Dubbed "MSBlast" by its author, the worm is spreading quickly, according to an initial analysis posted to the Internet Storm Center, a digital threat-tracking site. Ever since mid-July, when Microsoft announced a vulnerability in a widespread component of Windows, security experts have been waiting for some online vandal to create a worm that takes advantage of it.
The worm, which security experts believe started spreading early Monday, scans for vulnerable computers so widely that an unpatched Windows XP computer on the Internet could be infected in as little as 25 minutes, according to Symantec studies.
Symantec says to block TCP port 4444. I did this as soon as I read that - I'm patched already (since June, probably, I get all the critical updates), but extra security never hurts.
As far as I can tell, it tries 3x to get through a particular computer, then quits. So, in the below case, 4 computers tried scanning my 4444 port in a span of a few minutes. They were also all on my ISP, which apparenty also is a characteristic of this worm.