Worm Alert - Code Red II [Archive] - Chevelle Tech

: Worm Alert - Code Red II


Matt Smith
Aug 6th, 01, 2:27 PM
All Team Members with Broadband take note:

Code Red has infected many Broadband providers http://www.chevelles.com/forum/frown.gif Symptoms of your provider being infected include slow access, constant modem activity when not using it, and many probes on port 80 (HTTP)

Please note: THIS WILL NOT INFECT YOUR COMPUTER unless you run Internet Information Server without the patch. However, Code Red WILL affect your Internet access which is why I decided to post this.

[This message has been edited by Matt Smith (edited 08-06-2001).]

RickS
Aug 6th, 01, 4:56 PM
It's trying to get into my computer like crazy right now. The light on my cable modem is blinking constantly (fortunately they can't see me behind my router http://www.chevelles.com/forum/smile.gif)The new variant is really going after the cable/DSL IP addresses.

------------------
Rick Sutter
Member #383
'67 Chevelle Super Sport
67SS.com (http://67SS.com)

Dean
Aug 7th, 01, 6:51 AM
I just got this email from my cable provider
<BLOCKQUOTE>quote:</font><HR>

ROAD RUNNER ALERT

VIRUS ALERT. YOUR IMMEDIATE ACTION IS REQUIRED.

Dear Road Runner Subscriber:

Road Runner, like many other ISPs and indeed the entire Internet, has
today experienced an attack on its network which is apparently
attributable to the Code Red virus. It is possible that this virus has
infected the PC's of Road Runner's subscribers using the Microsoft
Windows NT or Microsoft Windows 2000 operating systems. Infected PC's
may continue to flood the Internet and Road Runner's network with virus
generated messages (even without your being aware of it).

Road Runner is working to alert all of its subscribers to this problem
and to instruct them on where to find and install the patch necessary to
eliminate the virus. In the meantime, Road Runner subscribers may
experience slow network response, flashing connectivity lights on the
cable modem, and other symptoms (such as unusual port scan log activity
or increased firewall activity) while Road Runner and the Internet
community work to control the impact of this virus.

IF YOUR PC IS RUNNING WINDOWS 2000 OR WINDOWS NT, PLEASE IMMEDIATELY
DOWNLOAD THE CODE RED PATCH FROM MICROSOFT'S WEBSITE
www.microsoft.com/security (http://www.microsoft.com/security) AND RESTART YOUR PC.

IF YOUR PC IS RUNNING WINDOWS 98, WINDOWS 95, OR WINDOWS ME, OR IF YOU
ARE A MACINTOSH USER, NO ACTION IS REQUIRED ON YOUR PART.

We ask for your patience while Road Runner continues to work with the
Internet community to address this virus.

Thank you.

Road Runner Security
<HR></BLOCKQUOTE>

Looks like "NO ACTION IS REQUIRED ON my PART.

------------------
Dean Call
Team Gold member #3 http://personal.clt.bellsouth.net/clt/m/g/mgervin/smilies/biggthumpup.gif
A.C.E.S. # 00235
Mid America Chevelle Club (http://macc.chevelles.net) #001
chevelles.net (http://chevelles.net)
My 69 (http://chevelles.com/showroom/deans69.jpg)

ACES/Midwest Chevelle Regionals (http://www.madmikesstuff.com/Chevelle2001.htm)

A soft answer turns away wrath, but a harsh word stirs up anger.




[This message has been edited by Dean (edited 08-07-2001).]

Matt Smith
Aug 7th, 01, 8:28 AM
I have some bad news boys, Code Red isin't over yet http://www.chevelles.com/forum/frown.gif

I HAVE JUST HEARD that a Code Red III (that's right, three) is on the loose. Code Red III WILL IMPACT Windows 95/98/Me machines by commiting Denial Of Service attacks against them. The attack will cause CPU usage to go to 100%, causing lockup of the machine. As of right now, I know of no defense for this http://www.chevelles.com/forum/frown.gif. Team Members using Broadband are at high risk for this DoS attack as many Broadband providers are infected by Code Red. As soon as I get more information I will pass it on

Matt Smith
Aug 7th, 01, 6:26 PM
UPDATE

There's NO new worm, that's the good news. the BAD news is that it's Code Red II causing the DoS by messing up providers routers. A good firewall will stop it though http://www.chevelles.com/forum/smile.gif