View Full Version : MSBlast virus!!! (WORM)
http://www.microsoft.com/downloads/details.aspx?FamilyID=2354406c-c5b6-44ac-9532-3de40f69c074&displaylang=en
that to prevent it
http://securityresponse.symantec.com/avcenter/FixBlast.exe
that to find and get rid of it....
This virus adds the value:
"windows auto update"="msblast.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Runso that the worm runs when you start Windows.
This has left people unable to connect to the internet to download virus updates or fixes. To remedy this remove the offending registry entry or run "msconfig" and untick "MSBlast.exe" on the startup tab.
Yeh, I updated my defs last night. 3 mins later found the virus.
Either use the above tool or find the file in system32 folder scan it, quarintene it then delete from quarintene.
Then windows update time :) to prevent it getting in again
Ahh, the benefits of a hardware firewall... :)
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp
You can find the patches here. Windows update is a tad busy atm :P
Not even 9:00 and I've had 3 laptops in with the virus on it :/
yeah any firewalling at all stops this virus aside from that sifnt automatic updates daily!!
everyone's all paranoid about how this virus WILL get u the second u use the net, esp with XP ppl, simplest initial fix is to have the XP built-in firewall enabled on your connection coz thats meant to stop it by default. most of the worry's should be of local traffic that usually isnt firewalled, but then thats what the patch is there to stop :D
meh so many ppl hit by a virus that shouldnt have got a look in :P
gee i sound cocky, but shit i'm sick of "woe is me, virus hates me.." no offence to any1, just venting :twisted:
You sure XP's built in firewall would stop it? Everything i've read says it get's in via a hole in XP's security.
It uses an exploit to get in via a couple ports, which XP's firewall actually manages to block. So it is good for something.
At work (RMIT), I figured the whole uni would be safe from it, unless some idiot brought in a laptop with it... and guess what happened in teh city campus today? Someone bought in a laptop and put it on the network... The amount of traffic basically crippled everything. Was funny, because I'm protected out here. ;)
haha, we had the same worry, if a laptop came in would be our threat, but we made that priority 1 that any laptops that came back in were checked and patched before uplinking.
another win for 99% of the office still being on windows 98 :D
Yeh we took our n/w offline for 1/2 hr and made sure all our servers where patched & checked for the virus.
lol my dads comp that shares the net to me and my sis runs win 98 so wee dun have a problem
lol can't say much bout me mums laptop
i finished cleanin it last night
btw if u have the virus boot in safe mode to run the eradicator thing (thx skull)
-smurf
vBulletin® v3.8.4, Copyright ©2000-2012, Jelsoft Enterprises Ltd.