W32.Blaster.Worm Removal Tool *updated*

Hello guest,
default
To benefit from all extra features you need to log in or sign up.
Living Room Discuss, W32.Blaster.Worm Removal Tool *updated* at Community forum; Go and grab the patch and cleaner tool for this nasty virus that allows a user too access any of the following OS and take control of yer pc. YOU HAVE BEEN WARNED! Security Patch Information For more information about how to resolve this vulnerability, click the appropriate link in

default_avatar
intercept (CD Freaks Senior Member)
Posts: 532
Posted: 13-08-2003
Go and grab the patch and cleaner tool for this nasty virus that allows a user too access any of the following OS and take control of yer pc.

YOU HAVE BEEN WARNED!

Security Patch Information

For more information about how to resolve this vulnerability, click the appropriate link in the following list:

Windows Server 2003 (All Versions)
Windows XP (All Versions)
Windows 2000 (All Versions)
Windows NT 4.0 (All Versions)

go and grab the patch from here

http://support.microsoft.com/?kbid=823980#WinXP

get the cleaning tool here

http://securityresponse.symantec.com...oval.tool.html

Run the patch 1st and then run the cleaner in that order only ok.

Glad too be of service too yah all

The Diplomat
__________________
Freedom is a Figure of Speech!

Respect (Ali G)
default_avatar
Today (MyCE Staff)
Posts: 15,596
Hemispasm's Avatar
Hemispasm (Senior Moderator)
Posts: 5,250
Posted: 13-08-2003
My girlfriend got it on her PC yesterday. Called me in panic telling me that her PC broke down, as it was shutting down all the time. Had to "diagnose" the darn think over the phone and try to explain to her how to apply the removal tool and MS patch to fix it, after i mailed it to her. God it took me the whole day !
Girls and PCs dont mix
__________________
[Airhead]: How the devil?! I got 69! I am a french lesbian!

*Hemi HATES wallpapers AND pickles* ........ never forget that

*There is one thing more evil than pickles, and that is STATISTICS...*
default_avatar
intercept (CD Freaks Senior Member)
Posts: 532
Posted: 13-08-2003
Me poor uncle foned me saying as soon as he connected too the net it would shut his pc down everytime, I went and looked and checked the error log with xp admin tools and sure enough there was a few rpc calls. I said will sort in the morning for him. I got home and there was a global msg on me msn account using Trillian giving me info and urls to go and get the patch and cleaner. I didnt know about it as I have zonealarm 4 up and running and configured with max settings without compromising opening webpages. Installed the patch ran the cleaner and my PC is clean as a whistle

Greetz from the HapPy Diplomat
__________________
Freedom is a Figure of Speech!

Respect (Ali G)
dhc014's Avatar
dhc014 (Retired Moderator)
Posts: 4,370
Posted: 13-08-2003
Oh goodness, two days ago my sister called me saying that she kept being forced to restart her computer every two minutes, that there was some kind of Remote Procedure Call error. I really should have suspected a virus sooner, but I was at work at the time so I just told her to go into services and change the Remote Procedure Call Service to not shut down her computer on errors. I figured that it was just time for a format and reinstall. After that she told me of many more errors and problems that I had no idea what would cause. I'd heard of a really bad new virus, and it looks like she got it.

Thanks for the links!
__________________
.:: Dave | http://dhc014.rpc1.org ::.

Last edited by dhc014; 13-08-2003 at 06:16.
default_avatar
MaFd0n (CDFreaks Resident)
Posts: 610
Posted: 13-08-2003
Well, here is how to remove it manually if you don't like to patch ( wierd but hey such people exist )

1) open your configuration screen and find RPC service, click properties and search for reboot. Turn it to restart service.

2) reboot

3) open your registry ( with regedit ) and search the registry for msblast.exe ( or search the exact keys on the microsoft site )

4) now open cmd ( ms-dos ) and go to your %windir%\system32 and write del msblast.exe. DO NOT PRESS ENTER

5) press crtl+alt+del and kill msblast.exe, after you did so try to press enter in cmd as fast as possible.

6) You are clean, now install a firewall!
__________________
MaFd0n
Da_Taxman's Avatar
Da_Taxman (Senior (non-technical) Admin)
Posts: 14,770
Posted: 13-08-2003
http://club.cdfreaks.com/showthread....n+AND+virus%2A
__________________
  • By registering to our forum you accepted our rules and policies (Dutch), so respect CD Freaks by respecting these rules and policies;
  • Please read these helpful tips and links for all (newbies and oldtimers)
  • Please describe your problem as clear as possible in your topic title, so that others can see what it is about and are more inclined to help if it is something they know something about;
  • I do not provide technical support over E-mail or Private Message (emails with such requests will be bounced);
  • Please post your questions as clear as possible, so others can help you get a correct answer sooner;
  • Please use our search, you might get an answer to your question sooner that way;
  • For any forum related issues you can contact me through PM;

  • I don't dislike newbies, just lazy people who expect others to do their work for them.
Wannez's Avatar
Wannez (The Slutty Professor)
Posts: 1,397
Posted: 13-08-2003
How exactly does it spread around?
2 of my friends had it yesterday, but others don't (yet).

edit: oops I just found the answer in the general software-topic, sorry!
Hemispasm's Avatar
Hemispasm (Senior Moderator)
Posts: 5,250
Posted: 13-08-2003
Quote:
Originally posted by Wannez
edit: oops I just found the answer in the general software-topic, sorry!
Computer keeps restarting
__________________
[Airhead]: How the devil?! I got 69! I am a french lesbian!

*Hemi HATES wallpapers AND pickles* ........ never forget that

*There is one thing more evil than pickles, and that is STATISTICS...*
default_avatar
intercept (CD Freaks Senior Member)
Posts: 532
Posted: 14-08-2003
I know I am in the middle of moving home whenever(all packed), will keep posting important topics like this one.

Greetz The Diplomat
__________________
Freedom is a Figure of Speech!

Respect (Ali G)
cico's Avatar
cico (CDFreaks Resident)
Posts: 1,445
Posted: 14-08-2003
i had it today... thank god i had installed nav 2003 just a couple of hours before...
i still have a question: how does it spread? i didn't check the email... i didn't even set any of my accounts... i wasn't browsing... i really can't believe that this damn thing just... "floats around" the www infecting at wil...
__________________
"Hi! I am a signature virus! Put me in your signature to help me spread myself around this forum!"

Clockwork Tangerine

There is no spoon. Stir your coffee with your finger.

See, the problem is that God gives men a brain and a penis, and only enough blood to run one at a time.

badger badger badger badger badger badger badger badger badger badger badger badger MUSHROOM MUSHROOM



My new pc is here!!

Asus a7n8x deluxe - AMD Athlon xp 2800+ barton 512k cache 2080 MhZ (166*12.5) - 512 mb ddr 400mhz (pc3200) (x2) - maxtor d.max plus9 6y080p0 80gb u-ata133 7200rpm 8mb cache - Sapphire ATI RAD9600Pro 128M DDR TvOutDVI 8X - Coolermaster tube cables - Cooler master hhcl61 silent heat pipe socket a - Pioneer DVD-106s 16x40 - Lite-ON ltr-52246s

The bo$$ would like to see you
default_avatar
intercept (CD Freaks Senior Member)
Posts: 532
Posted: 14-08-2003
Quote:
Originally posted by cico
i had it today... thank god i had installed nav 2003 just a couple of hours before...
i still have a question: how does it spread? i didn't check the email... i didn't even set any of my accounts... i wasn't browsing... i really can't believe that this damn thing just... "floats around" the www infecting at wil...
A typical IP address might look like this 10.45.345.4

I think the author of this worm virus has coded a small program and lets him enter the following and do a search 10.*.(thats an example) All ip addresses which start with 10 will be sent back to him he then does a mass attack on those ip addresses that start with 10, and hey presto you are infected without even knowing it. He then as full access at dos level mode only and allows him too delete files, or even issue a command too format yer drive(s) he also executes a script file so evertime you are on the net he will know, and then he can either issue an rpc which will shut your pc down within 30 seconds, or start zapping yer OS.


Hope that little explanation helps

Greetz From The Diplomat
__________________
Freedom is a Figure of Speech!

Respect (Ali G)
dhc014's Avatar
dhc014 (Retired Moderator)
Posts: 4,370
Posted: 15-08-2003
Read the technical details here: http://securityresponse.symantec.com...ster.worm.html

Basically, the current state of the worm simply spreads itself. Once you're infected, the worm generates a random IP address and targets that computer trying to infect it.

Chances are very slim that the author actually ever controls your computer. It restarts because the worm causes an error in the RPC service, and the service (by default) is set to restart your computer if it encounters an error.
__________________
.:: Dave | http://dhc014.rpc1.org ::.
AZImmortal's Avatar
AZImmortal (Retired Moderator)
Posts: 2,941
Posted: 15-08-2003
yeah, the worm spreads by itself and doesn't require any user interaction to infect computers. if ur computer is vulnerable, it'll automatically install and run itself. ironically, the windows patch (which was also available through windows update) came out on july 16, which was nearly a month ago.
__________________
Vob Blanker | DvdReMake (Pro)

I don't respond to questions through PM that should be asked in the forum
Huzzy's Avatar
Huzzy (Resigned)
Posts: 1,099
Posted: 15-08-2003
Good Work Intercept.

Im sure you saved a lot of people from getting this worm.
and helped a lot of others remove it

Cheers
ckin2001's Avatar
ckin2001 (CDFreaks Resident)
Posts: 3,468
Posted: 15-08-2003
Quote:
Originally posted by dhc014
Basically, the current state of the worm simply spreads itself. Once you're infected, the worm generates a random IP address and targets that computer trying to infect it.
from what i've read - its pretty poorly programmed as well. not nearly as efficient as the one that crippled korea.
__________________
www.livingwithoutmicrosoft.org

last 5 cd's
Avril Lavigne - Whatever the new one is called
Lucky Boys Confusion - Throwing the Game
lostprophets - Start Something
Story of the Year - Page Avenue
Flaming Lips - Yoshimi Battles the Pink Robots



Don't let schooling interfere with your education.
-Mark Twain
Hemispasm's Avatar
Hemispasm (Senior Moderator)
Posts: 5,250
Posted: 15-08-2003
Quote:
Originally posted by ckin2001
from what i've read - its pretty poorly programmed as well. not nearly as efficient as the one that crippled korea.
Imagine if it were well programmed then ...
__________________
[Airhead]: How the devil?! I got 69! I am a french lesbian!

*Hemi HATES wallpapers AND pickles* ........ never forget that

*There is one thing more evil than pickles, and that is STATISTICS...*
Airhead's Avatar
Airhead (Letiled Modelatol)
Posts: 7,109
Posted: 15-08-2003
Heh, I went over to a friends house just now to help him with his computer (new mobo), and so we reinstalled XP and everything was dandy. Then we installed the Ethernet drivers and logged on to the internet. Guess what happened

I must say it's very clever way to use this exploit, and like Hemi says, imgine what would have happened if it were "good" programming, like those viruses that change size and name by themselves.
__________________
  • This line is currently vacant. Or Is It???
  • You want fast answers? Use our search. <-- Or else!
  • If you have not already, read our rules! <-- Or else again!
  • bcn_246: "Wales are shitty animals to, all they do is swim around and make funny noises that people cant hear."
  • You really should join us on IRC! IrcNet, #cdfreaks-int | Or go here
  • Fear my massive avatar history log! Not updated!
  • "But do they keep increasing in size like mine?" - kwkard
default_avatar
intercept (CD Freaks Senior Member)
Posts: 532
Posted: 15-08-2003
I just got a msg off a friend I know in the USA on ICQ that this worm is suppose to strike big time tomorrow and cause chaos. I asked my friend where it came from and this is what she said.

[20:31] Maria: a friend emailed it to me

[20:35] Maria: should I pass this around to have people
search for it?

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. If in doubt, contact your network administrator. Incorrect editing of the Windows Registry can cause system failure.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
in the righthand pane select
windows auto update = msblast.exe
and delete it if it exists.

_______________________________________________
So if your are unsure about this then take your pc's off-line till Monday, and export a copy of your registry now as a backup. You can then restore in safe mode if needs be.

I keep getting warnings from MSN (using Trillian as my client for all chat servers) that the worm is out of control and causing chaos

Take it how you will, this is an important development and major risk to newbies and pros.

Just doing my job for the community

Greets The Diplomat
__________________
Freedom is a Figure of Speech!

Respect (Ali G)
Airhead's Avatar
Airhead (Letiled Modelatol)
Posts: 7,109
Posted: 15-08-2003
It's going to attack windows-update only.
MS tut on how to get rid of Msblast here
__________________
  • This line is currently vacant. Or Is It???
  • You want fast answers? Use our search. <-- Or else!
  • If you have not already, read our rules! <-- Or else again!
  • bcn_246: "Wales are shitty animals to, all they do is swim around and make funny noises that people cant hear."
  • You really should join us on IRC! IrcNet, #cdfreaks-int | Or go here
  • Fear my massive avatar history log! Not updated!
  • "But do they keep increasing in size like mine?" - kwkard
shuss's Avatar
shuss (CDFreaks Resident)
Posts: 1,431
Posted: 16-08-2003
when downloading the patch, there was the xp 32 and 64 bit option.
I chose 32 bit - whats the difference?
Hemispasm's Avatar
Hemispasm (Senior Moderator)
Posts: 5,250
Posted: 16-08-2003
There are 2 versions of Windows XP, 32bit and 64bit. The 64bit is essential for compatability with 64bit processors i think. Some of the benefits summarized here
__________________
[Airhead]: How the devil?! I got 69! I am a french lesbian!

*Hemi HATES wallpapers AND pickles* ........ never forget that

*There is one thing more evil than pickles, and that is STATISTICS...*
There's more to MyCE.com

Listen up, we've got more. Product information on 102,541 products. Our experts have written 521 articles. We've gathered 16,068 news items for you to always keep updated.

Active Commenters

Posting Rules

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
All times are GMT +2. The time now is 01:27.
Top