Blaster Computer Virus
Discovered on: August 11, 2003
Systems infected: Windows 2000, Windows XP.
Systems not infected: Linux, Macintosh, OS/2, UNIX, Windows 95, Windows 98, Windows Me, Windows NT.
W32.Blaster.Worm is a worm that exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. The worm targets only Windows 2000 and Windows XP machines. While Windows NT and Windows 2003 Server machines are vulnerable to the aforementioned exploit (if not properly patched), the worm is not coded to replicate to those systems. This worm attempts to download the msblast.exe file to the %WinDir%\system32 directory and then execute it. W32.Blaster.Worm does not have a mass-mailing functionality.
Patches and fixes:
To protect you from this worm download and install the following patch:
Microsoft patch 823980 (Windows 2000 and XP only)
Related News:
According network security researcher, it took virus writers only 32 days to produce the Blaster Windows worm after a patch was announced for it. California, USA, April 2004.
Available Cleaner/Removal: Microsoft Zapper
|