Results 1 to 4 of 4

Thread: What is MS Blaster, SQL Slammer & Nimda virus

  1. #1
    Join Date
    Mar 2009
    Posts
    36

    What is MS Blaster, SQL Slammer & Nimda virus

    Hi,
    I need some information on three type of viruses which are termed as the most worst one. They are MS Blaster, SQL Slammer & Nimda virus. What this virus actually do. Means how do they spread and what is the point where they get access. Also what are the changes made by them in the system. And also post some removal instructions for the same. Thanks.

  2. #2
    Join Date
    Jan 2006
    Posts
    4,221

    Re: What is MS Blaster, SQL Slammer & Nimda virus

    MS Blaster comes under worm category. The types under this are Win32. Poza, W32/Lovsan.worm, W32.Blaster.Worm, etc. Is it the first virus to exploit the vulnerability RPC / DCOM systems in Microsoft Windows, which allows remote processes to communicate. By exploiting the flaw through a buffer overflow, a malicious program can take control of the vulnerable machine. The worm is programmed in such a way to scan a range of IP addresses randomly looking for vulnerable systems to the RPC vulnerability on port 135. When the file is downloaded, it is executed, then it creates entries in the registry in order to restart automatically at every reboot. The location for it is HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ msblast.exe. To avoid the virus infection first right click on My Computer >Properties >Advanced >Startup and Recovery > Settings > Uncheck Automatically restart. Run a full system virus scan.

  3. #3
    Join Date
    Jan 2006
    Posts
    3,792

    Re: What is MS Blaster, SQL Slammer & Nimda virus

    SQL Slammer worm affects servers running Microsoft SQL Server or Microsoft SQL Desktop Engine. It allows the systems affected, to send the malicious packet to other SQL Server machines causing the slowdown, or even the fall of the affected network. This malicious code that runs the denial of service attack, is only memory-resident having no associated file. Because of this, those that do not perform antivirus scanning of memory, can not detect this worm. It should block UDP port 1434 where not needed, thus avoiding the spread of infection. SQLSlammer spreads through UDP packets to infect vulnerable systems as soon as they reach it. Once the worm gains control and begins to load WS2_32.DLL continuously send itself to port 1434/udp of IP address ranges in an infinite loop.

  4. #4
    Join Date
    May 2008
    Posts
    2,945

    Re: What is MS Blaster, SQL Slammer & Nimda virus

    The Nimda worm retrieves the list of addresses found in address books of Microsoft Outlook and Eudora, as well as e-mails contained in the HTML files on the disk of the infected machine. Then it ends to all recipients a mail whose body is empty, the subject is random and often very long and attached to an email attachment named Readme.exe or readme.eml. The virus using an extension like. eml exploit a vulnerability in Microsoft Internet Explorer 5. On the other hand, the Nimda virus can spread through shared folders of Microsoft Windows networks, infecting executable files. Indeed, the Nimda virus is also able to take control of a Web server Microsoft IIS by exploiting certain vulnerabilities. To eradicate the Nimda worm, the best method is to first disconnect the infected machine's network, then use a recent virus update or antivirus offered by Symantec.

Similar Threads

  1. Help! E-blaster on Mac!
    By dazed&cnfsed in forum Networking & Security
    Replies: 2
    Last Post: 07-03-2013, 08:53 AM
  2. How to use Facebook Blaster Pro
    By Edie Adams in forum Technology & Internet
    Replies: 4
    Last Post: 26-09-2011, 01:26 PM
  3. From Where I can get Barney Blaster
    By Vincent D in forum Video Games
    Replies: 4
    Last Post: 06-02-2011, 02:47 AM
  4. How to remove LovSan/Blaster virus
    By Xmen in forum Networking & Security
    Replies: 3
    Last Post: 15-10-2009, 04:40 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,499,441.26394 seconds with 17 queries