Sophos

W32/Blaster-D

Aliases
  • W32/Lovsan.worm.d
  • Exploit-DcomRpc
  • trojan
  • WORM_MSBLAST.E
Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 28 September 2003 09:46:37 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

Please follow the instructions for removing worms.

Please see W32/Blaster-A for recovery instructions.

More Information

W32/Blaster-D spreads in the same way as W32/Blaster-A. However, the Blaster-D variant is packed differently, uses the filename (and process name) mspatch.exe instead of msblast.exe, and adds the registry entry

HKLM\Software\Microsoft\Windows\CurrentVersion\Runon\Nonton Antivirus

Microsoft issued a patch for the vulnerability exploited by this worm on July 16, 2003. The patch is available from
http://www.microsoft.com/technet/security/bulletin/MS03-026.asp.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer