New Blaster Variant Surfaces
Available patch blocks original, variant, and copycat worms.
Paul Roberts, IDG News Service
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
Less than two days after it first appeared on the Internet, the W32.Blaster worm has already spawned a variation that is also spreading, warn antivirus vendors.
However, major antivirus vendors have updated their virus definitions to identify and repair damage by the original worm (also called Lovsan). Fixes are underway to control its variant as well as a new pest that appears to exploit the same Windows vulnerability as Blaster.
Security experts suggest users running vulnerable versions of Windows XP and Windows 2000 apply a software patch released by Microsoft in July.
Users can also search their hard drive for the worm file and delete it, and immediately obtain and install the patch. The malicious file is called msblast.exe in the original Blaster, and teekids.exe in the variant, which is dubbed W32/Blaster-B.
Blaster-B Crawls
The new variation of Blaster was identified Wednesday, according to antivirus company Sophos, which has already posted an updated fix.
Like the original worm, Blaster-B affects PCs running Microsoft's Windows XP and Windows 2000 operating systems.
Blaster takes advantage of a known vulnerability in a Windows component called the Distributed Component Object Model interface, which handles messages sent using the Remote Procedure Call protocol.
Windows XP users infected with Blaster report frequent system reboots and messages about "System Shutdown." Both Windows XP and Windows 2000 users may experience significant system slowdowns when using Windows or surfing the Internet if their machine is infected, according to Alfred Huger, director of engineering at Symantec Security Response.
Slight Changes
Little is known yet about how the new Blaster version differs from the original, according to Chris Belthoff, senior security analyst at Sophos.
Blaster-B works like the original Blaster. However, the new pest comes packaged as a file called teekids.exe.
Blaster-B also replaces an internal message stating "LOVE YOU SAN" with some colorful suggestions for Microsoft Chairman and Chief Software Architect Bill Gates, according to Sophos.
Antivirus company Symantec also identified the Blaster-B variant and rates it a Category 2, or "low", threat, according to a company spokesperson.
New Threat
A second new threat is named W32/RpcSpybot-A. It exploits the same vulnerability as Blaster, so it's not considered a variation. It contains code that creates a backdoor on infected machines that could give an attacker control over that machine, Sophos representatives say.
RpcSpybot-A uses the same exploit as the worm, but is an Internet Relay Chat Trojan. It scans the Internet for vulnerable systems, exploits the RPC DCOM security hole, then uses IRC to remotely control the infected systems for use in a denial-of-service attack, according to Symantec's Huger.
Sophos researchers were still analyzing RpcSpybot-A and did not yet know what other actions it might perform on infected systems, Belthoff says.
Similar threats that use the DCOM security hole have been circulating on the Internet for weeks, predating the release of Blaster, Huger says.
Neither Sophos nor Symantec knew of any infections stemming from RpcSpybot-A.
Fixes Available
Sophos has posted updated virus identity files to detect the RpcSpybot-A worm.
F-Secure also offers information and advice on the variant.
Symantec continues to monitor Blaster and its siblings, as does McAfee.
The emergence of new versions of the Blaster worm complicates the job of blocking attacks for customers who haven't patched their vulnerable Windows systems, Belthoff says.
"We're starting to see the floodgates open. We were hopeful that Blaster would be the first and last, but it seems like that's not going to happen," he adds.
PCW Download Guide
CDW Virtualization Center
Related Security Articles
- Online Encyclopedia Lists Internal Network Security Threats A new online encyclopedia lists internal network security threats.
- Judge Dissolves Gag Order Against MIT Students A U.S. District court judge on Tuesday dissolved a gag order against a trio of MIT students who say they found flaws in the...
- Data Security: What the Law Requires of IT IT's legal duty to secure sensitive data is complex and continuously evolving. Here's how to avoid the legal ramifications of a data breach.
- Wells Fargo Access Codes Compromise Personal Data Thieves may have accessed personal data of as many as 7,000 of the bank's customers.
- Internet Fraud Ignored by Authorities, Study Charges Spyware, viruses, and phishing cost consumers $7.1 billion in 2007, but a report says the U.S. fails to prosecute Internet fraud.
Best Prices on Antivirus Software
Anti-Virus 7.0 (Electronic Software Distribution)Price: $29.95
VirusScan Plus 2008 - 3-User (Full Product)Price: $7.24
AntiVirus 2008 (Full Product)Price: $14.95
Internet Security 2008 - 3 Users (Full Product)Price: $19.95
Norton AntiVirus 2008 - 3 UserPrice: $39.49
Anti-Virus 7.0 (Full Product)Price: $21.00
- CDW Virtualization Center What is Virtualization and how can it help you save money? Click here to find out.
- Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
- HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...







