Get Sp1 And Update Now!

If you haven't had a good reason to update your version of WindowsXP to SP1, now you've got it: DCOM RPC attacks through a host of sneaky worms. This weekend I got hit by W32/Lovsan.worm and although it was easy to remove, it was easier to avoid: Stay current with your free MS Windows updates.

The DCOM RPC security exploit has reached critical in under a week. Viruses like Code Blue, a Code Red varient, W32/Lovsan.worm and Win32.Poza (among others) exploit your systems unpatched service, then replicate like crazy, setting up a remote shell on TCP port 4444, and downloading a host of other .exe's to spread the love. Believe me, it's not a fun worm, because the leading symptom is an error in the RPC causes your system to restart about every few minutes, making backing up, downloading updates and other necessary measures damn near impossible.

Get SP1 and get yourself fully updated now!

#46785

me too, i got infected by it, but its ok, i cleaned it and ill reformat in a different time.

thanks for the tip, dizzy.

#46787

True but know matter how many service packs you apply antivirus and firewalls are the real protection.....

My reason..

I have used computers for 28 years, the internet/bulletin bourds for 16 year and have only had 1 virus..

#46788

A buch of guys here at work got nailed...

It's real easy to clean, just an anoyying pain in the a$$.

Now they all listen to me when I tell them to load firewall software on their desktops.

My log files in Zone Alarm Pro were getting pretty huge with blocked requests.

To clean, just go to your system32 dir and nuke the file MSBLAST.EXE.

You may have to kill it in task manager first.

Then delete the following reg key it sets up.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msblast.exe

Then run the MS03-026 patch on your PC.

Problem solved.

As of this afternoon McAfee and Norton have updates to detect the file.

EDIT: It's a post SP1 fix so SP1 alone will not take care of the issue, but it is a prerequisite for the patch.

#46794

"EDIT: It's a post SP1 fix so SP1 alone will not take care of the issue, but it is a prerequisite for the patch. "

No it's not, I dont use sp1, but the patch loaded fine, and can be seen in add/remove.

I think I was one of the first 10 people to upload an msblast.exe to SARC.

#46809

Where do you get this virus from? P2P? Email?

I am not noticing any symptoms, but I just want to make sure im not at risk.

Actually, this was the first time ive used Windows since I reinstalled 3 weeks ago. :lol:

#46820

yeah, where'd you get the virus from?

I better warn my younger siblings..

#46832

Well, I was already all patched up (I updated when I reinstalled) and my AV definitions looked good. I should be OK.

Customary Plug:

thank god I use Linux almost all the time. (sorry. :shy: )

#46836

Hear Hear!

_ALLWAYS_ have your OS, and AntiVirus program fully updated.

#46896

This virus has spread like a wildfire. Every single on of my friends had this. I was saved because of my firewall and antivirus programs.

#46898

I didn't get hit, but I think that's because I'm securely behind my University LAN-net firewall.

I never realized that being on this crappy "Res-Net" actually had its benefits. A-freakin-mazing. lol

#46918

Three Drives, you are correct.

SP1 is not required, but it is recommended.

The only issue would be that if you installed the patch before you installed SP1, you would have to remember to re-install the patch after updating to SP1.

The patch is considered a post SP1 patch. See info in reg key.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB823980

#46925

What I've come to notice is that a good Firewall system should properly protect you from Blaster. For example, Blaster tries to run a portscan on your connection before actually trying to infect you. Most Firewall software should pick up that activity and block that address from sending anything to you. Well, at least my Norton Personal Firewall did. Of course, its always a good idea to patch yourself up, im just saying that a Firewall appears to help.

Ive seen my friend get this worm actually. He was just talking on AIM when all of a sudden a box pops-up from windows saying that the "RPC Remote Procedure Call Service" has been shut off, and to prevent further damage to system, it will now shut off. about 30secs later (you get a countdown too) it totally shuts down. Really weird stuff. Either way though not very kewl.

Symantec's Security Response has raied W32.Blaster.Worm to a category 4 worm. This means its only getting worse people! Here are some links, first to the article from Symantec, and then a link to Symantec's Removal Tool for getting rid of this in case you already have it.

W32.Blaster.Worm Article

W32.Blaster.Worm Removal Tool

#46962

If I may throw it in here,

Outpost

has a free version as well that should serve almost everyone fine.

And the "Pro" version is the best Firewall around (well at least not worse than any other) PLUS it features ad-stopping, pop-up blocking and a whole freakshow of nice add-ons including plug-in support (there are a few written already).

Be safe,

McTrinsic

#47073