PDA

View Full Version : W32.Blaster.Worm (aka LovSan)


markblair
08-12-03, 07:22 AM
I didn't see this posted anywhere else so I thought I'd add it. There's a new virus hitting networks everywhere today. Symantec has it listed as W32.Blaster.Worm while others have called it 'LovSan'. From what I've read, this is a worm that exploits the DCOM RPC vulnerability using TCP port 135. It attempts to download and run the msblast.exe file.

Further information can be found at the below Symantec link:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html

beley
08-12-03, 12:09 PM
We just got hit with this today... fortunately 90% of our computers are up to date with definitions from yesterday (8/11) which is catching the worm. We have had a few infections though... but Symantec has a good fix if you get infected.

JeremyV
08-12-03, 12:52 PM
no problems here, my firewall is doing it's job :D