»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 08-14-2003, 07:59 PM   #1 (permalink)
Registered User
 
Join Date: Aug 2003
Posts: 6
aragorn6969 is on a distinguished road
Outdoors MSBLAST MUTATION please help....

Hi I have two computers both with XP. I them both infected by the MSBLAST worm but the thing is that one of them actually had MSBLAST.EXE and the other one didn't.
I managed to solve the problem in the first one, but in the second one there is NO MSBLAST.EXE. I downloaded MCafee FIREWALL and avoid the computer to keep restarting but the virus is still inside that one.
have you heard about something like this??
i think that maybe is a file on XP called SVCHOST.EXE??
could that be??

aragorn6969 is offline   Reply With Quote
Old 08-14-2003, 08:05 PM   #2 (permalink)
Guest
Guest
 
Posts: n/a
http://housecall.trendmicro.com/


run this see if it finds its and cleans it
  Reply With Quote
Old 08-14-2003, 08:17 PM   #3 (permalink)
Registered User
 
Xeroid's Avatar
 
Join Date: Oct 2001
Location: Georgia
Posts: 2,712
Xeroid is on a distinguished road
SVCHOST.exe is a Windows file. The error message you would get would mention SVCHOST.exe before your PC did an automatic shutdown. SVCHOST.exe isn't the problem. MSBLAST.EXE is the problem. Microsofts description of what SVCHOST.exe does:

http://support.microsoft.com/?kbid=314056

Are these two XP machines networked? I beleive that if one machine is infected it will take the other machine down if they are networked. I had the same thing happen to me. I had the MSBLAST worm on a WinXP machine and the other Win2000 machine would crash. I never found any evidence of infection on the Win2000 machine and now that I've got the WinXP machine cleaned up my Win2000 machine has started running properly.

Have you been over to Symantec to download the removal tool? Download it and run it a couple of times. If it finds nothing you're golden.

http://securityresponse.symantec.com...oval.tool.html

Have you applied the Microsoft patches? Look here:

http://www.microsoft.com/technet/tre...n/MS03-026.asp

Download the Microsoft patch, update your antivirus, and download the Symantec removal tool.

Run the Microsoft patch

Run the Symantec removal tool.

Run a full scan of your antivirus.

If nothing is found you should be OK.

EDIT: sorry I hit the respond button too soon.


Last edited by Xeroid; 08-14-2003 at 08:30 PM.
Xeroid is offline   Reply With Quote
Old 08-14-2003, 08:29 PM   #4 (permalink)
Registered User
 
Join Date: Aug 2003
Posts: 6
aragorn6969 is on a distinguished road
the thing is that they are not connected in a network
thanks
aragorn6969 is offline   Reply With Quote
Old 08-14-2003, 08:32 PM   #5 (permalink)
Registered User
 
Xeroid's Avatar
 
Join Date: Oct 2001
Location: Georgia
Posts: 2,712
Xeroid is on a distinguished road
Quote:
Originally posted by aragorn6969
the thing is that they are not connected in a network
thanks
OK, I fixed the link for the Symantec removal tool. Download it and the one GroundZero3 linked to and run both of them. See if you come up with anything.
Xeroid is offline   Reply With Quote
Old 08-14-2003, 08:56 PM   #6 (permalink)
Registered User
 
Xeroid's Avatar
 
Join Date: Oct 2001
Location: Georgia
Posts: 2,712
Xeroid is on a distinguished road
I was looking at the Symantec site again and there are variants that don't use MSBLAST.exe. They use *****32.exe and TEEKIDS.exe.

The Symantec removal tool will clean the W32.Blaster.Worm, W32.Blaster.B.Worm, and the W32.Blaster.C.Worm.

Mike
Xeroid is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:59 PM.