MUST see if you use XP

Thread Tools
 
Search this Thread
 
Old Aug 13, 2003 | 09:12 AM
  #16  
DetailAddict's Avatar
Former Vendor
iTrader: (52)
 
Joined: Nov 2002
Posts: 6,912
From: San Jose, CA
Car Info: Evo X
British Banger,
I think someone here at my work has the same problem. I'll check with him. But I am sure that you are not suppose to use the 64-bit version. That's for systems like Itanium 2.

Leo
Old Aug 13, 2003 | 09:18 AM
  #17  
DetailAddict's Avatar
Former Vendor
iTrader: (52)
 
Joined: Nov 2002
Posts: 6,912
From: San Jose, CA
Car Info: Evo X
well, my co-worker said our IT told him to bring the system back to them. So I don't know the fix for it. sorry
Old Aug 13, 2003 | 01:03 PM
  #18  
dr3d1zzl3's Avatar
VIP Member
iTrader: (1)
 
Joined: Dec 2002
Posts: 8,159
From: The Least Coast :(
Car Info: 08 sti
British banger..

You need to disable the file restore option in XP.. See once you repalce a system file XP trys to replace it.. Well slight problem with that as it is trying to replace it with a bad copy.. Give me one sec and i will post the url to a how to so that you can disable it.
Old Aug 13, 2003 | 01:04 PM
  #19  
dr3d1zzl3's Avatar
VIP Member
iTrader: (1)
 
Joined: Dec 2002
Posts: 8,159
From: The Least Coast :(
Car Info: 08 sti
http://www.europe.f-secure.com/v-descs/sfc_dis1.shtml
Old Aug 13, 2003 | 01:05 PM
  #20  
dr3d1zzl3's Avatar
VIP Member
iTrader: (1)
 
Joined: Dec 2002
Posts: 8,159
From: The Least Coast :(
Car Info: 08 sti
For full instructions

It is also possible to remove the worm manually with the following steps:

1. Turn off Windows XP System Restore by following this guide:
http://www.europe.f-secure.com/v-descs/sfc_dis1.shtml

2. Terminate the msblast.exe process using the Task Manager

3. Delete msblast.exe from Windows System Directory

4. Remove the following registry value

'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ru
n\windows auto update'



5. Apply the Microsoft patch.

You might also want to turn on Windows XP's internal firewall to prevent access to port 135:
http://www.microsoft.com/windowsxp/h...e_firewall.asp
Old Aug 13, 2003 | 10:26 PM
  #21  
British Banger's Avatar
Underpants Gnome
iTrader: (1)
 
Joined: Mar 2003
Posts: 591
From: Cambridge, England
Car Info: 1.4 Ford Fiesta
Thanks for the responses iblu and dredizzle.

I'm trying to follow your directions dredizzle, but i don't know how to do the last one (The removing the registry value). Thanks a lot, my computer Is really screwed up!

James
Old Aug 14, 2003 | 07:53 AM
  #22  
DetailAddict's Avatar
Former Vendor
iTrader: (52)
 
Joined: Nov 2002
Posts: 6,912
From: San Jose, CA
Car Info: Evo X
go to start and run
type in regedit
Old Aug 14, 2003 | 12:55 PM
  #23  
dr3d1zzl3's Avatar
VIP Member
iTrader: (1)
 
Joined: Dec 2002
Posts: 8,159
From: The Least Coast :(
Car Info: 08 sti
whoops sorry. sorta forgot that step.. Just 2nd nature.
Old Aug 14, 2003 | 09:33 PM
  #24  
British Banger's Avatar
Underpants Gnome
iTrader: (1)
 
Joined: Mar 2003
Posts: 591
From: Cambridge, England
Car Info: 1.4 Ford Fiesta
Thanks Iblu and dredizzle, I think it worked.

My computer is finally back under my control!
Old Aug 14, 2003 | 10:20 PM
  #25  
British Banger's Avatar
Underpants Gnome
iTrader: (1)
 
Joined: Mar 2003
Posts: 591
From: Cambridge, England
Car Info: 1.4 Ford Fiesta
Okay nevermind, it didn't work, msblast keeps on appearing in the windows system32 folder, and in the task manager.

I am pretty certain that I did all the steps correctly, maybe you could elaborate on step #3. For this step I just did a search and found msblast inside Windows/system32, and deleted it.

Thanks all
Old Aug 15, 2003 | 08:29 AM
  #26  
DetailAddict's Avatar
Former Vendor
iTrader: (52)
 
Joined: Nov 2002
Posts: 6,912
From: San Jose, CA
Car Info: Evo X
British Banger,
This to follow instruction from this link.
http://securityresponse.symantec.com...ster.worm.html

or

http://securityresponse.symantec.com...er.b.worm.html

or

http://securityresponse1.symantec.co...ster.worm.html
If doesn't work search for W32.Blaster on the internet for other removal instructions...
Old Aug 15, 2003 | 01:54 PM
  #27  
dr3d1zzl3's Avatar
VIP Member
iTrader: (1)
 
Joined: Dec 2002
Posts: 8,159
From: The Least Coast :(
Car Info: 08 sti
make sure you install a software firewall like zonealarm. it is free and it will stop you from furthur infections. You may infact have cleaned it up only to get infected again cause you have no firewall installed.
Old Aug 17, 2003 | 01:50 AM
  #28  
British Banger's Avatar
Underpants Gnome
iTrader: (1)
 
Joined: Mar 2003
Posts: 591
From: Cambridge, England
Car Info: 1.4 Ford Fiesta
Thanks guys, I downloaded zonealarm and it worked, no more virus.

Thanks again for all your help!

James
Old Aug 17, 2003 | 01:58 AM
  #29  
BADWRX's Avatar
Registered User
iTrader: (5)
 
Joined: Nov 2002
Posts: 1,305
From: Kandahar, Afghanistan
Car Info: 09 E90 M3 SEDAN w/DCT
Originally posted by iBlueVirus
British Banger,
I think someone here at my work has the same problem. I'll check with him. But I am sure that you are not suppose to use the 64-bit version. That's for systems like Itanium 2.

Leo
Actually, XP 64 is tailored for the Intel crushing Opteron and Athlon64 AMD processors.

AMD is a company fixing to come alive. I am a huge advocate. Intel has nothing on the AMD64 core. Especially when MS is writting the 64 bit programs to be optimized on the new AMD architecture.
Old Aug 17, 2003 | 05:43 AM
  #30  
Peaty's Avatar
Registered User
iTrader: (2)
 
Joined: Nov 2002
Posts: 1,644
From: Lawrence, Kansas
Car Info: 19' Impreza Sport Manual / 99 Miata / 13' OB
Edit, sorry now I see this is up in the messages, I missed it in a quick scan - Sorry

------

I haven't tried this myself but I understand that this will stop the count down to the PC rebooting once you see the window pop up.

Hit the Start menu, select run type in "command" to bring up the command box, then type in "shutdown -a" press enter. There is a space between the n and the - . Then you can go get the patch. I haven't been hit to try it though, a tec support person told me about the command.

Peaty

Last edited by Peaty; Aug 17, 2003 at 12:27 PM.



All times are GMT -7. The time now is 08:00 AM.