Borked!

TheSaviorTheSavior Join Date: 2003-10-14 Member: 21688Members
edited June 2004 in Off-Topic
<div class="IPBDescription">What does that mean, anyway?</div> First off, my apologies for posting this here.

It would seem as though I cannot start a topic within the off topic forum, but I CAN start one here. (I would appreciate it if this was also moved to OT.)

That was my first problem, my second problem is this;

I was browsing the forums, listening to winamp, chattign on AIM as usual when my computer starts working extremely hard for an unknown reason. This goes on for roughly 5 minute before I am confronted with this image.

<img src='http://myweb.cableone.net/rtmm1977/mikes/moo.jpg' border='0' alt='user posted image' />

My Question - Is this a possible sign of bad things to come? Possibly a virus? Or maybe just a random act of randomness by a confuzzled computer fresh from a recent format, struggling to regain its identity in this harsh cyber world? (O_o)

Thanks in advance for any help.

Any Mod - please PM me why I cannot post in the OT forum. A simple "No bloody clue." would even suit me. I'm usually content just replying to already created topics.

Edit: Should probrably make it clear what its like when I attempt to post in OT - I get nothing. It just goes to a completely blank page with a black background. No message, no sign of life on other planets, no hint or indication as to what the heck is going on. Just black nothingness.

2nd Edit: Darn spelling errors.

Comments

  • surprisesurprise Join Date: 2003-01-16 Member: 12382Members, Constellation
    edited June 2004
    yes, its a virsu, though i cant tell you which one of the many we had in the last time :/


    you should get a virus-scanner and never use ie again!!!

    opera, firefox or mozilla are excellent browsers and have far less security problems



    and ms-blast is a virus <!--emo&::nerdy::--><img src='http://www.unknownworlds.com/forums/html//emoticons/nerd.gif' border='0' style='vertical-align:middle' alt='nerd.gif' /><!--endemo-->
  • LegionnairedLegionnaired Join Date: 2002-04-30 Member: 552Members, Constellation
    It's not a virus, there's an exploit in the NT kernel that causes that to happen after about 30 seconds.

    First, get the patch <a href='http://microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp' target='_blank'>Here.</a>

    Then on your computer hit CTRL, ALT and DELETE and find MSBlast.exe in the running processes (under processes tab in Windows XP). End the process then go to your windows folder and to system32. If system32 is not seen, then it must be hidden so just type c:\windows\system32 in the address bar. Delete the msblast.exe file. Now the actual file itself is gone but, it was set to boot with your computer so next time you boot your computer, you would get a message saying that it cant find the file. But you can remove it from startup easily by clicking start - run and type msconfig. Click the startup tab and uncheck it. Now it wont be set to boot with the computer but it wont disappear from the list on its own so if you're like me and dont even like having it in the list, do the following instead!

    Click start - run and type regedit. Now navigate to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run and remove the string with the value msblast.exe. It should be called Windows Update or something similar!

    Now hit the f5 key to refresh your registry. Close it and I recommend a reboot! Then when you reboot, go to <a href='http://www.windowsupdate.com' target='_blank'>http://www.windowsupdate.com</a> and download any security updates for your OS. The reason these stupid worms get out anyway is because people don't keep their OSes updated. Update it at least once a week.
  • RushakraRushakra Join Date: 2004-03-25 Member: 27523Members
    Borked is a term that (to the best of my knowledge) originated in the Star Wars Galaxies Beta and was used to describe something that was "broken," as in not functioning correctly.

    In NS 2.01, someone could say that Fade hitboxes were borked.
  • WirheWirhe Join Date: 2003-06-22 Member: 17610Members
    edited June 2004
    Well, if you do not have a firewall and Blaster has already got in, I can only guess in how gruesome your comps pains are really. This is what you should do, and is the regular procedure in all computer shops:

    1) Format. Twice. Then format again just in case.
    2) But before you format ( <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html//emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo--> ), remember to download ZoneAlarm firewall. It's free and it's good enough for you. Burn it somewhere.
    3) Install some OS, or use Knoppix -it doesn't require installing if you have enough RAM.
    4) Install the firewall ASAP. Then update your OS.
    5) Get Mozilla/Konqueror/Firefox/whatever as long as it isn't IE (the worst browser in the market).

    Formatted.
    Fixed.
    Finished.

    Almost what Caesar said. <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html//emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo-->
  • GrillkohleGrillkohle Join Date: 2003-12-23 Member: 24695Members, Constellation
    That is the Blaster worm, I've had it once before. All you need to do is enter shutdown -a in command console to stop the timer, and then you can go to symantec.com and download a free removal tool somewhere.
  • taboofirestaboofires Join Date: 2002-11-24 Member: 9853Members
    Borked = deliberate mispelling of broken, and it has been around at least as long as the internet has. Right around the time where BBS's were extremely popular and 8800 baud modems were common.

    <a href='http://people.kldp.org/~eunjea/jargon/?idx=borken' target='_blank'>source</a>

    If you ever see "remote procedure call," it means some program running on your computer is basically phoning home to run a program for your computer. If nothing you have running should be doing that (it's unlikely that you would), you are infected with something.

    RPC is not a very common programming tactic anymore. Unless you're contacting a supercomputer for a weather sim or something, your PC should be able to do anything that the programmer wants to do itself, and faster by cutting out the latency of networking.
  • GrillkohleGrillkohle Join Date: 2003-12-23 Member: 24695Members, Constellation
    Once again:
    Click Start -> Run... -> enter "CMD" and hit OK to open a command prompt.
    Then put in the command
    shutdown -a
    to stop the computer from shutting down.

    Then, download the Removal tool, <a href='http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html' target='_blank'>this one right here</a> to remove the virus, and you're done. There is nothing about RCP that you need to know.
  • RedfordRedford Monorailcatfjord Join Date: 2002-04-28 Member: 528Members, NS1 Playtester
    You know, some people don't like formatting their PCs (like me!) whenever a byte is out of place and instead actually want to try to fix the problem directly. Formating is sort of a sloppy, catch-all solution that isn't exactly good technical help - if there is a solution other then formatting, the person should probally do it simply because that person may have better things to do then backing up every important file on their computer then reinstalling everything again.
  • explodingheadboyexplodingheadboy Join Date: 2003-04-18 Member: 15636Members, Constellation
    <!--QuoteBegin-taboofires+Jun 7 2004, 01:35 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (taboofires @ Jun 7 2004, 01:35 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> RPC is not a very common programming tactic anymore. Unless you're contacting a supercomputer for a weather sim or something, your PC should be able to do anything that the programmer wants to do itself, and faster by cutting out the latency of networking. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Hell, it's really uncommon, I thought I could safely disable it along with all the other services I don't need.

    ...

    Then I had a problem with my videocard and tried to reinstall the drivers. Of course, nvidia's driver setup doesn't finish unless you have the RPC service running... It too me a while to figure that one out.

    What a pain in the ****.

    And then I switched to ATI.
  • SDJasonSDJason Join Date: 2003-05-29 Member: 16841Members
    i duno... but i had this virus thingie the msblast worm... and i unplugged my computer from the internet and it stopped shutting down.... from there i was able to delete it and stuff.... yaay!!

    That might be just a coincidenc... but i believe it worked by contacting an internet site, which ran the "code" that shutdown the computer... no internet... no shut down

    At least for me nayways

    ~Jason
  • TheSaviorTheSavior Join Date: 2003-10-14 Member: 21688Members
    edited June 2004
    Thanks a ton for the help guys <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html//emoticons/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /><!--endemo--> It was indeed blaster <!--emo&???--><img src='http://www.unknownworlds.com/forums/html//emoticons/confused.gif' border='0' style='vertical-align:middle' alt='confused.gif' /><!--endemo--> I got it fixxed.

    I already recently reformatted, and I wasnt about to again...I havent gotten around to putting in my AV software yes... And is IE *really* that bad? I've been using it for as long as I can remember... (I've been an int4rw3b monkey since I was 8 years old, I'm 18 now.) I hear Firefox is pretty good... I'll look into that.

    Once again, thanks a ton for all of your help <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html//emoticons/smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /><!--endemo-->
  • DaxxDaxx Join Date: 2002-04-16 Member: 460Members, Constellation, Reinforced - Shadow
    <!--QuoteBegin-Rushakra+Jun 7 2004, 01:00 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Rushakra @ Jun 7 2004, 01:00 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Borked is a term that (to the best of my knowledge) originated in the Star Wars Galaxies Beta and was used to describe something that was "broken," as in not functioning correctly.

    In NS 2.01, someone could say that Fade hitboxes were borked. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Heh, while that is an acurate discription of the word, its been around for a <b>lot</b> longer than the Star Wars Galaxies beta <!--emo&;)--><img src='http://www.unknownworlds.com/forums/html//emoticons/wink.gif' border='0' style='vertical-align:middle' alt='wink.gif' /><!--endemo-->
  • im_lostim_lost TWG Rule Guru Join Date: 2003-04-26 Member: 15861Members
    Firefox is definitely better than IE.

    1. Tabbed browsing (which can be ignored if you decide not to use it)
    2. Popup blocker (very useful)
    3. Automatically imports IE favorites list for convenient switchover

    Occasionally sites are made using code that only works in IE, so it is useful to keep it installed just in case.
  • crummycrummy Join Date: 2003-08-14 Member: 19709Members
    <!--QuoteBegin-i'm lost+Jun 7 2004, 02:37 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (i'm lost @ Jun 7 2004, 02:37 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Firefox is definitely better than IE.

    1. Tabbed browsing (which can be ignored if you decide not to use it)
    2. Popup blocker (very useful)
    3. Automatically imports IE favorites list for convenient switchover

    Occasionally sites are made using code that only works in IE, so it is useful to keep it installed just in case. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    And there's a mouse gestures plugin too! Wooties!
  • WirheWirhe Join Date: 2003-06-22 Member: 17610Members
    Yeah, formatting is the easy way out, but if Blaster got in, I'm ready to bet that his comp has all doors wide-open, thus there might be some trojans and other nasty scrub too. Thus, formatting is the best option in a case like that (don't want to risk your credit card, do you?)
  • DelarosaDelarosa Naturally Custom Join Date: 2002-11-29 Member: 10214Members, NS1 Playtester
    moved to OT as requested.
  • SirusSirus Join Date: 2002-11-13 Member: 8466Members, NS1 Playtester, Constellation
    Actually, "Borked" actually came from a Reagan Supreme Court nomination. Robert Bork was a nominee for a seat on the supreme court, he endured the longest confirmation hearing of any Supreme Court Nominee, and testified for some 30 odd hours. Essentially, it was really bad for him politically and a tumultuous period of time.

    The term, at least politically, means to go through extremely difficult, fierce, and demoralizing trial and still succeed. Although, after coming through the mess, it leaves the person "bloodied", for a lack of a better word. Sometimes, almost making the ordeal not worth it.
  • douchebagatrondouchebagatron Custom member title Join Date: 2003-12-20 Member: 24581Members, Constellation, Reinforced - Shadow
    i got that error when i was bored and started shutting down all the programs that are running in the background.
  • GlissGliss Join Date: 2003-03-23 Member: 14800Members, Constellation, NS2 Map Tester
    <!--QuoteBegin-i'm lost+Jun 7 2004, 11:37 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (i'm lost @ Jun 7 2004, 11:37 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Firefox is definitely better than IE.

    1. Tabbed browsing (which can be ignored if you decide not to use it)
    2. Popup blocker (very useful)
    3. Automatically imports IE favorites list for convenient switchover

    Occasionally sites are made using code that only works in IE, so it is useful to keep it installed just in case. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Though I'm not sure about the Popup Blocker, MyIE2 can do these things and is far more customizable. You also won't have to download ten billion extensions just to get it to work the way you want it to.
  • im_lostim_lost TWG Rule Guru Join Date: 2003-04-26 Member: 15861Members
    <!--QuoteBegin-pjofsky+Jun 7 2004, 04:20 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (pjofsky @ Jun 7 2004, 04:20 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-i'm lost+Jun 7 2004, 11:37 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (i'm lost @ Jun 7 2004, 11:37 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Firefox is definitely better than IE.

    1.  Tabbed browsing (which can be ignored if you decide not to use it)
    2.  Popup blocker (very useful)
    3.  Automatically imports IE favorites list for convenient switchover

    Occasionally sites are made using code that only works in IE, so it is useful to keep it installed just in case. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Though I'm not sure about the Popup Blocker, MyIE2 can do these things and is far more customizable. You also won't have to download ten billion extensions just to get it to work the way you want it to. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    I have received <b>zero</b> popup ads since I started using Firefox at the beginning of this year. Occasionally it will block a popup box that you want, but it is easy to tell it to unblock that site so you can have the box show up. I saw that MyIE2 also has an ad blocker, but it seems like it takes more work customizing it. I also looked through all of the extensions for Firefox, and didn't see a single one worth downloading.

    Anyway, the point is, don't use IE. There are lots of other choices out there, and I think they are all better in terms of security and convenience (if you can deal with the initial time investment to install and configure it, which isn't much).
  • ZelZel Join Date: 2003-01-27 Member: 12861Members
    the RPC service is required to keep any NT kernel operating system running properly. this includes windows NT4, 2000, and XP.

    closing random svchost.exe entries in the task manager crashes the RPC service, (svchost stands for service host). if the rpc service closes for any reason, windows recognizes that it is broken, and decides to reboot to restart the service.

    because it is windows trying to shut itself down, and not the virus forcing you, "shutdown -a" will happily cancel the timer.

    however, many parts of windows wont work without RPC. do not blame your nvidia drivers, for even floppy drives and usb drives wont work without RPC.

    IE does not cause the virus, any unpatched windows XP machine is vulnerable. you must run windows update to patch the vulnerability, there are three vital patches for this particular exploit, one for each virus "Blaster", "Sasser", and the new one "Korgo."

    next, reboot and run an antivirus software such as Trend-Micro's Housecall, because the virus DID get in as the timer started. MSBlast and Sasser are extremely prevalent these days. so long as you do not clean the virus off, your computer is actively using your bandwidth in effort to cause this whole thing on other people's computers.

    I am a professional PC repairman, and see these things happen so often, that i felt obligated to tell you what i know. run windows update weekly to prevent this from happening. the sasser and blaster patches were avaliable from microsoft's windows update MONTHS before the waves of viruses came out exploiting unpatched systems.
Sign In or Register to comment.