PDA

View Full Version : Security Breach in Windows


philipwhiteold
08-11-2003, 11:53 PM
If you havent already downloaded the patch make sure to do so immediately. I got hit with this today. Its not fun to clean up. It affects Windows NT, 2000, and XP. There are links to the patches in the news announcement on MS's site.

Microsoft Anouncement (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp)

petertdavis
08-14-2003, 11:37 AM
How did you get hit with that? I thought it only went after networks?

philipwhiteold
08-14-2003, 04:02 PM
Apparently not. It hit my dads personal computer too. Symantec has a tool to erase to erase the worm although its not too hard to do manually.

BTW thanks for stopping by Peter.

YaSO
08-17-2003, 07:06 AM
I presume that most people resolved the problem by now, but in case that you are still having a problem ...

Chances are that your machine is infected by the worm W32.Blaster.Worm. I suggest that you do the following:

1. Terminates the W32.Blaster.Worm viral processes.

Alt-Ctrl-Dlt brings up a task manager; go to processes and find msblast.exe or ... similar names. Right-click and terminate processes.

2. Delete the W32.Blaster.Worm files.
3. Delete the dropped files.
4. Delete the registry values that the worm added.

After you take the step 1, your machine should not shut down. You can following the rest of the steps 2, 3, and 4, but you can just download FixBlast.exe from here http://securityresponse.symantec.com/avcen...er/FixBlast.exe (http://securityresponse.symantec.com/avcenter/FixBlast.exe).

You may want to check the following two sites for details

http://securityresponse.symantec.com/avcen...moval.tool.html (http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html)
http://www.ootpdevelopments.com/board/show...ad/t-41539.html (http://www.ootpdevelopments.com/board/showthread/t-41539.html)

philipwhiteold
08-17-2003, 01:33 PM
Thanks for the link Yaso. I used the Symantec cleaner when I got rid of the worm. It took awhile to scan the computer but it did the job.