8221; Kuo said. Previous versions of MSBlast tried to spread to 20 different network addresses at a time but had to wait for each attempt to fail if no computer was at that address. The Nachia variant tries to spread to 300 different address at a time and doesn&#8217;t wait, letting it spread very fast.<br />
<b>Â»</b> The latest version of the SoBig mass-mailing computer virus also caused headaches for network administrators. E-mail service provider MessageLabs stopped more than 100,000 messages carrying the latest virus in the first few hours of the attack.</p></blockquote>
<p><b>Source From <a href="http://www.iexbeta.com/" target="_blank">ieXbeta</a></b></p>
]]></content:encoded>
			<wfw:commentRss>http://lesterchan.net/blog/2003/08/21/sobig-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Removing the W32.Blaster.Worm</title>
		<link>http://lesterchan.net/blog/2003/08/13/removing-the-w32blasterworm/</link>
		<comments>http://lesterchan.net/blog/2003/08/13/removing-the-w32blasterworm/#comments</comments>
		<pubDate>Wed, 13 Aug 2003 03:28:27 +0000</pubDate>
		<dc:creator>Lester Chan</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.lesterchan.net/blogs/archives/2003/08/13/removing-the-w32blasterworm/</guid>
		<description><![CDATA[Surf several sites regarding this worm. Shall be sharing some helpful tips with you all. 1. Go to Start, Run and type in shutdown -a. This will cancel the shutdown attempt 2. Patch Your System with the appropriate MS03-026 Patch 3. After Installation of the Patch, Reboot your system. 4. Download and run &#8220;FIXBLAST.exe&#8221; to [...]]]></description>
			<content:encoded><![CDATA[<p>Surf several sites regarding this worm. Shall be sharing some helpful tips with you all.</p>
<blockquote><p>1. Go to Start, Run and type in shutdown -a. This will cancel the shutdown attempt<br />
2. Patch Your System with the appropriate <a href="http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp" target="_blank">MS03-026</a> Patch<br />
3. After Installation of the Patch, Reboot your system.<br />
4. Download and run &#8220;<a href="http://securityresponse.symantec.com/avcenter/FixBlast.exe">FIXBLAST.exe</a>&#8221; to remove the MSBLAST.exe file, terminate the process and remove added registry keys by the worm.<br />
5. Reboot your pc one last time.<br />
6. Visit WindowsUpdate.com more often and take note of our repeated warnings to keep your system updated.</p></blockquote>
<p>User&#8217;s should block access to TCP port 4444 at the firewall level. User&#8217;s should also block the following ports, if they do not use applicaitons listed:<br />
<blockquote><b>Â»</b> TCP Port 135, &#8220;DCOM RPC&#8221;<br />
<b>Â»</b> UDP Port 69, &#8220;TFTP&#8221;</p></blockquote>
<p>Direct Links:<br />
<blockquote><b>Â»</b> <a href="http://download.microsoft.com/download/0/1/f/01fdd40f-efc5-433d-8ad2-b4b9d42049d5/Windows2000-KB823980-x86-ENU.exe">Windows 2000 English Patch (MS Site)</a><br />
<b>Â»</b> <a href="http://download.microsoft.com/download/9/8/b/98bcfad8-afbc-458f-aaee-b7a52a983f01/WindowsXP-KB823980-x86-ENU.exe">Windows XP English Patch (MS Site)</a></p>
<p><b>Â»</b> Windows 2000 English Patch (Mirrored)<br />
<b>Â»</b> Windows XP English Patch (Mirrored)</p>
<p><b>Â»</b> <a href="http://securityresponse.symantec.com/avcenter/FixBlast.exe">FixBlast &#8211; W32.Blaster.Worm Removal Tool</a></p>
<p><b>Â»</b> <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html" target="_blank">Symantec Security Response &#8211; W32.Blaster.Worm Removal Tool</a></p>
<p><b>Â»</b> <a href="http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp" target="_blank">Microsoft Security Bulletin MS03-026</a></p></blockquote>
<p>Always keep your Windows Updated.</p>
]]></content:encoded>
			<wfw:commentRss>http://lesterchan.net/blog/2003/08/13/removing-the-w32blasterworm/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>W32.Blaster.Worm</title>
		<link>http://lesterchan.net/blog/2003/08/12/w32blasterworm/</link>
		<comments>http://lesterchan.net/blog/2003/08/12/w32blasterworm/#comments</comments>
		<pubDate>Tue, 12 Aug 2003 14:56:44 +0000</pubDate>
		<dc:creator>Lester Chan</dc:creator>
				<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://www.lesterchan.net/blogs/archives/2003/08/12/w32blasterworm/</guid>
		<description><![CDATA[Lots of people have been infected by the W32.Blaster.Worm. It is a worm that will exploit the DCOM RPC vulnerability using TCP port 135. It will attempt to download and run a file, msblast.exe. Â» Infection Length: 6,176 bytes Â» Systems Affected: Microsoft IIS, Windows 2000, Windows NT, Windows XP Â» Systems Not Affected: Linux, [...]]]></description>
			<content:encoded><![CDATA[<p>Lots of people have been infected by the <b>W32.Blaster.Worm</b>. It is a worm that will exploit the DCOM RPC vulnerability using TCP port 135. It will attempt to download and run a file, msblast.exe.</p>
<blockquote><p><b>Â»</b> Infection Length: 6,176 bytes<br />
<b>Â»</b> Systems Affected: Microsoft IIS, Windows 2000, Windows NT, Windows XP<br />
<b>Â»</b> Systems Not Affected: Linux, Macintosh, OS/2, UNIX</p></blockquote>
<p>Basically, what the virus does is it will auto restart your Windows after a certain time.</p>
<p>Fixes:<br />
<blockquote><b>Â»</b> <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html" target="_blank">Symantec Security Response &#8211; W32.Blaster.Worm Information (Removal)</a><br />
<b>Â»</b> <a href="http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp" target="_blank">Microsoft Security Bulletin (Patch)</a></p></blockquote>
<p>It is recommended that all users get this fixed as soon as possible.</p>
<p><b>*Update*</b> I have mirrored the Microsoft patch on this server. If it is illegal inform me and I will remove it immediately.<br />
<blockquote><b>Â»</b> WinXP English Patch<br />
<b>Â»</b> Win2K English Patch</p></blockquote>
<p><b>*Disclaimer*</b> Download at your own risk, I will not hold any responsibility if there is anything wrong with your computer after installing it.</p>
]]></content:encoded>
			<wfw:commentRss>http://lesterchan.net/blog/2003/08/12/w32blasterworm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Database Caching 4/10 queries in 0.009 seconds using memcached
Object Caching 378/386 objects using memcached

Served from: lesterchan.net @ 2012-05-25 09:27:35 -->
