New Blaster Variant Surfaces
Available patch blocks original, variant, and copycat worms.
Paul Roberts, IDG News Service
Less than two days after it first appeared on the Internet, the W32.Blaster worm has already spawned a variation that is also spreading, warn antivirus vendors.
However, major antivirus vendors have updated their virus definitions to identify and repair damage by the original worm (also called Lovsan). Fixes are underway to control its variant as well as a new pest that appears to exploit the same Windows vulnerability as Blaster.
Security experts suggest users running vulnerable versions of Windows XP and Windows 2000 apply a software patch released by Microsoft in July.
Users can also search their hard drive for the worm file and delete it, and immediately obtain and install the patch. The malicious file is called msblast.exe in the original Blaster, and teekids.exe in the variant, which is dubbed W32/Blaster-B.
Blaster-B Crawls
The new variation of Blaster was identified Wednesday, according to antivirus company Sophos, which has already posted an updated fix.
Like the original worm, Blaster-B affects PCs running Microsoft's Windows XP and Windows 2000 operating systems.
Blaster takes advantage of a known vulnerability in a Windows component called the Distributed Component Object Model interface, which handles messages sent using the Remote Procedure Call protocol.
Windows XP users infected with Blaster report frequent system reboots and messages about "System Shutdown." Both Windows XP and Windows 2000 users may experience significant system slowdowns when using Windows or surfing the Internet if their machine is infected, according to Alfred Huger, director of engineering at Symantec Security Response.
Slight Changes
Little is known yet about how the new Blaster version differs from the original, according to Chris Belthoff, senior security analyst at Sophos.
Blaster-B works like the original Blaster. However, the new pest comes packaged as a file called teekids.exe.
Blaster-B also replaces an internal message stating "LOVE YOU SAN" with some colorful suggestions for Microsoft Chairman and Chief Software Architect Bill Gates, according to Sophos.
Antivirus company Symantec also identified the Blaster-B variant and rates it a Category 2, or "low", threat, according to a company spokesperson.
New Threat
A second new threat is named W32/RpcSpybot-A. It exploits the same vulnerability as Blaster, so it's not considered a variation. It contains code that creates a backdoor on infected machines that could give an attacker control over that machine, Sophos representatives say.
RpcSpybot-A uses the same exploit as the worm, but is an Internet Relay Chat Trojan. It scans the Internet for vulnerable systems, exploits the RPC DCOM security hole, then uses IRC to remotely control the infected systems for use in a denial-of-service attack, according to Symantec's Huger.
Sophos researchers were still analyzing RpcSpybot-A and did not yet know what other actions it might perform on infected systems, Belthoff says.
Similar threats that use the DCOM security hole have been circulating on the Internet for weeks, predating the release of Blaster, Huger says.
Neither Sophos nor Symantec knew of any infections stemming from RpcSpybot-A.
Fixes Available
Sophos has posted updated virus identity files to detect the RpcSpybot-A worm.
F-Secure also offers information and advice on the variant.
Symantec continues to monitor Blaster and its siblings, as does McAfee.
The emergence of new versions of the Blaster worm complicates the job of blocking attacks for customers who haven't patched their vulnerable Windows systems, Belthoff says.
"We're starting to see the floodgates open. We were hopeful that Blaster would be the first and last, but it seems like that's not going to happen," he adds.
Full Windows 7 coverage
Save on Printing Costs
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2010 - 3 UsersPrice: $26.30
Norton Internet Security 2010 - 3 UserPrice: $26.30
Internet Security 2010Price: $31.89
Norton 360 Version 3.0 - 3 LicensesPrice: $39.99
Total Protection 2010 - 3 UserPrice: $26.97
Norton 360 Version 3Price: $41.10
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage


