Port 4444 is used after you are infected. The initial point of attack is tcp 135, then once infected the virus will listen on udp 69 (tftp server) and 4444 tcp (remote shell) for instructions.
For those of you who aren't using firewalls, sorry to say it, but you're BEGGING for this sort of crap to happen, as well as folk to jump onto your shared directories and play silly buggers with your hard drive.
Get a firewall. Now. Go download Zonealarm from http://www.zonelabs.com/ or SOMETHING.
Don't run your computer on the 'net without a firewall.
I'm friggin allergic to ZoneAlarm, since it fucked up all my networking. Kept getting "Transmit error code 65" or something like that when I tried pinging. couldnt even send files via MSN. Was a hair away from formatting my entire system when I was FORCED to try the microsoft support site, where they had an article saying that the problem was ZoneAlarm (which was disabled by the way). All better now, but never EVER touching ZoneAlarm again. Get something different.
I think i may have got the virus as my computer was doing the same thing. But as i didn't think it was a virus and is was only happening when i had my comp on the home network i ran the network setup wizard and it fixed it. (probably as it turned my firewall on as i had it off so i could play Generals online).
Hmm scanned for viruses used the latest AVG and found nothing.
dl it from here http://securityresponse.symantec.com/avcenter/FixBlast.exe
u might wanna read these instructions before u run the fix tool tho http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
If you just applied the patch and didnt remove the actual virus, then on the 16th of this month, it is going to launch a DDoS attack on windowsupdate.com
Alot of "low lifes" that make virus's are people who have found security flaws, gone to MS and been told to piss off so they think, well why not prove it.
Hey just for those people that might unfortunately get the virus...you might alrerady know this but it worked for a friend, and its just something i hope will help someone out :)
when you can boot up goto Start --> run and type "shutdown -a" without the ""
you all prbably knew it but like i said anything to help and it worked for a mate, he had time then to delete the virus :)
shit looks liek alot of u peopel got it o well teach ya's all a lesson i supose lucky its not too harmfull
but anywyas if i was the creator of this program and saw all these threads sayign shit i got it and blah blah i bet he is in the biggest orgasmic state atm lol oliek look how many GU members got it alone imaging how many got it in australia and anywhere else for that matter i dont think these peopel who make things liek this are very nice but i recon WD to this bloke cause his went a fair way in one day :P
Heh... thanks a lot guys! I'm heaps lucky, since my computer is hidden behind a hub :) so I don't need a firewall or anything (which is excellent, firewalls are annoying). However a few of my friends have got this, so I downloaded "FixBlast" and I'll go help them (girls, of course...).
As a last note, ZoneAlarm IS really crap. One of my friends has it (gamer), and he keeps saying "Oh ZoneAlarm just stopped like 527 attacks on my computer" (not 527, but is a lot, like 19 or something) and I say: "Um, people have better lives then to keep attacking your computer... you'll find that they're port scanners" - ZoneAlarm blows!
lol yesturday i got 3 peopel on msn saying shit its dixssconnection every second so i helped fix 3 and them flam last night lol o well hopefully it goes away soonish
Yeah i think my alcatel speed touch pro telstra modem ( :oops: ) has a built in firewall that drops everything thats going through ports i havent specified to be open, so im lucky :) .
It took me a long time to realise that, I was wondering why the hell i couldnt host diablo II games for like a year :? .
Quote from Unseen: I've been a busy boy today :) and most probs tomorrow aswell lol yeah i was thinking today shit i wonder how margret and bill are coping with all these people comming in saying my computer is doing thins and this and arrhh god lol so kurt mck issues with this?
supose its good for techs tho casue it takes 5 min to fix and then u charge them the fee to lok at it so easy money for busneiss
Quote from BrAiN DaNcE: If you just applied the patch and didnt remove the actual virus, then on the 16th of this month, it is going to launch a DDoS attack on windowsupdate.com
Just letting people know :P what is all this about robbie?
If the current month is after August, or if the current date is after the 15th, the worm will perform a DoS on Windows Update. The worm will activate the DoS attack on the 16th of this month, and continue until the end of the year.
windowsupdate.com is going down in 3 days :twisted:
I need help. MS fix for this evil virus doesn't install on my pc. It says it needs SP2 or higher to install and I have SP2. I re-installed SP2 again and it is still saying the same crap. I don't know what to do, for now I'm going to panic and run around in circles like a headless chicken.
Quote from Symantec: Calculates a random IP address, A.B.C.0, where A, B, and C are random values between 0 and 255.
NOTE: 40% of the time, if C > 20, a random value less than 20 will be subtracted from C.
Once the IP address is calculated, the worm will attempt to find and exploit a computer on the local subnet, based on A.B.C.0. The worm will then count up from 0, attempting to find and exploit other computers, based on the new IP.
So once youve got it you send it to pretty much random people across the internet, very wild and quite well designed as everyones already seen :roll: Good thing it doenst do anything serious like format your c drive or something or there would be a lot of people seriously screwed right now.
Quote from Odyssey: I need help. MS fix for this evil virus doesn't install on my pc. It says it needs SP2 or higher to install and I have SP2. I re-installed SP2 again and it is still saying the same crap. I don't know what to do, for now I'm going to panic and run around in circles like a headless chicken.
Bet you sure wish you had installed SP4 when I said it was out and advised so ;)
Anyway my server has it and that's as far as it's got on my network however. Although I've got another 6 machines to fix for my friends now too.
dl it from here http://securityresponse.symantec.com/avcenter/FixBlast.exe
u might wanna read these instructions before u run the fix tool tho http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
LOL I noticed on the page for the fix that ME isnt affected, guess whoever made the worm figured there were already enough problems with ME as it is :lol:
A few of the medical centres around darwin got hit too, RDH being one.. Poor Unseen, having to drive around and fix all the problems.. hehehehehe, better you than me dude ;)
its my understanding that DOS based OS's (95/98/ME) aren't infected by the virus because it was made to enter a machine via a port that is, by default, opened by the NT based OS's, does that sound right? or am i totally thinking of the wrong thing??
My brother got the damn virus i had no idea what it was and couldn't connect to the internet to find out, so i hooked up an old machine that had not been connected to the net ever b4 and within 2mins it too had the virus. I put the modem in my comp (still didn't know wat it was) connect to the internet and i didn't end up getting the virus.. ran the patch on my machine then to my bros and yeah works fine now. I think i found that if ur windows xp isn't on the automatic updates or u dont update, u most probably will get the virus :)
exodus, who cares wat it does as long as it works :)
Omg all these people on the radio with the "how you fix it" solutions, that require a "clean computer" with a burner, a cd, and the blood of 3 virgins...
seriously, if you have it, kill it in your processes, find and delete the exe, and then get the patch... stupid newspaper, they were all like.. it's a catch 22 you can't fix it, you should bring it to us and we'll charge you $200 to get rid of this impossible conundrum, in like 3 minutes :P
As you know, newspaper journos have a habit of twisting the words/meaning to make a story. In the end of the article it even suggests for users to give it a go first.
It is kind of a "catch 22" in the sense that many basic users can't download the patch before the shutdown counter starts. Most customers I recommend getting the patch for an alternative source first, as this is the most easy to explain over the phone.
As a more advanced computer user, most of us can find ways around the worm attack reboot issue, it like shutdown -a during the countdown or reconfigure RPC not to autoreboot on failure. Obviously I've been carrying the patches around with me today, but if the customer is up to it, I will always suggest a cheaper/better way to fix their computer themselves.
Most nontechnical (computer illiterate) customers find it easier to get expert advice or onsite assistance - or at the least the dozen or more different customers I attended today thought so and are happy to pay for.
Quote from Harbinger: seriously, if you have it, kill it in your processes, find and delete the exe, and then get the patch... stupid newspaper, they were all like.. it's a catch 22 you can't fix it, you should bring it to us and we'll charge you $200 to get rid of this impossible conundrum, in like 3 minutes :P
It's not the msblast process that makes the computer reboot. It's because the worm is shoddily written, and when a REMOTE computer attempts to use the wrong exploit against you (ie, the Win2k exploit against a WinXP machine), the forged packets make the RPC process die, thus your computer reboots.
Solutions include turning RPC to not reboot on failure, unplugging from the network, etc etc etc.
Killing msblast.exe just stops YOU from spreading the virus to more people, it doesn't stop your computer from rebooting.
We should all be thankful this virus isnt much more leathal, It could have been, very very easily. The exploit used in the virus allows a remote CMD shell to be opened.
When I was troubleshooting this comp, (not mine, flatmates) I rebooted, and watched the processes, and sure enough, as soon as it was on the internet, there was a cmd.exe showing up in the list. That is scary, access to all files, reboots, bios flashing, you name it. It could have all been done.
Dont get me wrong, the person who did this is still a turd, but he could have been an utter asshole.
And now with the code being dissasembled and spread arround, it wont be long before all the 1337 script kiddies get there hands on it and add a simple "format c: /u"
We should all be thankful this virus isnt much more leathal, It could have been, very very easily. The exploit used in the virus allows a remote CMD shell to be opened.
When I was troubleshooting this comp, (not mine, flatmates) I rebooted, and watched the processes, and sure enough, as soon as it was on the internet, there was a cmd.exe showing up in the list. That is scary, access to all files, reboots, bios flashing, you name it. It could have all been done.
Dont get me wrong, the person who did this is still a turd, but he could have been an utter asshole.
And now with the code being dissasembled and spread arround, it wont be long before all the 1337 script kiddies get there hands on it and add a simple "format c: /u"
Yep, Darkwolf is spot on. The msblast.exe process doesn't cause the shutdown on the local machine, instead it means that particular attempt/attack from the net was unsuccessful in infecting you.
Some customers I find get infected first, next comes the shutdown due to RPC flaw. Others shutdown first and no infection.
The concern is those who are still infected with the worm, have no AV software but have only applied the MS patch. The MS patch itself doesn't kill any virus !!
In this case the shutdown issue is fixed and they think they are all ok, but they are still spreading the worm and set to participate in this DOS attack on Sat.
Also keep an eye out for teekids.exe and penis32.exe and any other variants.