September 11th, 2005, 02:02 AM
|
#1 (permalink)
| | Ultimate Member
Join Date: Aug 2004 Location: Gladewater, TX
Posts: 1,189
|
I'm running AVG free and downloaded latest update. Did a scan and found this virus  . Don't know how long i had it, but its gone now Win32/Gaelicum.A
alias: Win32.Tenga, W32.Licum, W32/Gael
It`s parasitic infector and internet worm.
Virus spreads itself exploiting Buffer Overrun In RPC Interface vulnerability described in Microsoft Security Bulletin MS03-026.
When the worm is launched, it infects .EXE files on all accessible drives.
Virus also tries to download trojan horse from the internet.
Healing:
Please download Vcleaner utility.
Just wanted y'all to know whats up and how to fix it. |
| |
September 11th, 2005, 02:33 AM
|
#2 (permalink)
| | Ultimate Member
Join Date: Feb 2004 Location: Folsom Prison
Posts: 1,308
|
How I love NOT running Windows
__________________
When you're runnin' down my country, man
You're walkin' on the fightin' side of me
|
| |
September 11th, 2005, 10:45 PM
|
#3 (permalink)
| | Senior Member
Join Date: Dec 2003
Posts: 713
|
Eh this takes advantage of that RPC vulnerability, which WAS an issue a few years back (blaster worm anyone?). Please patch your Windows installations people. SP2 and all that other stuff at the Microsoft update page.
I hope you learned your lesson Ken ^_^
__________________
Mr. Jiggyfly, I have good news...
|
| |
September 11th, 2005, 10:55 PM
|
#4 (permalink)
| | Ultimate Member
Join Date: Aug 2004 Location: Gladewater, TX
Posts: 1,189
| Quote: |
Originally Posted by mr.jiggyfly ......I hope you learned your lesson Ken ^_^ | I'm running winxp/sp2 with all latest security updates and patches and anti-virus kept up to date thank ya very much. |
| |
September 11th, 2005, 11:06 PM
|
#5 (permalink)
| | Senior Member
Join Date: Dec 2003
Posts: 713
|
This particular vulnerability was described in detail in the article you linked, and a patch was released by Microsoft back in 2003, which is also in that link.
In any case, please check if indeed you do have that patch installed.
Edit: Check this out http://www.codingforums.com/archive/...p/t-63654.html
Seems this user got infected even with SP2 installed. Ok I guess I figured it out, you may have been patched against the worm, but was still open to attack by the virus itself, which probably hitched a ride on something you downloaded.
Last edited by mr.jiggyfly : September 11th, 2005 at 11:20 PM.
|
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |
Posting Rules
| You may post new threads You may post replies You may not post attachments You may not edit your posts HTML code is Off | | | | Most Active Discussions | | | | | Recent Discussions  | | | | | |