GetDotted Domains

Viewing Thread:
"msblast.exe"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Tue 12/08/03 at 16:02
Regular
Posts: 787
Last night I experianced something very strange - My computer kept on telling me there was an error with something and had to shutdown in 1 minute.

Turns out there's been a major security alert with NT based OS's and a virus has been spread to those who are vunrable. Luckily Zonealarm picked up 204 attempted "outgoing" connections from the application "msblast.exe" and told me to block the connection and download a patch from MS's site.

This is a warning to all XP user's - Check the "processes" list in task manager and see if ms blast is there.

****

"This worm spreads by exploiting a vulnerability in the RPC service for DCOM. This is described along with the fix for it in Microsoft Security Bulletin MS03-026. This affects the following systems; Windows NT 4, Windows 2000, Windows XP and Windows Server 2003. The worm also performs a Denial of Service (DoS) attack on the windowsupdate.com server.

The worm exploits vulnerability in DCOM RPC. It subsequently searches IP addresses and when it finds a vulnerable computer it uses the exploit to remotely run a shell which issues a command for downloading a copy of itself by TFTP. The copy of the worm is lunched directly after download.

When the worm is lunched it copies itself as a file named msblast.exe to the SYSTEM32 folder and registers msblast.exe as a windows auto update item in the following registry key

If your computer is infected by this virus, you will have to apply the Microsoft security patch available from this link:

microsoft.com/technet/security/bulletin/MS03-026.asp

Symptoms of the worms existence within a network (LAN):
- increased traffic on UDP port 69 (TFTP used by worm for downloading
- increased traffic on port 135 or 593 (worm sending data to try and exploit RPC for DCCOM)
- sudden system crashes reporting fault in RPC

Recommendation for network administrators is to disable outward access on ports 135 and 593 used by worm.

Virus also contains these texts:
I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ?
Stop making money and fix your software!!"


************

Heh. Clever - Yet scary.
Fri 15/08/03 at 18:00
Regular
"\\"
Posts: 9,631
Miserableman wrote:
> Windows 98 would crash long before any RPC exploit got the chance

HAHAHAHA
Fri 15/08/03 at 17:49
Regular
"bing bang bong"
Posts: 3,040
Windows 98 would crash long before any RPC exploit got the chance
Fri 15/08/03 at 15:34
Regular
"Eff, you see, kay?"
Posts: 14,156
]-[ØM€® B€€® §ØL!!D wrote:
> Thanks a lot, so sometimes it pays not to update.


That is absolute BS, there isn't a single reason why Win98 should have even been created in the first place.
Fri 15/08/03 at 13:45
Regular
"Dont come here ofte"
Posts: 4,264
Exactly, I'd been using W98 until 5 weeks ago, got quite friendly with the blue screen by the end.
Fri 15/08/03 at 13:37
Regular
"the burning sky"
Posts: 4,984
gamezfreak wrote:
> ]-[ØM€® B€€® §ØL!!D wrote:
> I am a windows 98 user, is there any chance of me getting this
> virus,
> as by the sounds of it it can be very harmful to the system.
>
> Nope - Your ok mate :)
>
> The virus only affects NT based operating systems: -
>
> Windows NT
> Windows 2000
> Windows XP.

Thanks a lot, so sometimes it pays not to update.
Fri 15/08/03 at 11:25
Regular
Posts: 10,364
]-[ØM€® B€€® §ØL!!D wrote:
> I am a windows 98 user, is there any chance of me getting this virus,
> as by the sounds of it it can be very harmful to the system.

Nope - Your ok mate :)

The virus only affects NT based operating systems: -

Windows NT
Windows 2000
Windows XP.
Fri 15/08/03 at 11:09
Regular
"the burning sky"
Posts: 4,984
I am a windows 98 user, is there any chance of me getting this virus, as by the sounds of it it can be very harmful to the system.
Thu 14/08/03 at 18:30
Regular
"\\"
Posts: 9,631
From what ntl are doing this thing seems to be out of control. When your in the ntl guide it has a non stop loop of how to get rid of msblast.exe instead of all the movie adverts... worrying.
Thu 14/08/03 at 00:47
Regular
"Dont come here ofte"
Posts: 4,264
I finally got rid of it, Norton deleted 4 files :(, thanks to Tom's shutdown -a command,

Cheers :)
Wed 13/08/03 at 17:19
Regular
"\\"
Posts: 9,631
Mine shutdown after the update fine?

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Continue this excellent work...
Brilliant! As usual the careful and intuitive production that Freeola puts into everything it sets out to do, I am delighted.
Thanks!
Thank you for dealing with this so promptly it's nice having a service provider that offers a good service, rare to find nowadays.

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre
Feedback Close Feedback

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.