Warning message... Link to action
Informational message... Link to action
Aliases: W32.Blaster.Worm (Symantec) W32/Lovsan.worm (McAfee) WORM_MSBLAST (Trend Micro) Win32.Poza (CA) Lovsan (F-secure) Worm.Win32.Blaster (Global Hauri) W32/Blaster (Norman) Blaster (Panda) W32/Blaster (Sophos)
Recovering from recurring infections on a network
Ensure that an antivirus product is installed on ALL computers connected to the network that can access or host shares.
Ensure that all available network shares are scanned with an up-to-date antivirus product.
Restrict permissions as appropriate for network shares on your network. For more information on simple access control, please see: http://technet.microsoft.com/library/bb456977.aspx.
Remove any unnecessary network shares or mapped drives.
Removing the threat
DoS attacks against Web sites, including windowsupdate.com, kimble.org, or tuiasi.ro, if the day of the month is greater than 15 or the month of the year is greater than 8.
Changing the Internet Explorer home page.
Opening a backdoor program, listening at a random TCP port, that allows attackers to gain access to the infected system, and reports the port number and infected system IP address to a remote server.
Take the following steps to help prevent infection on your computer:
Enable a firewall on your computer.
Get the latest computer updates for all your installed software.
Use up-to-date antivirus software.
Limit user privileges on the computer.
Use caution when opening attachments and accepting file transfers.
Use caution when clicking on links to Web pages.
Avoid downloading pirated software.
Protect yourself against social engineering attacks.
Use strong passwords.
Enable a firewall on your computer
Get the latest computer updates
Use up-to-date antivirus software
Limit user privileges on the computer
Use caution when opening attachments and accepting file transfers
Use caution when clicking on links to Web pages
Avoid downloading pirated software
Protect yourself from social engineering attacks
Use strong passwords