Page 1 of 2 12 LastLast
Results 1 to 15 of 24

Thread: Symantec: W32.Blaster.Worm Removal Tool

  1. #1
    Super Moderator Super Moderator Big Booger's Avatar
    Join Date
    Apr 2002
    Location
    JAPAN
    Posts
    10,941

    Symantec: W32.Blaster.Worm Removal Tool

    Step 1. Patch Your System with the appropriate MS03-026 Patch

    Step 2. After Installation of the Patch, Reboot your system.

    Step 3. run "FIXBLAST".exe to remove the MSBLAST.exe file, terminate the process and remove added registry keys by the worm.

    Step 4. Reboot your pc one last time.

    W32.Blaster.Worm Removal Tool

    Source
    Last edited by Reverend; August 12th, 2003 at 09:33 AM.

  2. #2
    Titanium Member Tinker's Avatar
    Join Date
    Apr 2002
    Location
    Indiana U.S.A.
    Posts
    1,064
    Thanks BB... Removal tool says computer is clean and patch is installed..


  3. #3
    Super Moderator Super Moderator Big Booger's Avatar
    Join Date
    Apr 2002
    Location
    JAPAN
    Posts
    10,941
    Good to know you won't be hit by this worm. I know it felt good having a little assurance that it won't happen to me.

  4. #4
    My Name is.... TZ Veteran Stripe's Avatar
    Join Date
    Oct 2002
    Location
    live?
    Posts
    892
    I got hit with this one on Sunday

    Haven't had a chance to patch and clean yet....

    Interesting behavior:
    Sygate reported tft.exe trying to access a port for tiny file transfer protocol. Of course I said no to this and kept browsing the web. About a minute later, I received a message that there was a problem with my RPC locator service and that the pc will shut down in 1 minute.

    If I disabled internet access, the RPC error did not re-occur.

    Once I updated the virus definations, Norton actually started picking it up but would not remove it.

    I'll be running the removal tool later today.

    Thanks for the post Big Booger.

  5. #5
    Friendly Neighborhood Super Moderator phishhead's Avatar
    Join Date
    Apr 2002
    Location
    San Diego, Ca.
    Posts
    3,732
    I'm all clean. I always cover my Jimmy. Always practice safe sex on the net.



  6. #6
    all bets are off... TZ Veteran SupaStar's Avatar
    Join Date
    Jul 2002
    Location
    Australia
    Posts
    1,680
    Originally posted by phishhead
    I'm all clean. I always cover my Jimmy. Always practice safe sex on the net.
    And in real life kiddies

  7. #7
    Techzonez Governor Super Moderator Conan's Avatar
    Join Date
    Apr 2002
    Location
    Philippines
    Posts
    4,343
    Originally posted by SupaStar
    And in real life kiddies
    Phishy doesn't need to cover his Jimmy any longer to avoid kids.

  8. #8
    Friendly Neighborhood Super Moderator phishhead's Avatar
    Join Date
    Apr 2002
    Location
    San Diego, Ca.
    Posts
    3,732
    Originally posted by Conan
    Phishy doesn't need to cover his Jimmy any longer to avoid kids.
    hey conan thats hitting below the belt.



  9. #9
    Super Moderator Super Moderator Big Booger's Avatar
    Join Date
    Apr 2002
    Location
    JAPAN
    Posts
    10,941
    Alert the authorities, there has been a thread hijack.



  10. #10
    Member Bee-Jay's Avatar
    Join Date
    Apr 2002
    Posts
    92
    Nice Big, Nice

  11. #11
    Near Life Experienced TZ Veteran zipp51's Avatar
    Join Date
    Oct 2002
    Location
    Massachusetts
    Posts
    1,114
    All clean here till the next one.Thanks for the quick references BB.
    The definition of insanity is doing the same thing over and over again and expecting different results.

  12. #12
    all bets are off... TZ Veteran SupaStar's Avatar
    Join Date
    Jul 2002
    Location
    Australia
    Posts
    1,680
    Originally posted by zipp51
    All clean here till the next one.
    So true

  13. #13
    Super Moderator Super Moderator Big Booger's Avatar
    Join Date
    Apr 2002
    Location
    JAPAN
    Posts
    10,941
    I wonder if running a Linux gateway, would this worm wiggle through?

    Just a thought.

  14. #14
    Titanium Member
    Join Date
    Jul 2002
    Location
    blk helo target, WA
    Posts
    3,536
    No wiggling worms in Phishead's jimmy.

  15. #15
    Titanium Member Tinker's Avatar
    Join Date
    Apr 2002
    Location
    Indiana U.S.A.
    Posts
    1,064
    I just got this from my ISP....

    IMPORTANT: Immediate action required to safeguard your computer from Phase Two of the MSBlast.exe virus

    Dear Comcast Customer,

    Have you taken the necessary steps to help ensure that your computer is clean and protected from the second phase of the MSBlast.exe virus or LovSan Web Worm? If not, we recommend that you immediately follow our suggested steps below.

    The MSBlast.exe virus or LovSan Web Worm may enter your computer through a vulnerability in your computer's Microsoft Windows®-based operating system. According to current reports, this virus or worm is designed to cause computers to launch an electronic attack against Microsoft's Windows® help web site on August 16, 2003.

    Here we go again.....

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •