Ahhhhhhhhhhhh!

Pookie

Ghetto Fabulous
I NEED HELP! My computer is infected with the msblast worm. I've d/l'ed the security patch from MS and ran it, and I've also tried to remove it manually.....to no avail. After doing so, I've restarted numerous times and the dang thing WON'T go away! What do I do?? Please help me!!!!!!!!!!!!!!
 

Pookie

Ghetto Fabulous
I've also got instructions on how to remove it from the registry, but I'm too skeered to touch it!
 

Otter

Nothing to see here
These may be the same instructions you have Em...don't know what else to tell you

he worm is relatively easy to clean up after detection.

Step one is to patch the infected system against the vulnerability that allowed the worm to "get in" in the first place. This process requires the user of the computer to have administrator level access to the system.

Once the user is logged in again with administrator rights, what they need to do is load up Internet Explorer, and direct the browser to windowsupdate.microsoft.com. The user will be prompted by some pop up windows, directed through a fairly easy to understand and intuitive process.

The next step is to reboot the system.

After the system has rebooted it will be necessary to delete the worm's executable file, msblast.exe. However, its process must be stopped before it can be deleted.

Once the user logs back in with administrator rights, they should load up the "Task manager" again as described above. Click on the "Image Name" field under the "Processes" tab and click once on the "msblast.exe" process. Press "End Process" to stop it from running.

The worm's executable file will be found in the system32 directory, which is a subdirectory of (by default) the "winnt" directory in Windows 2000 machines, and the "windows" directory in Windows XP installations.

Use Windows Explorer to navigate to the system32 directory, locate the mblast.exe file and delete it. Reboot your system. Done!

The final step, removing the registry key created by the worm, is optional. It isn't really that important -- the key simply causes the worm to start every time the system is re-booted, but once the worm file itself is deleted it's redundant anyway.

This is done manually by using the registry editor. It is important to note that making incorrect changes to the registry can have catastrophic consequences.

Load the registry editor by clicking on the start button, navigating to "Run..." and typing in "regedit". Run regedit and navigate to the following "key".

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

In the right hand section of the registry editor, the following value will be found:

"windows auto update"="msblast.exe"

Delete it.

Reboot. Done!
 

Otter

Nothing to see here
Originally posted by ememdee19
I've also got instructions on how to remove it from the registry, but I'm too skeered to touch it!

Thats the only way you are gonna get rid of it, Em...every reboot will bring it back unless you edit the registry.
 

Pookie

Ghetto Fabulous
Originally posted by otter
Thats the only way you are gonna get rid of it, Em...every reboot will bring it back unless you edit the registry.

Thanks, Otter and 2A!!!!
 

Pookie

Ghetto Fabulous
K - not sure if the virus is gone b/c I haven't ran another scan yet. I do however get the error report from MS everytime I re-start:

C:\DOCUME~1\MCCART~1\LOCALS~1\Temp\WER1B.tmp.dir00\FireDaemon.EXE.mdmp
C:\DOCUME~1\MCCART~1\LOCALS~1\Temp\WER1B.tmp.dir00\appcompat.txt

Claims it's a FireDaemon.exe error. Anybody have a clue wth this is?
 

Pookie

Ghetto Fabulous
Still haven't fixed the virus. Everything I've tried has been unsuccessful. Contacted my ISP and they couldn't even help me.......:frown:
 
Top