Blaster Worm Alert

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • WildmanJoe
    Super Member
    Super Member
    • Jan 2003
    • 283

    Blaster Worm Alert

    For uses of:
    * Microsoft Windows NT 4.0
    * Microsoft Windows 2000
    * Microsoft Windows XP
    * Microsoft Windows Server 2003

    The W32/Blaster worm exploits a vulnerability in Microsoft's DCOM RPC interface. Upon successful execution, the worm attempts to retrieve a copy of the file msblast.exe from the compromising host. Once this file is retrieved, the compromised system then runs it and begins scanning for other vulnerable systems to compromise in the same manner. In the course of propagation, a TCP session to port 135 is used to execute the attack. However, access to TCP ports 139 and 445 may also provide attack vectors and should be considered when applying mitigation strategies. Microsoft has published information about this vulnerability in Microsoft Security Bulletin MS03-026.

    Gain technical skills through documentation and training, earn certifications, and connect with the community


    If you have recently had abrupt restarts/crashes following some generic error message, use the following link to fix:

  • BoF
    Moderator
    • Nov 2001
    • 954

    #2
    You'r right WildmanJoe, that's not a joke and I can thank my firewall to protect one of my computer - that has been infected - from external remote control - gloups.

    edit: as usual, it creates a processus (a service based on /system32/msblast.exe) that is started via the Run registry Key. see msconfig and regedit to purge.
    Last edited by BoF; 13 Aug 2003, 12:50 AM.
    [www.scandiumrecords.com][Logan dataspirit]

    Comment

    • WildmanJoe
      Super Member
      Super Member
      • Jan 2003
      • 283

      #3
      I noticed that there were only 20 views for this post (at the time of this repost) and I hope that other people out there would take note of this worm.

      Tough luck BoF, having let the virus through under unforseen circumstances... then again I wasn't really much better off. I had the WinXP firewall that did crap.

      Comment

      • chickeneater
        Digital Video Expert
        Digital Video Expert
        • Apr 2002
        • 672

        #4
        I saw another post like this in the BCP forums. I don't bother with that stuff. I don't care for all I do. Norton does everything for me
        FFDShow filters
        Guliverkli's Media Player Classic

        Comment

        • WildmanJoe
          Super Member
          Super Member
          • Jan 2003
          • 283

          #5
          There's this Chinese saying... "If one doesn't see the coffin, one does not cry" which translate to: Unless it happens to you, one usually doesn't bother.

          Just for your information (FYI) Norton and other antivirus softwares cannot detect this worm.

          ChickenEater, you may be good at Divx-related stuff but don't get complacent. There are a lot of things that Norton CANNOT do.

          Comment

          • Batman
            Lord of Digital Video
            Lord of Digital Video
            • Jan 2002
            • 2317

            #6
            The bugs in MS ose's just keep getting scarier

            Comment

            • UncasMS
              Super Moderator
              • Nov 2001
              • 9047

              #7
              symantec has already released a removal-tool:

              Symantec security research centers around the world provide unparalleled analysis of and protection from IT security threats that include malware, security risks, vulnerabilities, and spam.

              Comment

              • chickeneater
                Digital Video Expert
                Digital Video Expert
                • Apr 2002
                • 672

                #8
                HA.

                thanks UncasMS
                anyway, i'm not sure about YOUR norton, but mine certainly has never let me down. ever.
                FFDShow filters
                Guliverkli's Media Player Classic

                Comment

                • Enchanter
                  Old member
                  • Feb 2002
                  • 5417

                  #9
                  Better safe than sorry, chickeneater...

                  Comment

                  • crazyman
                    Member
                    Member
                    • Feb 2003
                    • 56

                    #10
                    I some times get an error when going to shutdown or restart that says an error about rcpss is this also related to this bug?

                    Comment

                    • WildmanJoe
                      Super Member
                      Super Member
                      • Jan 2003
                      • 283

                      #11
                      Yes it is related, Crazyman. Random shutdowns/restarts are symptoms of this worm.

                      Btw chickeneater, I don't use Norton...

                      640K ought to be enough for anybody - Bill Gates

                      Comment

                      • BoF
                        Moderator
                        • Nov 2001
                        • 954

                        #12
                        Originally posted by WildmanJoe
                        Yes it is related, Crazyman. Random shutdowns/restarts are symptoms of this worm.
                        there are 2 behaviours:
                        1.when YOU shutdown or reboot your computer, you randomly get an error. (the process can't terminate correctly). it's not necessary a worm or a virus - I presonnaly believe windows enough strong to corrupt itself!
                        2.you randomly get an error while using your pc: stay connected to internet x seconds then crash (the worm doesn't wait for user orders )
                        [www.scandiumrecords.com][Logan dataspirit]

                        Comment

                        • MPS
                          Digital Video Enthusiast
                          Digital Video Enthusiast
                          • Mar 2003
                          • 358

                          #13
                          finally! an advantage of having win98

                          Comment

                          • chickeneater
                            Digital Video Expert
                            Digital Video Expert
                            • Apr 2002
                            • 672

                            #14
                            dude... I got checked with norton, and it didn't find anything...
                            FFDShow filters
                            Guliverkli's Media Player Classic

                            Comment

                            • Batman
                              Lord of Digital Video
                              Lord of Digital Video
                              • Jan 2002
                              • 2317

                              #15
                              Supposedly, the "latest" version of the MSBLASTER worm prevents M$'s patch from installing, leaving a complete format as the only option of disinfecting a system.

                              Comment

                              Working...