|
|||||
| Support: Security: PC Sentry: MSBlast | |||||
|
name: MSBlast aka: W32.Blaster.worm, Lovsan, Poza type: Worm host platform: Windows first Incidence: 08/11/03 last incidence: 08/20/03 level of incidence: High damage capacity: Medium links: McAfee, Norton look for: - The file msblast.exe in the WINDOWS SYSTEM32 directory - msblast.exe in Task Manager - Unusual TFTP* files - Computer repeatedly shutting down and starting back up. - Error messages about the RPC service failing (causes system to reboot) - 20 sequential TCP ports for listening in fixed range (eg., 2500-2520, 2501-2521, 2502-2522). The worm affects Windows 2000 and XP machines that have not patched the Buffer Overrun In Windows RPC Interface. Unlike most viruses and worms, MSBlast does not use email (and email attachments) as the means for spreading the infection. Instead, using an already infected machine, the worm randomly scans the Internet for unpatched systems. When such a system is found, it is infected and then used as an agent for furthering the infection. Green Apple has disabled ingress/egress on ports used by MSBlast as
recommended by Microsoft which greatly lessen the capability for the worm to
enter or leave our network and, thus, affect our users. However, every Windows
user is urged to visit Microsoft's Windows Update and install the patch to
close the RPC Buffer Overrun flaw. Windows Update is found at If you are infected, besides installing the patch, you will need to remove
the worm. Symantec (Norton) has developed a tool for this: For other sources, please see
|
|||||
|
|