http://www.symantec.com/
Ive just been struck by the worm that is going around. If your pc comes up with a message and starts to shut down you must go to the above website and read the information. I found a program running in my task manager called MBLAST.exe if you see that in your processes in your task manager click on it and end the application this will stop your pc from shutting down and enable you to update your anti virus and remove it. Access your task manager by pressing ctrl+alt+del once and look in processes. If you dont have MBLAST.exe running in there THEN UPDATE YOUR ANTIVIRUS NOW !!!! This worm has hit Sydney this morning and is running wild everywhere.
EpharGy
13-08-2003, 12:19 AM
yer, theres been like threads on just about every forum ive looked at
How to clean up after the MSBlast worm
3:30 PM August 12
The MSBlast worm has caused widespread infection on the Internet. This ZDNet Australia analysis contains infection information, detection strategies, and clean up instructions.
Infection.
The worm exploits a widely publicised 'DCOM' vulnerability found in several versions of Microsoft Windows. While the vulnerability affects Windows NT4, Windows 2000, Windows XP and Windows Server 2003, the worm only infects Windows 2000 and XP.
Because the method by which the vulnerability is exploited varies between the two operating systems, there have been numerous confirmed reports of the worm "crashing" systems. This happens when a worm uses a Windows 2000 exploitation technique on an XP machine and vice versa. The worm will use the Windows XP method 80 percent of the time, and the remaining attempts are directed at Windows 2000.
It is worth noting that an updated version of the worm could affect other Microsoft operating systems, so it is recommended that all of our readers patch their systems against the DCOM vulnerability.
Detection.
The worm is very easily detected by users.
Pressing control-alt-delete, then clicking on "Task Manager" and selecting the "Processes" tab will bring up a list of processes running on the machine. Clicking on "Image Name" will sort the processes alphabetically. If there is a process named "msblast.exe" running on the system, then it has been infected by the worm.
Clean up.
The worm is relatively easy to clean up after detection.
Step one is to patch the infected system against the vulnerability that allowed the worm to "get in" in the first place. This process requires the user of the computer to have administrator level access to the system.
Once the user is logged in again with administrator rights, what they need to do is load up Internet Explorer, and direct the browser to windowsupdate.microsoft.com. The user will be prompted by some pop up windows, directed through a fairly easy to understand and intuitive process.
The next step is to reboot the system.
After the system has rebooted it will be necessary to delete the worm's executable file, msblast.exe. However, its process must be stopped before it can be deleted.
Once the user logs back in with administrator rights, they should load up the "Task manager" again as described above. Click on the "Image Name" field under the "Processes" tab and click once on the "msblast.exe" process. Press "End Process" to stop it from running.
The worm's executable file will be found in the system32 directory, which is a subdirectory of (by default) the "winnt" directory in Windows 2000 machines, and the "windows" directory in Windows XP installations.
Use Windows Explorer to navigate to the system32 directory, locate the mblast.exe file and delete it. Reboot your system. Done!
The final step, removing the registry key created by the worm, is optional. It isn't really that important -- the key simply causes the worm to start every time the system is re-booted, but once the worm file itself is deleted it's redundant anyway.
This is done manually by using the registry editor. It is important to note that making incorrect changes to the registry can have catastrophic consequences.
Load the registry editor by clicking on the start button, navigating to "Run..." and typing in "regedit". Run regedit and navigate to the following "key".
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
In the right hand section of the registry editor, the following value will be found:
"windows auto update"="msblast.exe"
Delete it.
Reboot. Done!
GateKeeper
18-08-2003, 12:07 PM
for fucks sake!
I just got infected as well.
Why cant the ppl who create these lame-ass things just Get a FUCKING life??
Polar
18-08-2003, 06:08 PM
no idea why, it is pretty sad isn't it, the people who make these things :(
glad i haven't got it though :)
Powered by vBulletin™ Version 4.0.6 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.