How to Remove MSBLAST.exe
worm virus
(updated to include information on Variants A-G)
Read
about the Welchia or MSBLAST.D worm
What is
the MSBLAST.EXE worm aka Blaster.A, LoveSan or Msblast.A?
Download the Windows patches for this vulnerability by clicking on the links below: These Windows vulnerabilities are patched by using Windows Update to download all the critical updates for your system. However in some cases, people have reported getting an error 0x800A138F when trying to download updates. If you are receiving an error similar to this, read Marc Liron's excellent article about solving this at his updatexp.com website. What is the DCOM Vulnerability? The DCOM vulnerability in Windows 2000 and XP can allow an attacker to remotely compromise a computer running Microsoft® Windows® and gain complete control over it. The worm causes a buffer overrun in the Remote Procedure Call (RPC) service. When this service is terminated the virus infects the machine and then tries to infect other machines. What are the Symptoms of the MSBLAST worm? You'll see a screen similar to the one below when you are infected, this will countdown to zero and literally shut down the system completely. The warning will state "This shutdown was initiated by NT AUTHORITY\SYSTEM". The message will read Windows must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly.
You can disable this shutdown by following the steps below during the countdown
This will terminate the shutdown, however in most cases the system may be to unstable to try to recover and may need to be rebooted anyway. How Does MSBLAST Infect My Computer?
The worm contains the following text, which is never displayed: I
just want to say LOVE YOU SAN!! Windows 2000 Machines On Windows 2000 machines, I have seen the Control Panel icons switch to the left pane, functions like FIND in the browser stop working, and many other oddities. How Can I Remove the MSBLAST worm? Follow these steps in removing the MSBLAST or MSBLASTER worm. 1) Disconnect your computer from the local area network or Internet 2) Terminate the running program
3) Install the patches for the DCOM RPC Exploit, you can download the patches from the links below before disconnecting
4) Block access to TCP port 4444 at the firewall level, and then block the following ports, if they do not use the applications listed:
5) Remove the Registry entries
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>Current Version>Run
6) Delete the infected files (for Windows ME and XP remember to turn off System Restore before searching for and deleting these files to remove infected backed up files as well)
7) Reboot the computer, reconnect the network, and update your antivirus software, and run a thorough virus scan using your favorite antivirus program. 8) Now check for the worm again, if it returns, complete these steps once more until the virus is gone. With the patch in place, the virus wont be able to exploit the system, but sometimes it is difficult to remove the files for good. For Automatic Removal of MSBLAST, download the Symantec removal tool, you'll still need to download the patches above and install them, however this removal tool will stop the MSBLAST program from running, remove the items in the registry, and delete the infected files. You can find more information about this worm by visiting Symantec's or TrendMicro's pages on this worm Microsoft's Page on What You Should Know About the Blaster worm
|
Tools for Removing Spyware, Adware, and Malware PC HELL Welchia (Dllhost.exe and SVCHost.exe) Worm Removal Uninstall Antivir Instructions How to Manually Run the Microsoft Malicious Software Removal Tool Bloodhound.Exploit.6 Virus Removal Backdoor SDBot.H Trojan Removal
|
| Recommended Software for PC Hell Visitors | |||||
![]() Start FREE Scan... |
FREE Registry
Scan! Clean, repair, and optimize your system with the leading and award-winning Registry Booster from Uniblue. Registry Booster is the safest and most trusted solution to clean and optimise your system, free it from registry errors and fragmented entries. Through Advanced Error Detection Technology, Registry Booster automatically identifies missing, corrupt, or invalid items in your Windows registry and dramatically enhances performance and general stability. |
![]() Start FREE Scan... |
FREE Performance Scan! Now, you can get a faster, cleaner, and safer PC within minutes - without being a Windows expert! SpeedUpMyPC automatically finds the best settings for your PC and carefully controls your system resources to give you the best performance. Easy to use, this award-winning utility has all the features you could ever need to clean up your system, monitor resources, and improve performance. |
![]() Start FREE Scan... |
Free Spyware Scan! |
![]() including Ad-Aware SE, Norton Antivirus, and Mozilla Firefox |
![]() Perfect Uninstaller |
![]() Spy Sweeper |
|
Search PCHELL.COM |
|
|