Support our advertisers!
Spacer

Fastener Spacer
 Spacer
Local Links
Spacer
  My Account   Green Apple Logo   Check Email
Global Search
Spacer
Spacer
Green Apple Ohio High Speed Internet Local Links Web Hosting Web Site Designers Technical Support Job Opportunities Contact Us Navigation Bar
Spacer
Support: Security: PC Sentry: MSBlast
  
name: MSBlast
aka: W32.Blaster.worm, Lovsan, Poza
type: Worm
host platform: Windows
first Incidence: 08/11/03
last incidence: 08/20/03
level of incidence: High
damage capacity: Medium
links: McAfee, Norton
look for:
- The file msblast.exe in the WINDOWS SYSTEM32 directory
- msblast.exe in Task Manager
- Unusual TFTP* files
- Computer repeatedly shutting down and starting back up.
- Error messages about the RPC service failing (causes system to reboot)
- 20 sequential TCP ports for listening in fixed range (eg., 2500-2520, 2501-2521, 2502-2522).

The worm affects Windows 2000 and XP machines that have not patched the Buffer Overrun In Windows RPC Interface.

Unlike most viruses and worms, MSBlast does not use email (and email attachments) as the means for spreading the infection. Instead, using an already infected machine, the worm randomly scans the Internet for unpatched systems. When such a system is found, it is infected and then used as an agent for furthering the infection.

Green Apple has disabled ingress/egress on ports used by MSBlast as recommended by Microsoft which greatly lessen the capability for the worm to enter or leave our network and, thus, affect our users. However, every Windows user is urged to visit Microsoft's Windows Update and install the patch to close the RPC Buffer Overrun flaw. Windows Update is found at
    http://windowsupdate.microsoft.com

If you are infected, besides installing the patch, you will need to remove the worm. Symantec (Norton) has developed a tool for this:
    http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

For other sources, please see
    CNET: http://reviews.cnet.com/4520-6600_7-5062389.html?tag=news-rr
    CNN: http://www.cnn.com/2003/TECH/internet/08/16/microsoft.blaster.ap/index.html
    ABCNews: http://abcnews.go.com/wire/US/ap20030816_738.html
   CERT: http://www.cert.org/advisories/CA-2003-20.html

 


Home / Access / Development / Support / Hosting / Local Links / Computers
 Contact Us / Green Apple News / Jobs / Site Map / Link To Us / Policy

Lancaster-Fairfield County Chamber of Commerce, 2000 Small Business of the Year
www.greenapple.com
· tel. (740) 653-9890 · toll free. (866) 653-9890
Copyright © 1995 - 2007, Green Apple, Inc.