PC Tools - Essential tools for your PC
Search
 
 
Features
 
 
Newsletter
 
Security Home > Windows NT, 2000 & XP

What You Should Know About the Windows Blaster Worm New Popular

A new worm known as W32.Blaster.Worm (also known as MBlaster, W32/Lovsan.worm, MSBlast, W32.blaster.worm, Win32.posa.worm, Win32.poza.worm) has been identified that is seeking to exploit the vulnerability that was addressed by a recent Microsoft Security Bulletin. Blaster is designed to launch a denial of service attack against Microsoft's Windows Update Web site.

Issue

Microsoft recommends taking the following actions immediately:

For System Administrators and Technical Computer Users

Read the PSS Security Response Team alert for technical guidance.

For Home Computer Users

If you are using Windows NT 4.0, Windows 2000, Windows XP, or Windows Server 2003, you should follow the steps in this sequence to help protect your system and to recover if your system has been infected.

  1. Make sure you have a firewall installed and activated to help protect your computer against infection, before you take other steps. If your computer has been infected, activating firewall software will help limit the effects of the worm on your computer.
    • If you have Windows XP or Windows Server 2003, follow these instructions to enable the Internet Connection Firewall.
    • If you have Windows NT 4.0, Windows 2000 or Windows XP, you will need to install a third-party firewall. Most firewall software for home users is available in free or trial versions.
    • Alternatively, if you use Windows 2000, you can take steps to block the affected ports so that your computer can be patched. Here are some modified instructions from the TechNet article HOW TO: Configure TCP/IP Filtering in Windows 2000.
      1. In the Control Panel, double-click Network and Dial-up Connections.
      2. Right-click the interface you use to access the Internet, and then click Properties.
      3. In the Components checked are used by this connection box, click Internet Protocol (TCP/IP), and then click Properties.
      4. In the Internet Protocol (TCP/IP) Properties dialog box, click Advanced.
      5. Click the Options tab.
      6. Click TCP/IP filtering, and then click Properties.
      7. Select the Enable TCP/IP Filtering (All adapters) check box.
      8. There are three columns with the following labels:
        • TCP Ports
        • UDP Ports
        • IP Protocols

        In each column, you must select the Permit Only option.

      9. Click OK.
  2. Download and install the security update addressed in Security Bulletin MS03-026 for the version of Windows that you are using from the Microsoft Download Center. When you click the appropriate link below, a dialog box appears. To begin the download process, do one of the following:
  3. Make sure you install and use antivirus software.
  4. If you think your computer has been infected, use the worm removal tool available at your antivirus vendor's Web site. For additional details on this worm from antivirus software vendors participating in the Microsoft Virus Information Alliance (VIA) please visit the following links:

    Learn about Microsoft's Virus Information Alliance.

Affected Products

  • Microsoft® Windows NT® 4.0
  • Microsoft Windows® 2000
  • Microsoft Windows XP
  • Microsoft Windows Server 2003

Further Details

Source: Microsoft Corporation

Updated: August 15, 2003

>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<

 
  Copyright © 1998-2008 PC Tools. All rights Reserved. Privacy Policy | Legal Notice