Scarthy © ® ™ Posted August 12, 2003 Report Share Posted August 12, 2003 Hi all ;),I have just had an update/ warning about this worm on BigFix. I usually don't think much to the 'advise', but I found this article about removing it and thought the forum might benefit (or some reader who has the misfortune of aquiring this 'nasty little blighter') from me reproducing it...Patch Your System with the appropriate MS03-026 PatchAfter Installation of the Patch, Reboot your system.Download and run "FIXBLAST.exe" to remove the MSBLAST.exe file, terminate the process and remove added registry keys by the worm.Reboot your pc one last time.Visit WindowsUpdate.com more often and take note of our repeated warnings to keep your system updated.Result:Your System will no longer shutdown after 60secs, please follow the steps above to remove the worm off your computer and return your system to UPDATED safe status.UPDATE: If your having problems installing the patch within the 60 sec, when you see the window pop up telling you 60 sec, Go to Start, Run and type in shutdown -a. This will cancel the shutdown attempt.Download>>>Windows XP Patch<<<>>>Windows 2000 Patch<<<Download>>>FixBlast - W32.Blaster.Worm Removal Tool<<<View - Symantec Security Response - W32.Blaster.Worm Removal ToolNews Source;)(might be worth 'pinning' this one ellas ;)) Quote Link to comment Share on other sites More sharing options...
Redhat Posted August 12, 2003 Report Share Posted August 12, 2003 Your best and most complete defense against the RPC exploit is running a personal firewall. http://www.zonealarm.comhttp://www.kerio.comhttp://www.sygate.com Quote Link to comment Share on other sites More sharing options...
Guest Nellie2 Posted August 12, 2003 Report Share Posted August 12, 2003 Guess what??...........I just had a phone call from a friend who has this worm! :( given her the link for a page which tells her about it and has a download for the fix. (Didn't see this post!!!) Trouble is, the worm keeps shutting her PC down so she can only get on line for a few mins at a time!!! :ph34r: Quote Link to comment Share on other sites More sharing options...
Guest LB Posted August 12, 2003 Report Share Posted August 12, 2003 strange that, one of my mates came to me at work today and said "I was using kazaa and shortly after i downloaded something my computer keeps shutting down after about 1 minute!!"mmm...i wonder! Quote Link to comment Share on other sites More sharing options...
Redhat Posted August 12, 2003 Report Share Posted August 12, 2003 Nellie tell her to : Start > Run type (without quotes) "shutdown -a" stops the shut down procedure. Quote Link to comment Share on other sites More sharing options...
mark2 Posted August 12, 2003 Report Share Posted August 12, 2003 Also close port 135 with her firewall too ! Quote Link to comment Share on other sites More sharing options...
Guest Nellie2 Posted August 12, 2003 Report Share Posted August 12, 2003 thanks Redhat........... I'll give her a ring now!! Quote Link to comment Share on other sites More sharing options...
Guest Nellie2 Posted August 12, 2003 Report Share Posted August 12, 2003 You won't believe this...........she isn't running a firewall :huh: I just gave her a lecture on firewalls and am emailing her some links..... and no she isn't blonde she is a redhead!!! Quote Link to comment Share on other sites More sharing options...
mark2 Posted August 12, 2003 Report Share Posted August 12, 2003 :blink: :blink: :blink: This nasty uses the same ports as messenger spam, has she never been troubled by that ?And is she now going to join us here for future help ? Quote Link to comment Share on other sites More sharing options...
Guest Shirley_Crabtree Posted August 12, 2003 Report Share Posted August 12, 2003 I "caught" this one yesterday.I wasn't using my firewall :o The shame of it!!I downloaded an mp3 off K***a and half an hour later I was watching The Simpsons and had left my pc connected (and msn messenger on).All of a sudden it restarted all on its own.I was immediately suspicious and downloaded Sygate Personal Firewall.I then had major problems with latency issues on Counterstrike,I was pinging around 400-450...So I took off Sygate :blink: but the problem persisted.I then put AVG on(OK OK,I KNOW!!!) but couldn't download the updates as my pc kept restarting!!!!To cut a long story short I reformatted the bloody thing,it was only my "b" hdd.I have now switched back to my "a" hdd which is fully secure (I hope :unsure: )Cheers.Shirl. Quote Link to comment Share on other sites More sharing options...
Guest Nellie2 Posted August 12, 2003 Report Share Posted August 12, 2003 Errr she is actually a member but hasn't been around for a while because she has been ill. She was troubled by the messenger spam but used your article to turn it off :) Quote Link to comment Share on other sites More sharing options...
Guest Shirley_Crabtree Posted August 12, 2003 Report Share Posted August 12, 2003 :blink: :blink: :blink: This nasty uses the same ports as messenger spam, has she never been troubled by that ?This is how,I suspect,it got onto my PC,I think the K***a bit was a coincidence.(sp?)I've noticed,over the last fortnight,hotmail spam has gone from 1 or 2 a day to 9 or 10 a day.....Our Chris accumulated 35 viagra and farm $ex emails in about 4 days recently and he's just 12!! (it's a good job I routinely rinse his mailbox with Mailwasher :rolleyes: Cheers.Shirl. Quote Link to comment Share on other sites More sharing options...
mark2 Posted August 12, 2003 Report Share Posted August 12, 2003 Possibly came in via K******* but when executed, it adds the value "windows auto update"="msblast.exe" to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\which then uses TCP port 135 that can exploit the RPC vulnerabilitty to allow the the worm to be downloaded and run .A check in the registry for the above key will tell if you still have a problemShirley Crabtree 35 viagra and farm $ex emails in about 4 daysis that all ? it is a bit much for 12yr old tho :blink: Quote Link to comment Share on other sites More sharing options...
Guest Shirley_Crabtree Posted August 12, 2003 Report Share Posted August 12, 2003 Just got this email from Blueyonder :-Dear customer,If you use Windows NT4, Windows 2000, Windows XP or Windows 2003 you may be at risk from a new virus known as MSBlaster. This virus exploits a known security issue with Windows operating systems. It can cause your computer to reboot and can also result in slow speeds whilst browsing the Internet.If you are running one of these operating systems please visit the Symantec website [http://www.sarc.com/avcenter/venc/data/w32.blaster.worm.html] where you can find further information, including instructions on how to remove this virus.You can also visit the Microsoft site [http://www.microsoft.com/security/security_bulletins/ms03-026.asp] to get the latest security updates.If you are having problems accessing either of these sites, or would like further information, please visit http://help.blueyonder.co.uk/blaster .As this is a Microsoft technical issue customers should contact Microsoft technical support for further information at http://support.microsoft.com .We strongly advise all customers to regularly update their anti-virus protection.We are taking all the steps we can to minimise the impact of this virus on your service and appreciate your help.Regards,the team at blueyonderCheers.Shirl. Quote Link to comment Share on other sites More sharing options...
Agent Smith Posted August 12, 2003 Report Share Posted August 12, 2003 This caused us some grief at work today as well. After setting up some fresh installs, we connected them to the external side of our router (normal procedure for the first critical updates prior to them getting the network client and being connected to the internal network), and within 30 seconds all 3 base machines we were working on became infected :smart: :( Bad luck I think. No K*****, no messenger, in fact no nothing except Win2000 and some drivers.Still for further reference, McAfee also have a few bits of information. NAI.comMr. M. Quote Link to comment Share on other sites More sharing options...
Inprofile Posted August 12, 2003 Report Share Posted August 12, 2003 Here's a list we've compiled over at the "other site": http://pcpitstop.ibforums.com/index.php?ac...=ST&f=9&t=20008We will be adding to it, as and when, new info/patches are available.Anyone with any new info on this worm can pm me and if useful will be added to the list for the benefit of all!Would have posted before, but some bugger deleted me when my pc was being rebuilt. :D Quote Link to comment Share on other sites More sharing options...
monkey Posted August 12, 2003 Report Share Posted August 12, 2003 my brothers work had 500 computers down because of itHackers is on tv now on s4c Quote Link to comment Share on other sites More sharing options...
Redhat Posted August 13, 2003 Report Share Posted August 13, 2003 Many ISP's should now start blocking port 135 from their end, to protect their users. It's quite possible for entire ISP's to go down because of this Worm. It's now catagory 4, you don't get that everyday. Quote Link to comment Share on other sites More sharing options...
Scarthy © ® ™ Posted August 13, 2003 Author Report Share Posted August 13, 2003 A family friend also has this worm. His neighbour also has it and because they use 'remote assistance' I believe it has crossed from one to the other...? It has messed with his dial-up connection. I have told him about this forum and in particular this thread. I hope to see him joining soon ;)I also noticed yesterday that just about every page that I tried to access on the internet gave me an error (Page Cannot Be Displayed...Site may be having difficulties etc etc blah blah blah...). This happened several time on certain sites. I wonder if this was due to the worm? I thought it might be the M$ patch, but all seems OK today....[touch wood] ;) Quote Link to comment Share on other sites More sharing options...
Scarthy © ® ™ Posted August 13, 2003 Author Report Share Posted August 13, 2003 Here is a copy of the BigFix message that I received...VIRUS: W32.Blaster.Worm The W32.Blaster.Worm virus is a worm that will exploit the DCOM RPC vulnerability in Windows (described in Microsoft Security Bulletin MS03-026, See below for details) using TCP port 135.This worm will attempt to download and run a file called Msblast.exe. We recommend that you always update your Virus scanner regularly.For more info about this virus click the link below:-Click HERE for more info on the W32.Blaster.Worm virus Click HERE for more info on DCOM RPC vulnerability;) Quote Link to comment Share on other sites More sharing options...
mark2 Posted August 13, 2003 Report Share Posted August 13, 2003 Here's how the infection spreadsAn infected machine (PC1) will scan blocks of IP address until it finds a PC that is unpatched (PC2). It then sends a command to PC2 to get it to download the virus from PC1. Virus installs and PC2 starts scanning for PCs to infect.Got a case to deals with at the weekend, a friend uses dial up once a month, told him this morning not to use the net until I'd checked and made sure his security up to date , too late !! he got it last night !! :smart: Quote Link to comment Share on other sites More sharing options...
Tankus Posted August 13, 2003 Report Share Posted August 13, 2003 Ive got it too ...just downloaded the fix.....My AVG is bang up to date and I have ZA always on..........Ive rebooted the comp aroung 5 time s now ...........I dont use Kazaa anymore ...I wonder how it got on mine....? Quote Link to comment Share on other sites More sharing options...
mark2 Posted August 13, 2003 Report Share Posted August 13, 2003 You don't have to do anything to get it (see above).Can ZA be configured to block certain ports ? If you can block TCP ports 135-139. Quote Link to comment Share on other sites More sharing options...
Boris Posted August 13, 2003 Report Share Posted August 13, 2003 Just occasionally I'm really glad I don't run the latest O/S as the Win9 family apparently aren't affected by this. Quote Link to comment Share on other sites More sharing options...
mark2 Posted August 13, 2003 Report Share Posted August 13, 2003 Boris , don't be so smug :D :D :D Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.