Protecting yourself from the MSBlast worm
Published: 12 Aug 2003 10:15 BST
A new worm scans Internet to find vulnerable Windows 2000, NT, and XP systems
MSBlast, also known as Lovsan, is an Internet worm that exploits a known vulnerability in Windows 2000, NT, and XP. The worm takes advantage of the Distributed Component Object Model (DCOM) Remote Procedure Call (RPC) interface, which was patched in MS03-026, on 17 July, 2003. Because many people have yet to patch their systems, the worm is very active. MSBlast spreads quickly via the Internet and could damage infected system files, therefore, this worm rates a 7 on the ZDNet Virus Meter.
How it works
MSBlast does not spread via email. Instead, it scans the Internet on port 135 looking for vulnerable computers. When it finds one, it attempts to exploit the DCOM RPC buffer overflow, create a remote root shell on TCP port 4444, then use FTP to download a file called msblast.exe onto the infected computer.
At this time, antivirus vendors are still analyzing what msblast.exe does.
MSBlast updates the system Registry with the following line so that it will run each time the computer is rebooted.
Hkey_local_machine\software\Microsoft\Windows\CurrentVersion\ Run "windows auto update" = msblast.exe I just want to say LOVE YOU SAN!! Bill
Prevention
Users who have not yet patched their Windows 2000, NT, and XP systems should do so.
Windows NT 4.0 Server
Windows NT 4.0 Terminal Server Edition
Windows 2000
Windows XP 32-bit Edition
Windows XP 64-bit Edition
Windows Server 2003 32-bit Edition
Windows Server 2003 64-bit Edition
Removal
A few antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, F-Secure, McAfee, Symantec, and Trend Micro.
Full Talkback thread
97 comments
-
help - i am running windows 2000 and when I clik o... Anonymous -
It appears that my computer may have already been... Anonymous -
my computer has problems and i think it has b... Ishaya Gajere -
When I try to run the XP 32 bit patch it tells me... Duane Schowiak -
Since microsoft update doesn't work, why doesn't m... Anonymous -
Is it the case that MSBlast does not affect system... DIck Lawrence -
this worm is the first bug/virus that i have! it w... Anonymous -
I believe the person or persons who do this ought... Anonymous -
wat if u have windows MILLENIUM FERIDUNAK -
What is MSBLAST.EXE-09FF84F2.pf
it is in my C:\W... Anonymous -
Further to comment by Dick Lawrence, I have Win 98... Anonymous -
i have the worm virus on my computer and i have fo... edward stanley -
I had the virus MSBLAST. Norton Antivirus 2002 was... Mark Kempner -
Windows ME is not affected. It is only NT based sy... Jason -
It won't you fetch updates from Mirosoft site (and... Wish -
It's a bit difficult to download the patch once in... Paul Scholefield -
I am having trouble downloading the firewall from... Kat -
www.grisoft.com the free AVG software caught and s... Robin Jackson -
I have Windows ME and it is not on your list for p... Anonymous -
If you previously had the virus before you patched... Anonymous -
i cant remove the blast worm with any tool or anti... Ehab M. Mostafa -
We are also experiencing a lot of SVCHOST.EXE erro... Anonymous -
I'm unable to stay online long enough to download... Anonymous -
MS Blast is cleaned off my hard drive, but this va... Bryan -
what was the registry edit under hkey local machin... deborah mckown -
When you see the pop up window that is telling you... Kevin Dyer -
well u all better watch it, i no a gang of guys th... Anonymous -
I would like to know the phone number to call
if y... Anonymous -
I have another computer which seems to be infected... Anonymous -
Was able to get through to the Microsoft sight yes... Brendan Moran -
WATCH IT GUYS some guys called VG got a code copy... Cisco -
He doesn't want to worry about the virus. He shoul... The Headmaster -
i have XP and the instructions are to complicated.... delly bad -
This particualr file can be deleted without a prob... Damian Rees -
HELP!I have XP and i cant tell if im 32-bit or 64-... Michael Fossey -
I used Windows 98 computer to download XP security... Mike Miller -
Help: I want to load the patch against Mblast but... Mike Tebbitt -
How do you know if you have 32 or 64 bit XP. Esme Bunce -
Do i need to download if i am using windows ME????... Pamela -
hi i am using windows 98 so do i need to run the m... Anonymous -
is ms blast the same as peopsystem or joesustem th... Anonymous -
Avg sucks use Norton Its the best just keep it upd... Anonymous -
go into the control panel and into display. look... Anonymous -
Please could you advise me where I can get the pat... Anonymous -
hi i was wondering how do i find out how my pc has... emma -
here is a direct link to the windows xp 32bit patc... Nick -
here is a direct link to microsoft website 4 the b... Nick -
windows xp home edition is 32bit and windows xp pr... Anonymous -
This new virrus does not attack Windows 98 so ther... Anonymous -
i have windows xp but how do i know if i have the... Anonymous -
I downloaded the e-mailed instructions dated 88/15... Anonymous -
A friend of mine has problem with his pc. when he... Marife Cariaga -
dont know whitch xp patch to use. running xp pro.... Anonymous -
i have windows 2000ME and when i download your pat... Anonymous -
I am running windows millenium which was already o... Anonymous -
i have just got new pc not sure if 32bit or 64 i a... Anonymous -
i just got rid of this nasty beggar!!!!
type http:... anon -
ha ha ha.sorry i shouldnt laugh but im glad i run... thehornet_1 -
http://vil.nai.com/vil/stinger/ is the actual site... MJH -
does anyone know if the blaster worm will affect w... Anonymous -
i HAVE A computer with window98 and ever thing two... Anonymous -
How do i know if i have got the virus?what will it... Anonymous -
Window,s Me is not infected by this worm,But you s... Larry -
how do i know if my xp is 32bit or 64? Anonymous -
I have the same problem.This whole virus scare is... Laura Keates -
im having that trouble too help me 32 bit or 64 bi... joanne -
i have been told that this virus has been latched... bill flynn -
my computer have this problem as nfected by this v... Anonymous -
how do i know if my xp is 32bit or 64? andi -
click on my computer, go in to local drive, then w... karl corner -
I think that it could be made a bit easier to find... concerned user -
I have Windows '98 but seem to have all the sympto... Caz -
Trying using anti - virus program PC-CILLIN, this... paul chapman -
i would like to try the protections against viruse... charles stewart -
Unable to get rid of worm blaster. Keep closing co... Anonymous -
HELP!!How can I get on to the internet while havin... I.T -
Dont worry about the MSBLAST.EXE-09FF84F2.pf file... Anonymous -
Hi, usual question from a technophobic but how do... Rebeka -
Yes, it seems my computer's caught the worm as wel... Yiin Tham -
I have problem inwindows after 5 mint windows is c... Anonymous -
Go to www.evesham.com where you will find a compre... Gilson Chapple -
I have windows millenium every time i reboot... Anonymous -
go to norman antivirus and download trial software... stephen -
To stop your computer shuting down try typing "shu... Kate -
I deleted msblast from windows task manager proces... Kate -
I tried removing msblast using avg and once it was... Kate -
I see I am not the only one getting an error messa... Melissa Ballenger -
I have a severe problem..going through some old un... Travis Gibeaut -
What a really anoying virrus one minute browsing t... Michael Shellshear -
IF UNABLE TO GET RID OF BLAST WORM E-MAIL ME @ msh... Michael Shellshear -
I Ran the Blaster removal tool from Symantec, and... Anonymous -
i cant remove iciba programs in add and romove pro... dowson tay -
First I have noticed so much garbage out here sinc... Kathy Garcia -
i want to update my current anti virus Anonymous -
I have Windows XP. When on the web, I hear a fog... jsbj -
Help. Please!
I have AVG anti virus (Free Edition... Dr. Pedro Rodriguez -
Norton SUCKS NORTON SUCKS my brothers friend had i... Anonymous






