WSAZ Apologizes.

If it's about broadcasting, radio, TV, satellite, cable, this is where to talk about it.

Moderators: Hoosier Daddy, The People's DJ, Arp2

Post Reply
User avatar
genlock
Moderator
Moderator
Posts: 5867
Joined: Fri Dec 21, 2001 4:09 pm
Location: OW

WSAZ Apologizes.

Post by genlock »

WSAZ's Amanda Barren apologized at the top of the newscast for a "virus" that is affecting grafx, captioning and a lot of other stuff. Amanda indicated that the "virus" reached WSAZ via the parent company, Gray Broadcasting.
I wonder if the computer people were able to be located to be called out to fix it. I wonder if someone just crashed the newsroom system and couldn't get it to re-boot properly.

The newscast ended at 6:18pm.
User avatar
genlock
Moderator
Moderator
Posts: 5867
Joined: Fri Dec 21, 2001 4:09 pm
Location: OW

Post by genlock »

WSAZ will, no doubt, accept many awards tonight at the WVBA meeting.
At least they cannot blame Parkervision.
User avatar
square_enix
Newbie
Posts: 9
Joined: Wed Dec 31, 2003 2:03 am
Location: Hunt Town

Post by square_enix »

Yeah, The Virus knocked down all of our Windows 2000 Systems and servers that were tied to the GRAY network.

2 Of Grays TV stations were knocked completely off the Air because of the Virus.

We thought it was a pure inside job until we discovered WOWK-TV had also been hit by the Virus.


As far as Newsroom went, We lost ENPS, Internet, and Email.

A Fun Evening all around.
User avatar
genlock
Moderator
Moderator
Posts: 5867
Joined: Fri Dec 21, 2001 4:09 pm
Location: OW

Post by genlock »

Is it fixed?
User avatar
fearpeddler
Member
Member
Posts: 1662
Joined: Mon Jul 10, 2006 8:27 pm

Post by fearpeddler »

whats the name of "the virus"??
Doesn't MSNBC stand for the Media that Spins the News for Barrack's Cabinet?



Political Correctness is always having to say you're sorry. - Me
User avatar
square_enix
Newbie
Posts: 9
Joined: Wed Dec 31, 2003 2:03 am
Location: Hunt Town

Post by square_enix »

As of right now,
We still have the virus in house. And continue to operate on a skeleton system.

Name of the Virus, I dont know that yet.
"Look at this place, fifty-thousand people used to live in this city, now it's a ghost town. I've never seen anything like it." : Captain Macmillan {In reference to Pripyat Ukraine}
Lee
Member
Member
Posts: 904
Joined: Fri May 03, 2002 8:56 pm

Post by Lee »

Genlock is the WSAZ Police.

He notifies us of all the goings on of Randy Yohe and Adam Joseph.

Without Genlock's updates, we are not updated on Randy Yohe.

We would be lost without him.
twitter.com/CrypticBullshit
Cameron
Member
Member
Posts: 887
Joined: Fri Aug 09, 2002 8:41 am
Location: Birmingham Ala-BAMA!
Contact:

Post by Cameron »

square_enix wrote:As of right now,
We still have the virus in house. And continue to operate on a skeleton system.

Name of the Virus, I dont know that yet.
It a virus that piggybacks on .ani animated cursor files - either via e-mail or embedded in webpages.

We're on holy-crap lock-down on our servers too.
Hopefully, there will be a patch this week.
Norton has the following:
ThreatCon Level is 2

The ThreatCon has been raised to level 2. A new, zero-day attack that exploits an unpatched vulnerability in the way Microsoft Windows handles Animated Cursor (ANI) files has been discovered in the wild. The malicious ANI files are most likely to be hosted on websites. When a victim visits a site, arbitrary code may run. Microsoft has confirmed the issue and is currently planning to issue a Security Update. An exploit code leveraging the vulnerability has been released publicly. Since the exploit works independently of the file extension, blocking ANI files would not mitigate the issue. A self propagating, worm-like variant of the exploit has also been reported, which propagates links to websites hosting malicious ANI files. It is being detected as W32.Fubalca by Symantec AntiVirus. Customers are advised to block the following domains which are known to host the exploit and keep their AntiVirus definitions up-to-date. 1.520sb.cn 220.71.76.189 222.73.220.45 55880.cn 81.177.26.26 85.255.113.4 bc0.cn count12.51yes.com count3.51yes.com d.77276.com fdghewrtewrtyrew.biz i5460.net jdnx.movie721.cn newasp.com.cn s103.cnzz.com s113.cnzz.com ttr.vod3369.cn uniq-soft.com wsfgfdgrtyhgfd.net 04080.com 33577.cn h3210.com hackings.cn koreacms.co.kr macrcmedia.com macrcmedia.net ncph.net xxx.cn 2007ip.com microfsot.com Microsoft Security Advisory (935423): Vulnerability in Windows Animated Cursor Handling (http://www.microsoft.com/technet/securi ... 35423.mspx
------------------------
Cameron Smith - CSRE®
Senior Member - SBE 68 Birmingham
Senior Digital Product Manager - Hibbett Sports|City Gear
Dave Allen
Member
Member
Posts: 1859
Joined: Fri Apr 14, 2006 8:22 am
Location: Nowhere near Wheeling, thank you Jesus!

Post by Dave Allen »

BTW I think Adam Joesph is long gone from WSAZ. Speaking of WSAZ, Cameron, don't you have a picture to post for Nunley?
Titties and beer...thank God almighty for titties and beer!
Cameron
Member
Member
Posts: 887
Joined: Fri Aug 09, 2002 8:41 am
Location: Birmingham Ala-BAMA!
Contact:

Post by Cameron »

Start adding these forbidden domains to your router's firewalls before the sales-geeks open their mail Monday:

1.520sb.cn
220.71.76.189
222.73.220.45
55880.cn
81.177.26.26
85.255.113.4
bc0.cn
count12.51yes.com
count3.51yes.com
d.77276.com
fdghewrtewrtyrew.biz
i5460.net
jdnx.movie721.cn
newasp.com.cn
s103.cnzz.com
s113.cnzz.com
ttr.vod3369.cn
uniq-soft.com
wsfgfdgrtyhgfd.net
04080.com
33577.cn
h3210.com
hackings.cn
koreacms.co.kr
macrcmedia.com
macrcmedia.net
ncph.net xxx.cn
2007ip.com
microfsot.com
------------------------
Cameron Smith - CSRE®
Senior Member - SBE 68 Birmingham
Senior Digital Product Manager - Hibbett Sports|City Gear
Cameron
Member
Member
Posts: 887
Joined: Fri Aug 09, 2002 8:41 am
Location: Birmingham Ala-BAMA!
Contact:

Post by Cameron »

daveinthemorning wrote:BTW I think Adam Joesph is long gone from WSAZ. Speaking of WSAZ, Cameron, don't you have a picture to post for Nunley?
Whoops, almost forgot...
------------------------
Cameron Smith - CSRE®
Senior Member - SBE 68 Birmingham
Senior Digital Product Manager - Hibbett Sports|City Gear
User avatar
genlock
Moderator
Moderator
Posts: 5867
Joined: Fri Dec 21, 2001 4:09 pm
Location: OW

Post by genlock »

WSAZ is the onliest one of the GRAY stations that mentions computer problems on a website. Which GRAY stations went off the air due to computer virus?
User avatar
fearpeddler
Member
Member
Posts: 1662
Joined: Mon Jul 10, 2006 8:27 pm

Post by fearpeddler »

so was it just gray stations that had a run-in with this bug..
Doesn't MSNBC stand for the Media that Spins the News for Barrack's Cabinet?



Political Correctness is always having to say you're sorry. - Me
User avatar
square_enix
Newbie
Posts: 9
Joined: Wed Dec 31, 2003 2:03 am
Location: Hunt Town

Post by square_enix »

According to sources:
WOWK-TV also got it.


On Good News, SAZ's systems are slowly returning to an Online State.

"VIRUS WATCH 07" is hopefully over...
"Look at this place, fifty-thousand people used to live in this city, now it's a ghost town. I've never seen anything like it." : Captain Macmillan {In reference to Pripyat Ukraine}
whatchamacallit
Newbie
Posts: 6
Joined: Thu Feb 05, 2004 9:54 pm

Post by whatchamacallit »

Not sure who your sources are but as fas as i am aware of no WV media stations have been hit with this virus... all IT and engineering staff at WV Media stations were notified as soon as word got out that WSAZ-TV got hit... and everyone took a very proactive stance in light of this situation.

It is unfortunate that many news outlets that use enps and other hardware/software combinations that are forced to use older operating systems that Microsoft does not release patches in a timely manner.
User avatar
DosPrompt
Member
Member
Posts: 13
Joined: Thu Aug 18, 2005 9:10 am

Post by DosPrompt »

WOWK was NOT hit.. Just Rumor..
Cuz someone at WSAZ called them and told them what was going on..
Computer viruses Suck!
That 70's Employee
Member
Member
Posts: 30
Joined: Mon Dec 08, 2003 2:22 pm

Virus Story from FTV

Post by That 70's Employee »

Computer Virus causes Havoc at WSAZ

A vulnerability in Microsoft Windows operating system apparently allowed a potent virus to penetrate the computer systems at WSAZ (West Virginia).

It happened early Saturday morning just before "NewsChannel 3 Sunrise" went on the air at 6am.

According to information technology (IT) professionals at WSAZ, it appears a "zero day attack" is the source of the problems, affecting the station's critical systems.


According to Wikipedia, a zero day attack is "a computer threat that exposes undisclosed or unpatched computer application vulnerabilities. Zero-day attacks can be considered extremely dangerous because they take advantage of computer security holes for which no solution is currently available."

The systems affected include the station's graphics, closed captioning, and many other computer applications that help bring a newscast to air. Despite these hurdles, WSAZ still aired newscasts as scheduled Saturday at 6am and 6pm, although the latter was shortened from 30 to 18 minutes.

The vulnerability was announced on Wednesday, March 28. According to Microsoft, a "hole" in certain versions of Microsoft Windows could allow an attacker to remotely run programs on some computers if the user accesses certain websites that contain malicious code.

Right now, Microsoft has not released a fix for the vulnerability in its software.

The same attack has also caused significant issues at other television stations owned by WSAZ's parent company, Gray Television. A computer security website reports that this system flaw has reached "highly severe" status.

Despite the system problems, WSAZ will continue to bring you up-to-date, live newscasts.
Post Reply