W32.Blaster.worm

Off Topic Discussion - Chat about anything, just keep it fairly clean.

Moderator: snoopdog

Post Reply
User avatar
snoopdog
Yellow Tang
Posts: 4258
Joined: Mon Feb 17, 2003 7:37 pm
Are you a Bot ?: No
Location: Mobile, Al
Contact:

W32.Blaster.worm

Post by snoopdog »

Considering the fact that this sucker infected my laptop from a remote source and the number of machines that came into the office today this is one mean sucker. There was alot of talk of it yesterday as IT and Admin work alot of overtime handling the support calls. Anyway here is a fix for it and a description.
Based on the number of submissions received from customers and based on information from the Symantec's DeepSight Threat Management System, Symantec Security Response has upgraded this threat to a Category 4 from a Category 3 threat.

W32.Blaster.Worm is a worm that exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. This worm attempts to download and run the Msblast.exe file.

Block access to TCP port 4444 at the firewall level, and then block the following ports, if they do not use the applications listed:


TCP Port 135, "DCOM RPC"
UDP Port 69, "TFTP"

The worm also attempts to perform a Denial of Service (DoS) on Windows Update. This is an attempt to prevent you from applying a patch on your computer against the DCOM RPC vulnerability.

Click here for more information on the vulnerability that this worm exploits, and to find out which Symantec products can help mitigate risks from this vulnerability.

NOTE: This threat will be detected by virus definitions having:
Defs Version: 50811s
Sequence Number: 24254
Extended Version: 8/11/2003, rev. 19
http://securityresponse.symantec.com/av ... .tool.html
"When they was no meat we ate fowl, when there was no fowl we ate crawdad. And when there was no crawdad to be found, we ate sand."--Cellmate
"You ate what?"--H.I.
"We ate sand."--Cellmate
"You ate sand?"--H.I.
"That's right."--Cellmate
User avatar
Scott
Goby
Posts: 2495
Joined: Wed Feb 19, 2003 9:00 pm
Are you a Bot ?: No
Location: West Mobile
Contact:

Post by Scott »

How about a little of that in English? How do you know if you have it?
Wanted: to set up a tank again.
User avatar
snoopdog
Yellow Tang
Posts: 4258
Joined: Mon Feb 17, 2003 7:37 pm
Are you a Bot ?: No
Location: Mobile, Al
Contact:

Post by snoopdog »

Your computer will just "reboot" constantly, normally happens if you are on a static connection like DSL or cable, but could happen on dial-up. Also predominate with 2000, or Win XP.
"When they was no meat we ate fowl, when there was no fowl we ate crawdad. And when there was no crawdad to be found, we ate sand."--Cellmate
"You ate what?"--H.I.
"We ate sand."--Cellmate
"You ate sand?"--H.I.
"That's right."--Cellmate
User avatar
ShagMan
Goby
Posts: 2145
Joined: Fri Feb 21, 2003 3:41 pm
Location: Mobile, AL
Contact:

Post by ShagMan »

We had to reload our laptop due to this bugger yesterday. It would kill the RPC service, causing a forced reboot. Had to burn our stuff to CD's in safe mode and then reformat/reinstall. Nasty.
-Josh Murrah
User avatar
SaltnLime
Chromis
Posts: 1514
Joined: Tue Mar 04, 2003 10:49 pm
Location: Mobile
Contact:

Post by SaltnLime »

does norton recognize that bug yet?
"Well......maybe I did get alittle carried away! "
User avatar
snoopdog
Yellow Tang
Posts: 4258
Joined: Mon Feb 17, 2003 7:37 pm
Are you a Bot ?: No
Location: Mobile, Al
Contact:

Post by snoopdog »

It is listed as a known threat so as long as you are updated then yes.
"When they was no meat we ate fowl, when there was no fowl we ate crawdad. And when there was no crawdad to be found, we ate sand."--Cellmate
"You ate what?"--H.I.
"We ate sand."--Cellmate
"You ate sand?"--H.I.
"That's right."--Cellmate
User avatar
Melissakins
Bristleworm
Posts: 610
Joined: Tue Mar 11, 2003 1:44 pm
Location: Bay Minette

Post by Melissakins »

Here's something you might try:


Windows 2000 Patch:
http://microsoft.com/downloads/details. ... laylang=en


Windows XP Patch:
http://microsoft.com/downloads/details. ... laylang=en[/url]

Or run a Windows update: Start button, Window's update, etc...
"You can say any fool thing to a dog, and the dog will give you this look that says, `My God, you're RIGHT! I NEVER would've thought of that!'" - Dave Barry

40 gallon tall
15 gallon refugium
2.5 gallon mantis tank
Post Reply