GetDotted Domains

Viewing Thread:
"msblast.exe"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Tue 12/08/03 at 16:02
Regular
Posts: 787
Last night I experianced something very strange - My computer kept on telling me there was an error with something and had to shutdown in 1 minute.

Turns out there's been a major security alert with NT based OS's and a virus has been spread to those who are vunrable. Luckily Zonealarm picked up 204 attempted "outgoing" connections from the application "msblast.exe" and told me to block the connection and download a patch from MS's site.

This is a warning to all XP user's - Check the "processes" list in task manager and see if ms blast is there.

****

"This worm spreads by exploiting a vulnerability in the RPC service for DCOM. This is described along with the fix for it in Microsoft Security Bulletin MS03-026. This affects the following systems; Windows NT 4, Windows 2000, Windows XP and Windows Server 2003. The worm also performs a Denial of Service (DoS) attack on the windowsupdate.com server.

The worm exploits vulnerability in DCOM RPC. It subsequently searches IP addresses and when it finds a vulnerable computer it uses the exploit to remotely run a shell which issues a command for downloading a copy of itself by TFTP. The copy of the worm is lunched directly after download.

When the worm is lunched it copies itself as a file named msblast.exe to the SYSTEM32 folder and registers msblast.exe as a windows auto update item in the following registry key

If your computer is infected by this virus, you will have to apply the Microsoft security patch available from this link:

microsoft.com/technet/security/bulletin/MS03-026.asp

Symptoms of the worms existence within a network (LAN):
- increased traffic on UDP port 69 (TFTP used by worm for downloading
- increased traffic on port 135 or 593 (worm sending data to try and exploit RPC for DCCOM)
- sudden system crashes reporting fault in RPC

Recommendation for network administrators is to disable outward access on ports 135 and 593 used by worm.

Virus also contains these texts:
I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ?
Stop making money and fix your software!!"


************

Heh. Clever - Yet scary.
Tue 12/08/03 at 16:02
Regular
Posts: 10,364
Last night I experianced something very strange - My computer kept on telling me there was an error with something and had to shutdown in 1 minute.

Turns out there's been a major security alert with NT based OS's and a virus has been spread to those who are vunrable. Luckily Zonealarm picked up 204 attempted "outgoing" connections from the application "msblast.exe" and told me to block the connection and download a patch from MS's site.

This is a warning to all XP user's - Check the "processes" list in task manager and see if ms blast is there.

****

"This worm spreads by exploiting a vulnerability in the RPC service for DCOM. This is described along with the fix for it in Microsoft Security Bulletin MS03-026. This affects the following systems; Windows NT 4, Windows 2000, Windows XP and Windows Server 2003. The worm also performs a Denial of Service (DoS) attack on the windowsupdate.com server.

The worm exploits vulnerability in DCOM RPC. It subsequently searches IP addresses and when it finds a vulnerable computer it uses the exploit to remotely run a shell which issues a command for downloading a copy of itself by TFTP. The copy of the worm is lunched directly after download.

When the worm is lunched it copies itself as a file named msblast.exe to the SYSTEM32 folder and registers msblast.exe as a windows auto update item in the following registry key

If your computer is infected by this virus, you will have to apply the Microsoft security patch available from this link:

microsoft.com/technet/security/bulletin/MS03-026.asp

Symptoms of the worms existence within a network (LAN):
- increased traffic on UDP port 69 (TFTP used by worm for downloading
- increased traffic on port 135 or 593 (worm sending data to try and exploit RPC for DCCOM)
- sudden system crashes reporting fault in RPC

Recommendation for network administrators is to disable outward access on ports 135 and 593 used by worm.

Virus also contains these texts:
I just want to say LOVE YOU SAN!!
billy gates why do you make this possible ?
Stop making money and fix your software!!"


************

Heh. Clever - Yet scary.
Tue 12/08/03 at 16:14
Regular
"Dont come here ofte"
Posts: 4,264
I have this virus, appeared from nowhere last night, there is coverage of it on bbc.co.uk also
Tue 12/08/03 at 16:22
Regular
Posts: 10,364
Valentino Rossi wrote:
> I have this virus, appeared from nowhere last night, there is coverage
> of it on bbc.co.uk also

Yeah - I got mine at about 10:45 last night.
Tue 12/08/03 at 16:29
Regular
"Eff, you see, kay?"
Posts: 14,156
I have a Linux gateway. Muagaaagaaahahaha.
Tue 12/08/03 at 16:35
Regular
"Dont come here ofte"
Posts: 4,264
I was using PC fine for an hour, then about 8.00pm it started, managed to back up alot of important stuff between shut downs :)
Tue 12/08/03 at 16:36
Regular
"Twenty quid."
Posts: 11,452
I had the "Shutting down in 60 seconds" thing last night - first thing I did was go to the Windows update site and download a couple of critical updates and make sure my McAffee was fully up to date. Hasn't happened since ...
Tue 12/08/03 at 17:30
Regular
"cachoo"
Posts: 7,037
Ho that's scary. Viruses scare the crap out of me. Starts the panic.

But speaking of viruses. Don't suppose anyone has heard of one called "Trickler" ?

It pops up every so often wanting to 'access the internet'. And I've 'never' seen anything called this before ever.
It's also in the Processes list in Task Manager.
Tue 12/08/03 at 17:40
Regular
"bing bang bong"
Posts: 3,040
Turbonutter wrote:
> I have a Linux gateway. Muagaaagaaahahaha.


*laughs with Turbonutter*

Those of you who have or have had the virus will need to reinstall Windows. You might be okay, but you'll never be sure without reinstalling.


I'm trying so hard to be sympathetic, I really am..
Tue 12/08/03 at 17:43
Posts: 2,131
Trickler? That's the Gator thingy that sneakily requests you install it. It usually comes with a program, and is a nightmare once you've installed it. Just remove it from startup and find out where the actual program is and you'll be fine.
Tue 12/08/03 at 17:44
Regular
"bing bang bong"
Posts: 3,040
Ms NY wrote:
> Ho that's scary. Viruses scare the crap out of me. Starts the panic.
>
> But speaking of viruses. Don't suppose anyone has heard of one called
> "Trickler" ?
>
> It pops up every so often wanting to 'access the internet'. And I've
> 'never' seen anything called this before ever.
> It's also in the Processes list in Task Manager.


Trickler is not a virus, but it's about as nasty a piece of **** as software can get. It's spyware/malware secretly installed by a variety of other programs without your being consulted. What it's doing when Zonealarm is catching it is trying to download yet another piece of spyware, and that other bit of software (I believe affiliated with GAIN/Gator) will get up to all sorts of mischeif.

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Unrivalled services
Freeola has to be one of, if not the best, ISP around as the services they offer seem unrivalled.
Continue this excellent work...
Brilliant! As usual the careful and intuitive production that Freeola puts into everything it sets out to do, I am delighted.

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre
Feedback Close Feedback

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.