Quantcast

W32/Blaster worm corrective action

The CERT Coordination Center has issued Steps for computer users to take if their computer has been been infected by the W32/Blaster worm.

1. Physically disconnect the machine from the network. (remove phone cord, cable, dsl, wireless card)

2. Kill the "msblast.exe" process in the Task Manager.

2a. CTRL-ALT-DELETE
2b. Click "Task Manager" button
2c. Select "Processes" tab
2d. Highlight "msblast.exe"
2e. Click "End Process" button (note that this will bring up a Warning dialog box which a user needs to answer "Yes")

3. Delete any files named "msblast.exe" on the machine.

3a. Start -> Search -> Find Files or Folders
3b. Search for "msblast.exe"
3c. For each match:
3c1. Right-click, select delete

4a. Disable DCOM on all affected machines

From
<http://microsoft.com/technet/treeview/default.asp?url=/technet/
security/bulletin/MS03-026.asp>

4a1. Run Dcomcnfg.exe.

If you are running Windows XP or Windows Server 2003 perform these additional steps:

* Click on the Component Services node under Console Root.
* Open the Computers sub-folder.
* For the local computer, right click on My Computer and choose Properties.
* For a remote computer, right click on the Computers folder and choose New then Computer. Enter the computer name. Right click on that computer name and choose Properties.

4a2. Choose the Default Properties tab.

4a3. Select (or clear) the Enable Distributed COM on this Computer check box.

4a4. If you will be setting more properties for the machine, click the Apply button to enable (or disable) DCOM. Otherwise, click OK to apply the changes and exit Dcomcnfg.exe.


4b. Enable ICF:

From <http://support.microsoft.com/default.aspx?scid=kb;en-us;283673>

4b1. In Control Panel, double-click Networking and Internet
Connections, and then click Network Connections.

4b2. Right-click the connection on which you would like to enable
ICF, and then click Properties.

4b3. On the Advanced tab, click the box to select the option to
Protect my computer or network.

4b4. If you want to enable the use of some applications and services through the firewall, you need to enable them by clicking the Settings button, and then selecting the programs, protocols, and services to be enabled for the ICF configuration

5. Reboot the machine and reconnect to the network.

6. Install the patch from Windows Update, or MS03-026.

6a. Using Internet Explorer, go to http://www.windowsupdate.com and
follow the instructions there to install any available patches.

7. Read and apply the clean up measures outlined in MS03-026.

<http://microsoft.com/technet/treeview/default.asp?url=/technet/
security/bulletin/MS03-026.asp>
 

Tenchiro

Attention K Mart Shoppers
Jul 19, 2002
5,407
0
New England
Originally posted by SwisSlesS
Are a lot of the computers in your office up and running yet?
We run a mixed environment of 98/2000/XP. It looks like most of the XP computers were hit the hardest. I think SP3 for 2000 fixed the problem and most of our 2000 computers are running fine.
 

Tenchiro

Attention K Mart Shoppers
Jul 19, 2002
5,407
0
New England
Originally posted by dh girlie
Crap...I'm seeing all these different fixes...which one should I use? I'm not very computer technical, but I know I have this damn virus on my home computer...HELP!
Disable the RPC service (Control Panel -> Admin Tools -> Services -> Remote Procedure Protocol). Right Click -> Properties -> Stop.

Then update windows, update your virus scanner then run it on your entire hard drive.
 

dh girlie

MISS MISSY (geek)
Originally posted by Tenchiro
Disable the RPC service (Control Panel -> Admin Tools -> Services -> Remote Procedure Protocol). Right Click -> Properties -> Stop.

Then update windows, update your virus scanner then run it on your entire hard drive.
K...ummm...where do I get the windows and norton updates...just off their sites? I never know which one to choose...I have windows 2000.
 

Tenchiro

Attention K Mart Shoppers
Jul 19, 2002
5,407
0
New England
Originally posted by dh girlie
K...ummm...where do I get the windows and norton updates...just off their sites? I never know which one to choose...I have windows 2000.
Norton can update it self just right click on the icon in your system tray there should be an update option, and if you go to microsoft.com they have an update to d/l.
 

dh girlie

MISS MISSY (geek)
Originally posted by Tenchiro
Norton can update it self just right click on the icon in your system tray there should be an update option, and if you go to microsoft.com they have an update to d/l.
OK...well this am before I left for work I started running the virus scan thingy....but never checked back on it...what a pain in the ass...are there people out there that are so geeky and jones'n for something to do that they gotta start this crap?
 

shocktower

Monkey
Sep 7, 2001
622
0
Molalla Oregon
Originally posted by dh girlie
OK...well this am before I left for work I started running the virus scan thingy....but never checked back on it...what a pain in the ass...are there people out there that are so geeky and jones'n for something to do that they gotta start this crap?
What do you think gurly gurly ;) ;) ;) ,and the they have small junk to ;) ;) ;) ,so their really pissed off :eek: :eek: ,BTW I got mine at MS look at DL`s and there will be a patch for this problem :D :D :D ,got the info from my geek bro inlaw he`s one of those IT guy`s ,but way cool ;)