MSBlast infects eight million PCs

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
New data from Microsoft suggests that at least eight million Windows computers have been infected by the MSBlast, or Blaster, worm since last August -- many times more than previously thought.

The latest data comes from the software giant's ability to track the usage of an online tool that its engineers created to clean systems infected with the worm. Since the January release of the tool, more than 16 million of the systems that connected to Microsoft's Windows Update service were found to be infected with MSBlast and were offered a patch and the use of the disinfecting tool, the software giant told ZDNet sister site CNET News.com. During the same period, about eight million systems actually called on Update to patch them and prevent reinfection and used the special tool to remove the worm.

Though Microsoft believes the total number of users infected by the worm is likely to be closer to the higher, 16 million, tally, the eight milllion figure may provide a more solid indication of the minimum number of systems hit. The larger number may include systems counted more than once, as busy computers users declined to deal with the worm immediately, or cancelled the process once it had begun, only to return to Windows Update later. Once those systems were disinfected and patched, however, they would not be re-counted. Microsoft did not track what systems, specifically, used the tool, just that it was used.

Late last year, "we knew we were getting reports from customers saying that they were still seeing symptoms of Blaster," said Stephen Toulouse, security program manager for Microsoft's security response centre. "Our Internet service provider partners were seeing a lot of Blaster traffic on their networks as well."

In fact, the worm hit so hard that the company quickly asked some development teams to stop work on the software giant's next version of Windows and create an interim update, known as Service Pack 2, to enhance the security of Windows XP. Moreover, several months of complaints led Microsoft to augment Windows Update with the online tool to detect and clean the MSBlast worm.

The tool has also given Microsoft an invaluable data point to quantify the threat of such Internet worms.

Already, the size of the digital epidemic far exceeds the estimates of researchers who have tracked the worm since it first started spreading, on 11 August. Typically, researchers try to estimate the size of a worm epidemic by collecting data from the records of network devices, such as firewalls and intrusion detection systems. By aggregating the information from the devices, researchers can count the number of Internet addresses from which a worm, such as MSBlast, is trying to spread.

Most Internet security organisations had believed that at most 500,000 systems had been compromised by the self-propagating program.

"I don't doubt [the new] number," said Johannes Ullrich, chief technology officer for the Internet Storm Centre, which collects firewall logs from thousands of volunteers in order to gauge which digital threats are spreading on the Internet. Using the voluntarily submitted records, the Internet Storm Centre had tallied enough Internet addresses to estimate that between 200,000 and 500,000 computers had been infected by the worm.

Another threat tracker, security company Symantec, has agreements with the owners of some 20,000 network devices to use their records for analysis. The company crunches the numbers to keep track of threats on the Internet, and though it stopped counting once the MSBlast worm spread to more than 40,000 computers, Symantec estimated that "a couple hundred thousand" systems may have been compromised, said Alfred Huger, senior director of engineering for the company.

"I am surprised by [Microsoft's] number," he said. "However, I can't contest it; they have the best insight. We certainly see Blaster out there in spades."

A survey of 2,000 computers completed by Symantec found that, on average, a system will receive a network packet from a MSBlast-infected computer within one second of connecting to the Internet. Such tenacious spreading is part of the reason that Symantec waited until February, five months after MSBlast started spreading, to reduce its threat rating of the worm from a three to a two on its five-point scale.

The wide gap between previous estimates and the latest data calls into question Internet researchers' ability to accurately gauge the spread of computer worms.

The Internet Storm Centre's Ullrich stressed that counts based on network sensors only see the data that goes outside a company's firewall. Many companies block the data that the MSBlast worm uses to spread. Moreover, many Internet service providers also blocked the data, further reducing the apparent number of infected systems on the Internet.

"Sure we missed some of them," Ullrich said. "The biggest discrepancy is likely in the large corporate networks."

Microsoft's Toulouse has confidence that the software giant's data is correct. Windows Update patches the vulnerability that allows the MSBlast to spread, but before January, it didn't eradicate the worm from the compromised system. That behaviour resulted in many users having their systems patched after the worm successfully infected their computers. That prompted Microsoft to create the tool to clean those Windows systems.

"They were protected from being re-infected, but they had already been infected," he said. "The tool doesn't even get offered to (users), unless they had (the patches) installed and we detected the existence of Blaster on their computer."

Security researchers still weren't ready on Friday to put complete faith in the new numbers. They seemingly needed time to acclimate to a new reality where a single worm or virus could threaten millions of computers.

"It's a very large number," said Symantec's Huger.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

3 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

5 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

5 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

7 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

9 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

10 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

11 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

11 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

12 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

14 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

19 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

22 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

22 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

23 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

24 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?