The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  MSBlast Patches and Fixes
Time: 15:48 EST/20:48 GMT | News Source: ActiveWin.com | Posted By: Alex Harris

Here is the information about the Worm and fixes and removal tools to remove the virus:

PSS Security Response Team Alert - New Worm: W32.Blaster.worm [Microsoft]

WHAT IS IT?

The Microsoft Product Support Services Security Team is issuing this alert to inform customers about a new worm named W32.Blaster.Worm which is spreading in the wild. This virus is also known as: W32/Lovsan.worm (McAfee), WORM_MSBLAST.A (Trendmicro), Win32.Posa.Worm (Computer Associates). Best practices, such as applying security patch MS03-026 should prevent infection from this worm. Customers that have previously applied the security patch MS03-026 before today are protected and no further action is required.

TECHNICAL DETAILS:

This worm scans a random IP range to look for vulnerable systems on TCP port 135. The worm attempts to exploit the DCOM RPC vulnerability patched by MS03-026. Once the Exploit code is sent to a system, it downloads and executes the file MSBLAST.EXE from a remote system via TFTP. Once run, the worm creates the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "windows auto update" = msblast.exe I just want to say LOVE YOU SAN!! bill

Symptoms of the virus: Some customers may not notice any symptoms at all. A typical symptom is the system is rebooting every few minutes without user input. Customers may also see:

  • Presence of unusual TFTP* files
  • Presence of the file msblast.exe in the WINDOWS SYSTEM32 directory

To detect this virus, search for msblast.exe in the WINDOWS SYSTEM32 directory or download the latest anti-virus software signature from your anti-virus vendor and scan your machine.

Here are links to the patches to stop this worm attacking again:

Windows XP

Windows 2000

If you already have the worm on your PC and you need to remove it then here is the information and links to the Symantec site:

W32.Blaster.Worm Removal Tool [Symantec]

Symantec Security Response has developed a removal tool to clean the W32.Blaster.Worm infections.

What the tool does:

  • Terminates the W32.Blaster.Worm viral processes.
  • Deletes the W32.Blaster.Worm files.
  • Deletes the dropped files.
  • Deletes the registry values that the worm added.

You can download the removal tool from here.

Obtaining and running the tool

  • Download the FixBlast.exe file from: http://securityresponse.symantec.com/avcenter/FixBlast.exe
  • Save the file to a convenient location, such as your downloads folder or the Windows Desktop (or removable media that is known to be uninfected, if possible).
  • To check the authenticity of the digital signature, refer to the section, "Digital signature."
  • Close all the running programs before running the tool.
  • If you are running Windows XP, then disable System Restore. Refer to the section, "System Restore option in Windows Me/XP," for additional details.
  • CAUTION: If you are running Windows XP, we strongly recommend that you do not skip this step. The removal procedure may be unsuccessful if Windows XP System Restore is not disabled, because Windows prevents outside programs from modifying System Restore.
  • Double-click the FixBlast.exe file to start the removal tool. Click Start to begin the process, and then allow the tool to run.
  • NOTE: If, when running the tool, you see a message that the tool was not able to remove one or more files, run the tool in Safe mode. Shut down the computer, turn off the power, and wait 30 seconds. Restart the computer in Safe mode and run the tool again. All the Windows 32-bit operating systems, except Windows NT, can be restarted in Safe mode. For instructions, read the document "How to start the computer in Safe Mode."
  • Restart the computer.
  • Run the removal tool again to ensure that the system is clean.
  • If you are running Windows XP, then re-enable System Restore.
  • Run LiveUpdate to make sure that you are using the most current virus definitions.

I know this is a very long post, but from work today at PC World in the UK we created discs with the removal tool and patch on it and had at least 30 people throughout the day come in saying they had this, so it is very widespread. Please note if you have already installed the patch MS03-06 then you are already protected.

Write Comment
Return to News

  Displaying 151 through 154 of 154
Prev | First
  The time now is 6:48:23 AM ET.
Any comment problems? E-mail us
#151 By 4240821 (193.36.231.111) at 7/1/2024 7:22:37 PM
https://sexonly.top/get/b160/b160vbnbkwapgcifaeh.php
https://sexonly.top/get/b666/b666hbcpkpkaswedeek.php
https://sexonly.top/get/b606/b606cqzqaxlnasvuppo.php
https://sexonly.top/get/b700/b700ljymqxwayjmcnob.php
https://sexonly.top/get/b45/b45ukjtnapgkydranl.php
https://sexonly.top/get/b168/b168zoygifdaxejcuky.php
https://sexonly.top/get/b70/b70siimmhuaxvhqvdg.php
https://sexonly.top/get/b250/b250qgkgceniefmidzj.php
https://sexonly.top/get/b121/b121szrmrehlurbycnc.php
https://sexonly.top/get/b108/b108ptyixdjbbhojipj.php

#152 By 4240821 (193.36.231.111) at 7/2/2024 10:58:19 AM
https://sexonly.top/get/b944/b944acbkpmmxvicsisp.php
https://sexonly.top/get/b32/b32mxzrlzxksqnjngt.php
https://telegra.ph/Sandra-Ackermann---Berlin--Berlin--Germany-11-20
https://sexonly.top/get/b372/b372ccawwwsdmegnndv.php
https://sexonly.top/get/b127/b127uimxxcsezpwfxps.php
https://sexonly.top/get/b428/b428cxcvlijentwlmzz.php
https://sexonly.top/get/b368/b368dgksxolxoacojgr.php
https://telegra.ph/Lisa-Black---Jackson--Mississippi--USA-01-06
https://sexonly.top/get/b540/b540jigszfgkitxekrr.php
https://sexonly.top/get/b122/b122ieeqzcxmzjogozf.php

#153 By 4240821 (193.36.231.111) at 7/3/2024 7:43:30 AM
https://sexonly.top/get/b718/b718yohoghhegoimqbe.php
https://smutty.com/s/uDKLH/
https://sexonly.top/get/b171/b171yrmgzgnlndfreqq.php
https://sexonly.top/get/b749/b749jbgwvetmgnyoywr.php
https://sexonly.top/get/b371/b371ehndnotnvblkiry.php
https://sexonly.top/get/b124/b124osxbsiukemonaox.php
https://sexonly.top/get/b850/b850bkiyqieuglktzdy.php
https://telegra.ph/LanaRhoades-Foot-Clips4sale-Leak-12-21
https://sexonly.top/get/b486/b486jwrxiwponniomxa.php
https://sexonly.top/get/b954/b954efphbbzenefgdeh.php

#154 By 4240821 (193.36.231.111) at 7/3/2024 7:24:16 PM
https://sexonly.top/get/b870/b870cdauflcjubweclz.php
https://sexonly.top/get/b434/b434gwaslyswwcneytt.php
https://sexonly.top/get/b812/b812lrvdrnussqkbuqn.php
https://sexonly.top/get/b118/b118tamiakqivfzvozn.php
https://sexonly.top/get/b554/b554wzhtsnmzkkuadvv.php
https://sexonly.top/get/b152/b152mvqzzsdjyddmgrf.php
https://sexonly.top/get/b491/b491rhuxpnflzmxlvag.php
https://sexonly.top/get/b574/b574dhlpfrfjllprkkn.php
https://sexonly.top/get/b966/b966retxfmlfragxhoi.php
https://sexonly.top/get/b993/b993ffhmnppjlmesiqx.php

Write Comment
Return to News
  Displaying 151 through 154 of 154
Prev | First
  The time now is 6:48:23 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *