Subliminal Visions Subliminal Visions

msblast.exe ---> worm/virus?

msblast.exe ---> worm/virus?

I have noticed that the application, msblast.exe has been clogging my internet connection and causing a fatal exception/reboot of my system.

According to my ISP the problem is a vulnerability in Windows OS/possible worm. Microsoft is supposed to be working on a fix.

So BEWARE! The Trivial Transfer Protocol is being used to send this file/worm. To check if this file is on your system restart in safe mode, delete the file msblast.exe (Windows/system32), and open msconfig to uncheck the startup of this file. Block Trivial Transfer (tftp.exe) in your firewall as well.

I hope this helps anyone who is having this problem. If anyone else has a better fix please post it here!
13,975 views 36 replies
Reply #26 Top
Please read AND HEED post #20.....thankyou.
Reply #27 Top
Yes, let’s stop the non-sense. This thread was made to create awareness of the recent worm to those that have come across the problem and don’t know what's causing it. It also serves to instruct those that got the worm how to remove it.
Bickering in this message board about how Windows is 'no good' or how, where, when and why people launch virus is not going to solve anything.
Reply #28 Top
Hey everyone, thanks for the info. I had a friend who uses dial up who was actually dinged by this and that link to that removal tool is exactly what she needed.

Thanks again!

… oh, and macrobaye, yes there have been serious holes in Apple and Linux products, I’ve patched a few of them myself. What you have to put into perspective is this: The number of virus writers is directly proportional to the number of people that the virus can affect. With the Windows operating system populating something like 90% (or higher) of the desktop market, there’s pretty much no reason to hunt down disruptive exploits that could be used in DoS style attacks because you’re not gonna get much notoriety with an audience that small, nor are you going to be able to make a huge impact with your DoS attack (or what have you) either. If either Apple or Linux had the bazillion users that Windows did than I’d bet everything that I own that you’d see some pretty serious exploits found there as well, because you’d have hundreds of thousands (millions ?) of would-be hackers and script kiddies hunting this stuff down on a daily basis like we see in the Windows environment.
Reply #29 Top
Kona: Please no personal attacks. If you can sit there and say that you're not annoyed by all the BS you've had to put up with as a Windows user, you will now become the most tolerant person I know. So please, I wasn't attacking any of you, nor did I make any distasteful or improper comments. So please mind your manners. There's no reason to get mad at me over a few comments made on a public message boad.
it was not a attack. put simplely if you do not like it, do not use it. And I do love windows. I LOVE XP!

that
Reply #30 Top
Actually, it seems this worm was intentionally written to promulgate quickly and gather attention, likely to make a very noticeable point about the RPC vulnerability rather than bring down the net (although evidently some cable companies had some of their equipment hit and outages resulted). Unlike malware previously spotted on the net which exploits this same vulnerability and was propagating slowly under the public's radar. Clearly this worm could have done something far more malicious to its victims' systems had the designer wanted it to.

With the other exploits already in the wild but moving slowly, those who went without firewalls and were unpatched could blithely go on without any notice that there was a real threat sneaking up on them. This msblaster (aka lovesan) brought a rather noticeable end to many people's unawareness of this vulnerability and the need to get patched and protected (some sort of port filter).

As one of the early spotters and identifiers of msblaster noted, this worm blew the cover under which other similar exploits were going unnoticed except by some security professionals. And some think that was quite intentional and a part of the point the designer wished to make.

Now far more people are aware and patched. Because no doubt this won't be the last time that such an exploit will be attempted and next time the malware may not be as "benign" toward its victim's PC's or the internet.
Reply #31 Top
In this day and age, it's OK to be pacifist. And if you think we should all subscribe to the same school of thought, then you should get out more. The world is a big place, with a variety of different cultures and ways of thinking. I happen to be anti-violent and pacifist. If you want to hate me for that, look up the word "hypocritical", and you'll find a good description of yourself.

I'm sorry for bringing all this up in this thread.

I think the admins should setp in when someone is getting picked on by other members. We are a community. let's all act like one. So Anthony, NO THREATS.
Reply #32 Top

Moderator hat on.....

 

Please stay on topic.

 

Moderator hat off.

 

[this is supposed to work...but I'm yet to be convinced]

Reply #33 Top
Just remember macrobyte, any 12yo skript kiddie can download a root kit and own a linux box in 2 minutes.

Yes, Linux etc. have their flaws just like Windows does.

The user base being more massive and widespread makes virii and the such much more of a big deal, as seen by the number of people here that have been affected by it.

Make sure you take that all into consideration before you go and sling crap at Windows. Your crap dosen't smell any better.


And FYI, the "critical update" that fixes this issue is over a week old.

Keep those boxes up to date or run automatic updates if you run a LAN with Windows machines, it'll save you alot of headaches.
Reply #34 Top
i'm just gonna shut up, seeing that no one really cares what other people with conflicting wiews say. If it doesn't follow the norm, them ignore it...right? that's your philosophy? anyways, this will be my last post in this thread on one condition:

If I see anything like "thank god" or anything demeaning towards me or what I posted, I will be forced to back up what I said. So it is now up to all of you whether to stay on topic, or to rile me up a bit. choose wisely.
Reply #35 Top
#34 by macrobaye - 8/12/2003 11:26:53 PM i'm just gonna shut up,




Reply #36 Top

I'm locking this thread. 

The personal attacks have gone on too long.

To everyone involved, please refrain from this in the future.