Jump to content

Removing The W32.blaster.worm


Scarthy © ® ™
 Share

Recommended Posts

Hi all ;),

I have just had an update/ warning about this worm on BigFix. I usually don't think much to the 'advise', but I found this article about removing it and thought the forum might benefit (or some reader who has the misfortune of aquiring this 'nasty little blighter') from me reproducing it...

Patch Your System with the appropriate MS03-026 Patch

After Installation of the Patch, Reboot your system.

Download and run "FIXBLAST.exe" to remove the MSBLAST.exe file, terminate the process and remove added registry keys by the worm.

Reboot your pc one last time.

Visit WindowsUpdate.com more often and take note of our repeated warnings to keep your system updated.

Result:

Your System will no longer shutdown after 60secs, please follow the steps above to remove the worm off your computer and return your system to UPDATED safe status.

UPDATE: If your having problems installing the patch within the 60 sec, when you see the window pop up telling you 60 sec, Go to Start, Run and type in shutdown -a. This will cancel the shutdown attempt.

Download>>>Windows XP Patch<<<>>>Windows 2000 Patch<<<

Download>>>FixBlast - W32.Blaster.Worm Removal Tool<<<

View - Symantec Security Response - W32.Blaster.Worm Removal Tool

News Source

;)

(might be worth 'pinning' this one ellas ;))

Link to comment
Share on other sites

Guest Nellie2

Guess what??...........I just had a phone call from a friend who has this worm! :( given her the link for a page which tells her about it and has a download for the fix. (Didn't see this post!!!) Trouble is, the worm keeps shutting her PC down so she can only get on line for a few mins at a time!!! :ph34r:

Link to comment
Share on other sites

strange that, one of my mates came to me at work today and said "I was using kazaa and shortly after i downloaded something my computer keeps shutting down after about 1 minute!!"

mmm...i wonder!

Link to comment
Share on other sites

Guest Nellie2

You won't believe this...........she isn't running a firewall :huh: I just gave her a lecture on firewalls and am emailing her some links..... and no she isn't blonde she is a redhead!!!

Link to comment
Share on other sites

Guest Shirley_Crabtree

I "caught" this one yesterday.I wasn't using my firewall :o The shame of it!!

I downloaded an mp3 off K***a and half an hour later I was watching The Simpsons and had left my pc connected (and msn messenger on).

All of a sudden it restarted all on its own.

I was immediately suspicious and downloaded Sygate Personal Firewall.

I then had major problems with latency issues on Counterstrike,I was pinging around 400-450...So I took off Sygate :blink: but the problem persisted.

I then put AVG on(OK OK,I KNOW!!!) but couldn't download the updates as my pc kept restarting!!!!

To cut a long story short I reformatted the bloody thing,it was only my "b" hdd.

I have now switched back to my "a" hdd which is fully secure (I hope :unsure: )

Cheers.

Shirl.

Link to comment
Share on other sites

Guest Nellie2

Errr she is actually a member but hasn't been around for a while because she has been ill. She was troubled by the messenger spam but used your article to turn it off :)

Link to comment
Share on other sites

Guest Shirley_Crabtree
:blink:  :blink:  :blink:

This nasty uses the same ports as messenger spam, has she never been troubled by that ?

This is how,I suspect,it got onto my PC,I think the K***a bit was a coincidence.(sp?)

I've noticed,over the last fortnight,hotmail spam has gone from 1 or 2 a day to 9 or 10 a day.....Our Chris accumulated 35 viagra and farm $ex emails in about 4 days recently and he's just 12!! (it's a good job I routinely rinse his mailbox with Mailwasher :rolleyes:

Cheers.

Shirl.

Link to comment
Share on other sites

Possibly came in via K******* but when executed, it adds the value "windows auto update"="msblast.exe" to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\

which then uses TCP port 135 that can exploit the RPC vulnerabilitty to allow the the worm to be downloaded and run .

A check in the registry for the above key will tell if you still have a problem

Shirley Crabtree

35 viagra and farm $ex emails in about 4 days

is that all ? it is a bit much for 12yr old tho :blink:

Link to comment
Share on other sites

Guest Shirley_Crabtree

Just got this email from Blueyonder :-

Dear customer,

If you use Windows NT4, Windows 2000, Windows XP or Windows 2003 you may be at risk from a new virus known as MSBlaster.  This virus exploits a known security issue with Windows operating systems.  It can cause your computer to reboot and can also result in slow speeds whilst browsing the Internet.

If you are running one of these operating systems please visit the Symantec website [http://www.sarc.com/avcenter/venc/data/w32.blaster.worm.html] where you can find further information, including instructions on how to remove this virus.

You can also visit the Microsoft site [http://www.microsoft.com/security/security_bulletins/ms03-026.asp] to get the latest security updates.

If you are having problems accessing either of these sites, or would like further information, please visit http://help.blueyonder.co.uk/blaster .

As this is a Microsoft technical issue customers should contact Microsoft technical support for further information at http://support.microsoft.com .

We strongly advise all customers to regularly update their anti-virus protection.

We are taking all the steps we can to minimise the impact of this virus on your service and appreciate your help.

Regards,

the team at blueyonder

Cheers.

Shirl.

Link to comment
Share on other sites

This caused us some grief at work today as well. After setting up some fresh installs, we connected them to the external side of our router (normal procedure for the first critical updates prior to them getting the network client and being connected to the internal network), and within 30 seconds all 3 base machines we were working on became infected :smart: :( Bad luck I think. No K*****, no messenger, in fact no nothing except Win2000 and some drivers.

Still for further reference, McAfee also have a few bits of information. NAI.com

Mr. M.

Link to comment
Share on other sites

Here's a list we've compiled over at the "other site":

http://pcpitstop.ibforums.com/index.php?ac...=ST&f=9&t=20008

We will be adding to it, as and when, new info/patches are available.

Anyone with any new info on this worm can pm me and if useful will be added to the list for the benefit of all!

Would have posted before, but some bugger deleted me when my pc was being rebuilt. :D

Link to comment
Share on other sites

A family friend also has this worm. His neighbour also has it and because they use 'remote assistance' I believe it has crossed from one to the other...? It has messed with his dial-up connection. I have told him about this forum and in particular this thread. I hope to see him joining soon ;)

I also noticed yesterday that just about every page that I tried to access on the internet gave me an error (Page Cannot Be Displayed...Site may be having difficulties etc etc blah blah blah...). This happened several time on certain sites. I wonder if this was due to the worm? I thought it might be the M$ patch, but all seems OK today....[touch wood] ;)

Link to comment
Share on other sites

Here is a copy of the BigFix message that I received...

VIRUS: W32.Blaster.Worm 

The W32.Blaster.Worm virus is a worm that will exploit the DCOM RPC vulnerability in Windows (described in Microsoft Security Bulletin MS03-026, See below for details) using TCP port 135.

This worm will attempt to download and run a file called Msblast.exe.

We recommend that you always update your Virus scanner regularly.

For more info about this virus click the link below:-

Click HERE for more info on the W32.Blaster.Worm virus

Click HERE for more info on DCOM RPC vulnerability

;)

Link to comment
Share on other sites

Here's how the infection spreads

An infected machine (PC1) will scan blocks of IP address until it finds a PC that is unpatched (PC2). It then sends a command to PC2 to get it to download the virus from PC1. Virus installs and PC2 starts scanning for PCs to infect.

Got a case to deals with at the weekend, a friend uses dial up once a month, told him this morning not to use the net until I'd checked and made sure his security up to date , too late !! he got it last night !! :smart:

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy