Forum Moderators: phranque
There is some application msblast.exe which has suddenly appeared on my computer (which I noticed via the task manager). I have windows 2000.
Now, I can't open any window by right-clicking on a link & selecting
"open a new window", neither am I able to doan uninstall from the "Control Panel > Add/Remove program", simply because when I click on "Add/Remove program" option in CP, it doesn't display anything. In short, many applications are not responding and I feel like my comps been hijacked.
I tried looking for msblast.exe in google to learn more about it, but can't find anything.
Does anyone have an idea whats happening?
[added] Another potential clue could be the svchost.exe file. Windows suddenly gave an error that this particular file has done an error or some message like that, and now I see this msblast.exe
I can't do a ctrl+c or any basic functions as well[/added]
Block access to TCP port 4444 at the firewall level, and then block the following ports, if they do not use the applications listed:TCP Port 135, "DCOM RPC"
UDP Port 69, "TFTP"
More on the topic: Here [securityresponse.symantec.com]
Just install a decent firewall (e.g. Zone Alarm) and keep your computer patched.
d_
I an only see the bullets, images, etc, but no text. But if I open the page source and read it, everything looks fine.
Don't know what is causing this! Anyone...
thank you for your help
when i ran the ms patch it created its own restore point from what i could tell
is there anything else i need to do?
I got the virus day before, and I simply did the following steps to get rid of it.
- Got this file and did a scan: [www3.ca.com...] [which almost removed the worm)
- Went to registry using the Run > Regedit & searched for "msblast", and removed the entry.
- Downloaded SP2 [microsoft.com] from Microsoft & did a patch.
- Furthermore, downloaded the RPC patch [microsoft.com] and did another patch as well. {I think you need SP2 (service pack 2) installed before you can install this particular patch.
And that done, my pc's quick as ever :)
Read these articles on how to clean your infected pc:
[zdnet.com.au...]
[webadvantage.net...]
[securityresponse.symantec.com...] [tool for removal]
Perhaps as some sites mentioned, you may not be able to remove the msblast.exe application from task manager, because it may be in use.
The best way to stop it is to download a msconfig substitute program from [mlin.net...] and installing it.
Then go to: Start > Settings > Control Panel > Startup > HKLM/RUN & deselect the msblast.exe (and also deleting that key from there). Then restart your pc and follow other steps as mentioned above.
Lastly, download a good firewall like Zone Alarm Pro from www.zonelabs.com (buy it or crack it) and keep it running.
A Must Read from the Microsoft site: [microsoft.com...]
Webmaster World is it possible we could have a new forum for all Security, Viruses and Firewall issues.
The ever ending increase of the viruses and hoaxes are making headaches for many.
Just a thought.
I just did a control+Alt+delete and the worm is running on my computer but I see any performance issues at all, or any of the problems I have heard about.
Can anyone tell me why I have it but no symptoms?
Thanks,
The advice he gave me was total rubbish and was more harmful than the dam virus! Any way I bought myself a firewall, deleted the thing by hand and that was that.
The shop assistant stated he was wiping the harddrives of 18 customers PC's a day, horrific figure, and totally over board.
Guess theres a lesson there.
Does anyone know where it came from?
I just did a control+Alt+delete and the worm is running on my computer but I see any performance issues at all, or any of the problems I have heard about.
5stars, make sure that when you did the Ctrl+Alt+Del that it was not this topic in IE that you were seeing. Because of the title of this thread, some may mistakenly think that msblast.exe is running on their system when in fact it is your IE browser displaying the title of the page you are viewing. ;)
msblast.exe - Microsoft Internet Explorer
P.S. It also appears that this msblast.exe does not affect older OS like Win98 which I am still running.
Customers not infected by the virus:
1. Educate the customer of the virus and direct the customer to review the Microsoft security bulletin (http://www.microsoft.com/security/security_bulletins/ms03-026.asp) and download the recommended fix.
2. Inform the customer that Microsoft is experiencing a high volume of calls due to this virus and offer online resources to the customer.
3. If the customer wishes to speak to an SP, despite the potential wait time, follow existing call handling procedures per the KB and CRT.
Customers who are infected by the virus:
Inform the customer you can walk them through steps to restore the stability of their system. These steps will:
· Stop the system from rebooting every few minutes
· Patch the system and stop the vulnerability from being exploited again
· Update the customer’s antivirus signature and help to protect them from re-infection and clean any malware resulting from the infection
· It is important that the customer clean their systems using software from their antivirus vendor after applying the fix from Microsoft
1. Extend restart settings
a. Click Start, select Run, and type services.msc.
b. Scroll down and double click Remote Procedure Call.
c. Select the Recovery tab.
d. Click the Restart Computer Options button.
e. Change Restart computer after from one to 30 minutes.
f. Click OK.
g. Click Apply and then click OK on the Remote Procedure Call (RPC) Properties window.
h. Close the Services window.
2. Enable Windows Connection Firewall (ICF)
a. Open the Control Panel, double-click Networking and Internet Connections, and then click Network Connections.
b. Right-click the current Internet or Network connection, and then click Properties.
c. On the Advanced tab, click the check box to select the option to Protect my computer or network.
3. Direct the customer to apply the patch for Security Bulletin MS03-026 by going to one of the following locations:
Option 1
· Connect to [microsoft.com...]
· The customer can download the update through the Windows Update site by selecting the link “Get this and other available Windows updates”
Option 2
· Connect to [microsoft.com...]
· Select “Blaster Worm: Critical Security Patch for Windows XP”
4. Note The above steps will not remove the virus from the customer’s system. Customers should visit a Microsoft Virus Information Alliance partner available at one of the below links:
· Network Associates:
[us.mcafee.com...]
· Trend Micro:
[trendmicro.com...]
· Symantec:
[securityresponse.symantec.com...]
· Computer Associates:
[www3.ca.com...]