Blaster Worm

drlove

Ph.D. in Pussyology
Oct 14, 2001
4,778
130
63
The doctor is in
Just a couple of questions about the "blaster worm"...

I downloaded Microsoft's patch the other day from their site; does that mean I am protected??

Also, if infected, can using the "system restore" function or installing the recovery disks get rid of the worm and return the system to normal??
 

Stumpy

Member
May 31, 2003
115
0
16
I had one of our employee's computer come down with it the other day. Used McAffee 7.0 and followed the instructions on the McAffee website. No problem to remove. Mostly the virus scanning and cleaning (or deletion) worked automatically to remove the msblast stuff. Checked the registry and nothing was to be found in there regarding it anymore.

The nasty part of the virus is the fact that it shuts you down after 30 minutes, then less time between shutdowns, until you're about 1 minute between shutdowns.

One thing I figured out was to unplug the ethernet cable from the back of the system, thus preventing (or perhaps defeating) the RPC's that ultimately cause the reboot.

Follow the instructions regarding disabling the RPC as well as the system restore. However MAKE SURE YOU PUT THOSE SETTINGS BACK after you have done the update and virus scan.

McAffee 7.0 didn't come with the newest upgrades, even though I bought the package that day. You'll need to get online to be able to download the newest, so you'll definitely need to disable the RPC's.

Also was able to use Norton AntiVirus 2003 on another system to get the patches, and found they had pretty much the same instructions as McAffee.
 

Kev

Crap
Jul 29, 2003
549
0
0
Vancouver
Good point stumpy

Everyone should get the latest virus definitions. There are so many viruses out there 65000 i believe at last count.

I discovered i had a new virus (as of August 5th) called Backdoor Hale. (no guys i'm not talking about anal here Hah hah!!) This virus allows unauthorized remote access to an infected computer. They can get at passwords and such. It was easy to get rid of, but a pain nonetheless.

I since installed a Firewall, soooo come and get me now ya little vermon.....ya want a piece of me.....BITCHES... i'll show ya what i got...i'll give ya little of this and a little of that, along with a couple of those.....ya petty, insignificant, little vermon.

I think Symantec own Norton and McAfee.....i think. --- Kev
 

Stumpy

Member
May 31, 2003
115
0
16
Symantec=Norton, McAfee is on it's own.

Careful 'bout the firewall though, our employee was behind a cable router, with it's own firewall. Still nailed him.

Seems that blaster is (forgive if the terminology is incorrect) a semi-sniffer. Your IP is randomly targeted, a small package arrives, which opens up a port (135 if I remember) and then downloads the rest of the more damaging code.
 

pussylicker

Prosopagnosia Sufferer
Jun 19, 2003
1,659
0
0
Doing laps at the Y
JML, that seems like an awfull lot of work. I went to the Symantec site and downloaded Blaster worm removal tool. It found one contaminated file and deleted it. No problems since. Didn't get patch like some people did. I've done the Norton virus scan every day since, and it's clean
 
Ashley Madison
Toronto Escorts