This is topic New worm going around -W32.Blaster.Worm in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=002362

Posted by Michael Gonzalez (Member # 593) on 08-12-2003, 01:11 PM:
 
I hear that this worm had really been making the rounds lately despite the fact that a security patch has been available from Microsoft for over a month. I have my computer set up for automatic updates so I don't seem to have a problem with these but if you caught the worm, here is how you can remove it:

Norton has removal tool here

http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

Microsoft has a patch here (1-866-PC-Saftey)

http://www.microsoft.com/security/security_bulletins/ms03-026.asp

Systems affected

The following operating systems are affected by this vulnerability:
• Windows NT 4.0 Workstation
• Windows NT 4.0 Server
• Windows 2000 Professional
• Windows 2000 Server
• Windows 2000 Advance Server
• Windows XP Home
• Windows XP Professional
This security threat affects Windows 2000, NT, and XP and has recently been the subject of a security bulletin released by Microsoft. It is a vulnerability in a Windows Distributed Component Object Model (DCOM) Remote Procedure Call (RPC) interface which allows an attacker to gain full access and execute any code on a target machine, leaving it compromised.
Solution: Customers should install the security patch immediately and consider installing a firewall Customers with a firewall installed or who are running Operating Systems other than those listed above may see increased Internet traffic but will not be otherwise affected

ADVANCED USERS:
You can temporarily get around the issue by doing the following:

1.Go to administrative tools>services
2.Double click remote procedure call
3.Under the recovery tab, set all failure reactions to "Take No Action" and set "Reset failure count after" to zero [0] days.

Port numbers affected you can block are

tcp port 4444

tcp 135

udp 69
 
Posted by Adam Martin (Member # 641) on 08-12-2003, 04:34 PM:
 
I found out about this one this past weekend when I took my desktop home from work and used it on dialup without a firewall. Switching the RPC termination to "no action" and turning on XP's dialup firewall as stated above remedied the problem until I could download the patch.
 
Posted by Matthew Bailey (Member # 601) on 08-12-2003, 05:57 PM:
 
Once I tried to load the MS update & I had to use ctrl+alt+delete to inerrupt it because it either stalled or hung during downloading.
 
Posted by Ken Layton (Member # 133) on 08-12-2003, 06:04 PM:
 
So, Windows 98 is not affected? That's what I have.
 
Posted by Richard Thomas (Member # 1815) on 08-12-2003, 06:05 PM:
 
This is a bad deal. I have a firewall (Zone Alarm) and it is catching and blocking over 100 probes per hour just sitting there connected to the internet. If you have a open port and this thing finds it, you are likely to get infected. It is not like a worm that comes in an email requiring clicking; this baby just gets you if you are connected and things are just right. Nasty deal.
 
Posted by Tim Reed (Member # 137) on 08-12-2003, 07:27 PM:
 
Welcome, Richard!
 
Posted by John Walsh (Member # 168) on 08-12-2003, 07:30 PM:
 
I'm behind a Sonicwall firewall router/NAT, then ZoneAlarm. I wouldn't say I'm bulletproof, but doin' OK....
 
Posted by Joe Redifer (Member # 3) on 08-12-2003, 07:30 PM:
 
To find out if you have this worm, you must go to the TASK MANAGER and see if something called "msblast." is running. If so, you have the worm.

Why don't I have the worm? I can never get this stuff and my ports are all wide open!

Is this the worm that gives Microsoft hell by attacking their website somehow? Also, Michael... the link to Microsoft above does not go straight to the patch. You have to click around everywhere and suddenly you are engulfed in many many different critical updates. Which one is it? Boy, Windows sure seems to have a lot of security updates quite frequently. Every single update to their OS is to resolve a vunerability in security. Why does Microsoft program such crappy OS's with no beta testing, no debugging, and whatnot?

Mac OS is BETTER than Windows OS. Period.
 
Posted by Adam Martin (Member # 641) on 08-12-2003, 08:08 PM:
 
This one apparently affects NT/2000/XP/2003 OS's.

The patch will not apply properly if the worm is present on your system. Download the removal tool from the Symantec link above and it will scan your system, remove the affected files, and ask you if you want to go to the Microsoft page and download the patch.
 
Posted by Mitchell Cope (Member # 32) on 08-12-2003, 08:26 PM:
 
According to McAfee,
quote:
This worm spreads by exploiting a recent vulnerability in Microsoft Windows. The worm scans random ranges of IP addresses on TCP port 135. Discovered systems are targeted. Exploit code is sent to those systems, instructing them to download and execute the file MSBLAST.EXE from a remote system via TFTP.
If I'm interpreting this correctly, Microsoft may have recently added this vulnerability.

Indications of Infection:
* Presence of unusual TFTP files
* Presence of the file msblast.exe in the WINDOWS SYSTEM32 directory
* Error messages about the RPC service failing (causes system to reboot)
 
Posted by Paul G. Thompson (Member # 655) on 08-12-2003, 10:36 PM:
 
Now you know why I get so darned angry with the computers on DSL at the radio station. We have a simple peer-to-peer network and the computers are wide open for the probes that are inward bound. When a window pops up saying basically someone is trying to bust into the machine, the guys running the computers don't know what to do so they say "let it." [Embarrassed] [Mad] [Frown] [Roll Eyes]

To add insult to injury, they don't raise the firewall to block all traffic when they are done. They are idiots!!!!
 
Posted by Chris Hipp (Member # 1788) on 08-13-2003, 02:29 AM:
 
I got this worm yesterday I think, or at least I Started seeing symptoms of it. What would happen is about 10 minutes of being online I would get an error saying SVC Host synce error or somethign and then I couldnt load Java on any websites.

I installed the patch and it fixed it, I run win2000
 
Posted by Adam Fraser (Member # 1074) on 08-13-2003, 11:18 AM:
 
I have a friend who is a computer tech and I visited him yesterday at his store. He was in the process of fixing 3 or 4 at the same time and had fixed 15-20 by 3 PM. They are loving it, kind of makes me wonder if computer repair people make up these worms so they can charge $50-100 each to fix them. [Cool]
 
Posted by Richard Thomas (Member # 1815) on 08-13-2003, 01:37 PM:
 
Thanks for the kind welcome Tim! It is great to be here. [Big Grin]
 
Posted by Jack Ondracek (Member # 1466) on 08-13-2003, 04:49 PM:
 
Paul, don't you have some kind of router with a firewall after your DSL modem? You sure seem to get hit hard, & I'm wondering why your system has to be so open?????
 
Posted by Paul G. Thompson (Member # 655) on 08-14-2003, 02:21 AM:
 
Jack, the answer is no. And the boss does not want to spend the money to "tighten things down."
 
Posted by Scott Norwood (Member # 30) on 08-14-2003, 07:34 AM:
 
Paul--if your radio station uses an automation system, I can only hope that it is either a) not on a network and/or b) not running on Windows. [Eek!]
 
Posted by Adam Martin (Member # 641) on 08-14-2003, 12:46 PM:
 
Here is a Belkin Wireless 4 Port Cable/DSL Gateway Router at Micro Center Online. Four wired ports plus wireless. $59.99 - $40 rebate = $19.99. Mine should arrive tomorrow for the booth. Exactly how cheap is this guy? Hell, I'd buy the thing myself just to be able to quit removing viruses.
 
Posted by Paul G. Thompson (Member # 655) on 08-14-2003, 01:18 PM:
 
Scott, the automation system is on its own network. The owner wanted to put it on the DSL network so it could be "gotten into" from home in case of a mis-program glitch.

I told him he was nuts for even thinking about it. He says, "well my buddy does" to which my replay was "that's his problem - I am not gonna do it.".....

Adam, I felt the same as you about just buying one for him. But I decided to say "bullshit." When I have to buy a desk and a filing cabnit out of my pocket to store technical publications because there were not enough to go around, that's where I draw the line.

My workbench! HAH!!!!! What work bench?

Sunday I had to evict a family of bees that built their little house in a feedhorn of a satellite dish, his wooden ladder collapsed under my weight and I fell promptly to the ground. The rungs and supports of the ladder just splintered. I have been on his ass for at least a couple of years to buy a new ladder. So far, I have not seen one.

Adam, He is just too damn cheap and won't do it. He is so tight his ass squeaks when he walks.
 
Posted by Ian Price (Member # 14) on 08-14-2003, 01:36 PM:
 
We got it here at the Rialto.

Casey spent the better part of the day hunting it down and killing it.
 
Posted by Scott Norwood (Member # 30) on 08-15-2003, 08:04 AM:
 
Paul--good thinking with keeping the automation system on its own network...unless you wanted the programming to become more, um, "interesting. If he wants remote control capabilities, maybe direct-dial-in (perhaps with callback verification allowed only to a specific number) would be a better (though still not wonderfully secure) option.

It sounds like your station manager doesn't understand the issues involved with having unprotected Win32 machines on a public network, especially when they are being run by "untrusted" end users. What kind of CPE (router, bridge, etc.) do you have from the DSL provider? It may have some sort of limited packet filtering built into it. If it's a Cisco or Netopia box, get the root password for it and give me a call if you want help setting up some limited filtering (which won't stop people from downloading virii, etc., but is probably better than nothing).
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-11-2003, 07:23 PM:
 
FYI...

Released September 10, 2003:
http://www.microsoft.com/security/security_bulletins/ms03-039.asp
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2