# msblast.exe WTF?!?!?!?!?!

**URL:** https://boards.straightdope.com/t/msblast-exe-wtf/194466
**Category:** Factual Questions
**Created:** [August 11, 2003, 7:59pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466 "2003-08-11T19:59:26Z")
**Posts on this page:** 20
**Page:** 3

<div class="post-metadata">

### Author: ![Boo\_Boo\_Foo](https://avatars.discourse-cdn.com/v4/letter/b/e274bd/32.png) [@Boo\_Boo\_Foo](https://boards.straightdope.com/u/Boo_Boo_Foo)
#### Post date: [August 12, 2003, 11:11am UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/41 "2003-08-12T11:11:58Z")

</div>

My personal experience today with 3 mission critical web servers was that if you disabled the Internet Information Service, (not just stopped it, but actually disabled it so that it wouldn’t fire back up again after a reboot) and then rebooted those webservers, you could then work on the internet downloading all of the appropriate patches and Service Packs that you felt were necessary.

Caveat: My 3 webservers were WIN2K machines, one was a development machine running “Professional” and the other two are commercial servers running “Advanced Server”.

Shutting down the IIS functions disallows the “msblast worm” to successfully impregnate itself into a mission critical OS program which is already loaded into RAM which is called svchost.exe

My personal experience showed that there was no real effective way to keep your IIS functioning after the worm had impregnated itself into the svchost.exe’s memory space. You could try stopping the RPC service and the IIS and WWW Publisher services but no success sadly.

I actually have log files which show examples of the GET /.hash URL hits. I used “NEOTRACE” to search where these hits were coming from. Without exception, Bangkok and Manilla. GO figure. I guess a lot of porn webservers are based in those countries I’m thinking.

In closing? We had about 2 hours in total off air for our particular mission critical web database functions. Could have been worse with hindsight.

My personal belief is this - regardless of whether you’re running NT4.0, or 2000, or XP Advanced Server - I suspect that if your machine had been configured to NOT provide the IIS functions, then such machines would have been immune I rather think. However, once the worm was impregnated, your machine’s ability to send OUT nasty worm hits to other innocent machines might have been compromised.

---

<div class="post-metadata">

### Author: ![China\_Guy](https://avatars.discourse-cdn.com/v4/letter/c/779978/32.png) [@China\_Guy](https://boards.straightdope.com/u/China_Guy)
#### Post date: [August 12, 2003, 11:16am UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/42 "2003-08-12T11:16:16Z")

</div>

> [@](#):
>
> \*Originally posted by voltaire \*  
> **You can blame it on the numerous security holes in various Microsoft products. When Microsoft becomes aware of the exploit they usually supply a “Critical Security Update” through their website and Windows Update. One of the problems with this is that when they come out with a security update, they practically advertise the fact that there’s a vulnerability to all the hackers out there. Then the hackers focus their efforts on using the vulnerability on all the systems out there that haven’t been patched yet.**

To be fair to Microsoft, there is a Justice Department consent order that requires Microsoft to disclose vulnerabilities. Microsoft has no choice in the matter. Once disclosed, then this can be an illuminated bullseye for hackers to go after.

Keep your patches up to date people. The Slammer vulnerability had been patched about 6 months and then service packed months before that one hit.

---

<div class="post-metadata">

### Author: ![Boo\_Boo\_Foo](https://avatars.discourse-cdn.com/v4/letter/b/e274bd/32.png) [@Boo\_Boo\_Foo](https://boards.straightdope.com/u/Boo_Boo_Foo)
#### Post date: [August 12, 2003, 11:34am UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/43 "2003-08-12T11:34:47Z")

</div>

> [@](#):
>
> \*Originally posted by fruitbat \*  
> \*\*I have been infected. I am waiting to hear from my company’s tech support before installing the patch. While farting around trying to fix the problem though I may have done something inadvertently. I can’t open any link that would normally open another browser window. Is this an effect of the virus? Or did I mess something up trying to fix the virus? \*\*

That particular symptom was a direct result of the program called svchost.exe becoming infected in RAM. The file itself was not infected, merely the version loaded into RAM - and it’s the core program which is the basis of the Remote Procedure Call software - which is the mother program to a HELL of a lot of other services - ergo it really is quite a crippling blow to a webserver.

---

<div class="post-metadata">

### Author: ![hybrid\_dogfish](https://avatars.discourse-cdn.com/v4/letter/h/a587f6/32.png) [@hybrid\_dogfish](https://boards.straightdope.com/u/hybrid_dogfish)
#### Post date: [August 12, 2003, 11:45am UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/44 "2003-08-12T11:45:10Z")

</div>

Dont know whats going on, but when i just tried to connect to the windows updates, the server was not responding. Fortunately i got the updates yesterday, but i have to wonder if the reason the server is not responding is:

a)so many ppl trying to get the updates at the last minute (just about as effective as an automate DoS attack)

b)Microsoft taking it offline for a while so they can protect it from an upcoming DoS

c)The W32.Blaster.Worm starting it’s attack

d)Microsoft’s general incompetance and/or a temporary glitch.

---

<div class="post-metadata">

### Author: ![hybrid\_dogfish](https://avatars.discourse-cdn.com/v4/letter/h/a587f6/32.png) [@hybrid\_dogfish](https://boards.straightdope.com/u/hybrid_dogfish)
#### Post date: [August 12, 2003, 11:46am UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/45 "2003-08-12T11:46:21Z")

</div>

sorry, just managed to connect (after 30 mins of trying) guess i answered my own question, a)

---

<div class="post-metadata">

### Author: ![Tomcat](https://avatars.discourse-cdn.com/v4/letter/t/8e8cbc/32.png) [@Tomcat](https://boards.straightdope.com/u/Tomcat)
#### Post date: [August 12, 2003, 12:56pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/46 "2003-08-12T12:56:45Z")

</div>

Ooooh! I’m hit! Medic!

I managed to to delete the msblast while not connected to the internet, then I renamed a text file msblast.exe and stuck it in the temp folder, and that seemed to hold off the service downloading a new copy of it until I could get Trend’s stand alone downloaded and applied. What a pain! When PC-cillian was deleting the virus it was also deleting the TFTP folders and such, so I would assume that **Anthracite** wins the level-headedness award for the day. Apply the fix, apply the patch and I’m betting we’re all going to be safe. No way am I re-formatting my drive.

-Tcat

---

<div class="post-metadata">

### Author: ![Carnac\_the\_Magnificent](https://avatars.discourse-cdn.com/v4/letter/c/ccd318/32.png) [@Carnac\_the\_Magnificent](https://boards.straightdope.com/u/Carnac_the_Magnificent)
#### Post date: [August 12, 2003, 1:09pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/47 "2003-08-12T13:09:14Z")

</div>

> [@](#):
>
> \*Originally posted by Tomcat \*  
> \*\*Ooooh! I’m hit! Medic!
> 
> I managed to to delete the msblast while not connected to the internet, then I renamed a text file msblast.exe and stuck it in the temp folder, and that seemed to hold off the service downloading a new copy of it until I could get Trend’s stand alone downloaded and applied. What a pain! When PC-cillian was deleting the virus it was also deleting the TFTP folders and such, so I would assume that **Anthracite** wins the level-headedness award for the day. Apply the fix, apply the patch and I’m betting we’re all going to be safe. No way am I re-formatting my drive.
> 
> -Tcat \*\*

Agreed. Anthracite rocks.

---

<div class="post-metadata">

### Author: ![wmfellows](https://avatars.discourse-cdn.com/v4/letter/w/c2a13f/32.png) [@wmfellows](https://boards.straightdope.com/u/wmfellows)
#### Post date: [August 12, 2003, 3:36pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/48 "2003-08-12T15:36:30Z")

</div>

Thanks for the advice provided.

A note of amusement - if the file date on the Worm correctly suggests when it infected my system  
it hit when I was downloading updates from MS!! Indeed it appears that I was infected as I was pulling down the updates.

---

<div class="post-metadata">

### Author: ![Early\_Out](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@Early\_Out](https://boards.straightdope.com/u/Early_Out)
#### Post date: [August 12, 2003, 3:42pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/49 "2003-08-12T15:42:21Z")

</div>

It’s certainly a busy little worm today. I’m on a dialup, so I never bothered installing a firewall. This outbreak indicates that that’s no longer very safe, so I downloaded and installed ZoneAlarm. It’s getting port 135 hits several times a minute!!

Sure glad I retired a few years back (I used to be a sysadmin/LAN manager type guy). The next week or two are going to be ugly.

---

<div class="post-metadata">

### Author: ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)
#### Post date: [August 12, 2003, 3:52pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/50 "2003-08-12T15:52:46Z")

</div>

I got nailed with this yesterday, after I installed Earthlink. At first I thought it was on the Earthlink CD itself, but now I suspect that the IP address Earthlink gave me happened to be one that the worm scans for. I got hit within minutes of connected to the Earthlink network. It’s gone now, and the patch has been installed.

---

<div class="post-metadata">

### Author: ![Super\_Gnat](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@Super\_Gnat](https://boards.straightdope.com/u/Super_Gnat)
#### Post date: [August 12, 2003, 4:16pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/51 "2003-08-12T16:16:47Z")

</div>

Well, I had it, took it off with the Stinger, but the svchost.exe file just crashed again :(. I guess I better get the patches.

---

<div class="post-metadata">

### Author: ![wmfellows](https://avatars.discourse-cdn.com/v4/letter/w/c2a13f/32.png) [@wmfellows](https://boards.straightdope.com/u/wmfellows)
#### Post date: [August 12, 2003, 4:32pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/52 "2003-08-12T16:32:43Z")

</div>

> [@](#):
>
> \*Originally posted by Early Out \*  
> It’s certainly a busy little worm today. I’m on a dialup, so I never bothered installing a firewall. This outbreak indicates that that’s no longer very safe, so I downloaded and installed ZoneAlarm. It’s getting port 135 hits several times a minute!!

Question, how do I check on such things if at all via Win XP’s own firewall - which seems to be working fine by the way, thanks again.

---

<div class="post-metadata">

### Author: ![Frylock](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Frylock](https://boards.straightdope.com/u/Frylock)
#### Post date: [August 12, 2003, 4:43pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/53 "2003-08-12T16:43:53Z")

</div>

How can I know if my svcshost.exe file was affected? I don’t seem to have any of the symptoms, but I don’t see why my computer would not have been affected in this way while most people’s were…

-FrL-

---

<div class="post-metadata">

### Author: ![neutron\_star](https://avatars.discourse-cdn.com/v4/letter/n/51bf81/32.png) [@neutron\_star](https://boards.straightdope.com/u/neutron_star)
#### Post date: [August 12, 2003, 4:59pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/54 "2003-08-12T16:59:15Z")

</div>

> [@](#):
>
> \*Originally posted by wmfellows \*  
> \*\*Question, how do I check on such things if at all via Win XP’s own firewall - which seems to be working fine by the way, thanks again. \*\*

See Microsoft’s page, [Internet Connection Firewall security log file overview](http://www.microsoft.com/windowsxp/home/using/productdoc/en/default.asp?url=/windowsxp/home/using/productdoc/en/hnw_firewall_log_understanding.asp).

**Frylock** : I don’t know if you could tell if that particular file was affected. Note that it’s supposedly only changed after being loaded into RAM, so if you just search for that file on your system and look at the modified dated, that won’t tell you.

If you’ve installed the patch, you’re fine. Don’t worry about it. Why weren’t you affected? Well, does Windows Update download updates automatically on your computer? If so, maybe you were already patched and didn’t even know it. If not, there’s always the possibility that the range of IP addresses yours is part of wasn’t scanned by attackers.

---

<div class="post-metadata">

### Author: ![istara](https://avatars.discourse-cdn.com/v4/letter/i/e79b87/32.png) [@istara](https://boards.straightdope.com/u/istara)
#### Post date: [August 12, 2003, 5:51pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/55 "2003-08-12T17:51:07Z")

</div>

> [@](#):
>
> \*Originally posted by nitroglycerine \*  
> \*\*Well, I’ve learned a valuble lesson today. Always install the MS patches, and never EVER turn off Zone Alarm. \*\*

See, my problem is that no matter how I configure it, Zone Alarm blocks my wireless network.

My network consists of an ADSL modem plugged into a Sony Vaio USB port. The Vaio has a wireless router plugged into its ethernet port, which my Powerbook uses to get online. So no Vaio, no internet for the Powerbook. And when Zone Alarm is running on the Vaio, the internet won’t work on the Powerbook. And yes, I’ve put all the relevant IPs into trusted zones etc. Maybe Zone Alarm is just a bit crappity at this sort of thing?

Luckily the completely firewall free Powerbook has NEVER caught a virus, worm, or trojan of any kind. \<insert Mac smiley here\>

---

<div class="post-metadata">

### Author: ![Epimetheus](https://avatars.discourse-cdn.com/v4/letter/e/c4cdca/32.png) [@Epimetheus](https://boards.straightdope.com/u/Epimetheus)
#### Post date: [August 12, 2003, 6:08pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/56 "2003-08-12T18:08:32Z")

</div>

Strange, I am having a problem with my computer shutting down at seeming random times. sometimes it wont for days at a time, other times two or three times in a few hour period. Only when I have a browser or two open though. It never gives a warning. I do not have msblast.ext on my computer or on my startup, so I guess I am safe. I have a firewall- comes with [swbell.net](http://swbell.net).

Strange though that they are so similar.

---

<div class="post-metadata">

### Author: ![Futile\_Gesture](https://avatars.discourse-cdn.com/v4/letter/f/f05b48/32.png) [@Futile\_Gesture](https://boards.straightdope.com/u/Futile_Gesture)
#### Post date: [August 12, 2003, 6:20pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/57 "2003-08-12T18:20:51Z")

</div>

Bah!

It looks like I’m not infected, no msblast, virus check comes up clean. But every time I go online my svchost crashes and RPC shuts down. I’ve patched and everything.

---

<div class="post-metadata">

### Author: ![Tomcat](https://avatars.discourse-cdn.com/v4/letter/t/8e8cbc/32.png) [@Tomcat](https://boards.straightdope.com/u/Tomcat)
#### Post date: [August 12, 2003, 6:40pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/58 "2003-08-12T18:40:56Z")

</div>

btw- how does one block a specific port? In this case 130 (or is it 135?)

-Tcat

---

<div class="post-metadata">

### Author: ![absoul](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@absoul](https://boards.straightdope.com/u/absoul)
#### Post date: [August 12, 2003, 6:41pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/59 "2003-08-12T18:41:04Z")

</div>

Blargh.

Yesterday I worked a 10 hour shift. It was supposed to be 8 hours. Today looks to be more of the same. I removed this freaking virus from 40+ systems yesterday. Here is the best route I have found.  
Unplug Your Ethernet Connection from your computer.

Disable System Restore.  
Click – Start/Control Panel/System/System Restore(tab). Check “Turn off System Restore” or “Turn off System Restore on all Drives”. Click “Apply” and “Yes”.

Enable XP Firewall.  
Click – Start/Control Panel/Network Connections. Right Click on your internet connection and Left Click Properties. Click on Advanced(tab) check “Protect my computer.” Click “OK”

Connect your Ethernet connection and reboot your system.

Download Patch.  
Connect to the internet. Go to [www.microsoft.com](http://www.microsoft.com).  
Click on “Downloads” located in left hand panel under “Resources”.  
Click on “Windows XP Security Patch: Buffer Overrun In RPC Interface Could Allow Code Execution”. If you are running 2000 select 2000 Security patch instead.  
Click “Download” in first box to the right. Select “Open” in download dialog box. This will allow auto install. Reboot.

Stop Msblast process.  
Press \<Ctrl\>\<Alt\>\<Del\>. Click Processes(tab). Highlight “msblast” and click “End Process”

Edit Registry.  
Click Start/Run. Enter “regedit” in dialog box and Click “OK”.  
Follow the following path - HKEY\_LOCAL\_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run  
In the right hand pane delete both listings “windows auto update” and “msblast.exe”.  
Close registry.

Delete any remnants.  
Click Start/Search/All Files and Folders. Search for “msblast”. Delete any files found.

Enable System Restore.  
Click – Start/Control Panel/System/System Restore(tab). Uncheck “Turn off System Restore” or “Turn off System Restore on all Drives”. Click “Apply” and “Yes”.

Reboot.

When complete download and install Windows Updates. Using IE Click “Tools” then “Windows Updates”

Install a firewall program. A very nice FREE version of ZoneAlarm is located at [www.zonealarm.com](http://www.zonealarm.com).

Run updates on your Anti-virus Programs and Run a Full system check. You can get a FREE version of AVG anti-virus program at [www.grisoft.com](http://www.grisoft.com).

Lather, Rinse, Repeat

---

<div class="post-metadata">

### Author: ![Futile\_Gesture](https://avatars.discourse-cdn.com/v4/letter/f/f05b48/32.png) [@Futile\_Gesture](https://boards.straightdope.com/u/Futile_Gesture)
#### Post date: [August 12, 2003, 6:57pm UTC](https://boards.straightdope.com/t/msblast-exe-wtf/194466/60 "2003-08-12T18:57:36Z")

</div>

I’m now in love with ZoneAlarm.

It makes me feel like I’m in a safe, warm place. It’s also free and unconditional in it’s love (though it likes you to tell it your email address, shamelessly I lied.)

😃

I’ve been hit 3 times on port 135 in the last 3 minutes. I care not a jot!

Ha! Make that **4** times! Bring it on!

[Previous page](https://boards.straightdope.com/t/msblast-exe-wtf/194466.md?page=2)

[Next page](https://boards.straightdope.com/t/msblast-exe-wtf/194466.md?page=4)
