MadModder

The Breakroom => The Water Cooler => Topic started by: sbwhart on April 05, 2011, 07:43:07 AM

Title: Help my lap tops bin infected with W32 Blaster worm
Post by: sbwhart on April 05, 2011, 07:43:07 AM
My lap tops has been infected with a virus when I try to open a programe I just get a security warning about Malicious program

and that it can not start due to W32 Balster worm.

Can any of you Guys help me out.

If I had my way I'd hang the bastard who do this stuff,  up by their balls until their eyes opo out.

Stew
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: DavidA on April 05, 2011, 07:59:39 AM
Can you start up in 'Safe Mode' ? 

Dave.
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: lordedmond on April 05, 2011, 09:34:28 AM
This may help Stew


http://www.symantec.com/security_response/writeup.jsp?docid=2003-081119-5051-99


Stuart
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: saw on April 05, 2011, 09:48:44 AM
You can try this: http://www.malwarebytes.org/mbam.php (http://www.malwarebytes.org/mbam.php)
I hope it will help you  :dremel:
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: sbwhart on April 05, 2011, 05:04:39 PM
Thanks for your suggestions Guys, but unfortunately the virus won't let me get onto the internet to down load the patch in-fact I can't do anything on it I'm well a truly stuffed.

A well pissed off Stew

Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: raynerd on April 05, 2011, 05:18:13 PM
Stew, might not work but you could try:

Reboot laptop and keep tapping the F8 key - it`ll boot up in safe mode.
Select to open up in "Safe Mode"
Go to Start --> Accessories --> System Tools --> System Restore

.......and then select an earlier date to restore the computer to. It`ll then reboot your computer.

It might work...certainly worth a try!!

Chris
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: saw on April 05, 2011, 05:38:06 PM
I would say do as craynerd told you, but don't rebot, turn the computer of for 5 minutes. If you just rebot, you can still have the virus in the memmory and that will not help you. :(
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: andyf on April 05, 2011, 07:28:31 PM
Hi Stew,

Apparently, it is a very common worm, so your local computer shop probably has a geek who can kill it off. The instructions below are on the interweb, but I have no idea whether or not they work.

Andy

Please follow the instructions below if you would like to remove W32.Blaster.Worm manually. Please notice that you must follow the instructions very carefully and delete everything that is mentioned. In most cases the removal will fail if one single item is not deleted. If W32.Blaster.Worm remains on your system after stepping through the removal instructions, please double-check by stepping through them again.  
Enable your firewall. If you don't have a firewall installed, click here.  [dunno where that takes you]
Start your computer in safe mode.
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'
In the right pane, delete the value called 'windows auto update', if it exists.
Exit the registry editor.
Start Windows Explorer and delete:
%SystemDir%\msblast.exe

Note: %SystemDir% is a variable (?). By default, this is C:\Windows\System (Windows 95/98/Me), C:\WINNT\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Download all service packs and critical updates from www.windowsupdate.com.
 
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: John Rudd on April 06, 2011, 07:41:24 AM
Stew,

My eldest daughter's  lappie was infected last week...
I too tried to remove it manually by doing a regedit.........

Sadly, it was ineffectual...

So as a last resort I'm having to re-install Windoze  :dremel:   and really I think that is the only real way to ensure its gone, including reformatting the hdd...

So, if you have backup discs for your machine, mebbe worth a shot...?
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: Bogstandard on April 06, 2011, 12:15:24 PM
The boot up in safe mode and system restore to an earlier copy usually works well.

Where people go wrong, is that after you have done it, do a quick check to make sure everything is working as it should, then you must go to Control Panel/System/System Restore and turn off system restore for all disks.

What happens is that the virus will automatically be saved in your system restore files, where your virus protection can't get to it or touch it, and at the first opportunity, the virus can pop up again.

Once you have turned off sytem restore, you will lose all your restore points, but the virus contained within will be deleted as well, so you can then turn back on system restore, and it will start a new file from scratch.


Bogs
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: Pete49 on April 06, 2011, 07:48:42 PM
Some blackpowder down the dvd slot a small trail of bp and a match. :) :D :lol:
A bit too permanant some would say. :lol:
Google it as there is a simple removal method that I used on my old laptop
Cheers
Pete
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: Divided he ad on April 07, 2011, 04:13:04 AM
Dunno what the hell it was but I had some malware thing hit my comp' yesterday.... wiped out the ability to run EXE files??  luckily could run files as an administrator (right click on the short cut and selected it from the popup menu..... else I wouldn't have been able to get the info from here!


Using the method Chris and Bogs described I have managed to recover from it all....

Took me a couple of hours and a few of these  :bang:   Ran full antivirus and anti rootkit sweeps on the restore before I did the bit described by Bogs....


Had to re-install my firefox browser from the program file that was in my machine... Couldn't open a web page till I'd done that.
Then I downloaded and installed the upto date version and then had to re-install my bookmarks from the bookmarks back up... Thought I'd lost them all  :bugeye:


Thankfully it all seems to be ok now  :thumbup:




I think it'd be nice to get my hands on one of these programming types who makes these virus thingies  :hammer: :wack:  :hammer:  :wack:  :hammer: :wack:  :hammer:  :wack:  :hammer:  :wack:






Hope you get yours sorted Stew.







Ralph.
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: sbwhart on April 07, 2011, 03:47:37 PM
Yah oooooo  my little lap top is out of hospital and working like a good un.

 :ddb: :ddb: :ddb: :ddb: :ddb: :ddb: :ddb: :ddb: :ddb: :ddb: :ddb:

I'm going to get a pussy up and hunt down the bum who put the crap on the net.

A happy Stew
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: andyf on April 07, 2011, 04:54:19 PM
I'm going to get a pussy up and hunt down the bum who put the crap on the net.

A happy Stew

To save any transatlantic offence (or offense, even) it might be an idea to amend that to "posse", Stew  :lol:

Glad you got it sorted; in case it ever happens to me, how did you do it?

Andy
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: sbwhart on April 07, 2011, 04:56:31 PM
I wasnt thinking of that sort of pussy

Blush

You havn't seen the size of our cats
 
:lol: :lol: :lol: :lol: :lol: :lol: :lol:

Stew
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: Divided he ad on April 07, 2011, 05:09:20 PM
 :lol:  fair do's Stew I damn near colapsed in pain laughing at that  :lol:



Ralph.
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: Rob.Wilson on April 07, 2011, 05:20:37 PM
I wasnt thinking of that sort of pussy

Blush

You havn't seen the size of our cats
 
:lol: :lol: :lol: :lol: :lol: :lol: :lol:

Stew



I right o Stew  :lol: :lol: :lol: :lol: :lol: :lol: :lol: :lol: :lol: 


Rob
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: sbwhart on April 08, 2011, 01:24:47 AM
I'm going to get a pussy up and hunt down the bum who put the crap on the net.

A happy Stew

To save any transatlantic offence (or offense, even) it might be an idea to amend that to "posse", Stew  :lol:

Glad you got it sorted; in case it ever happens to me, how did you do it?

Andy



Sorry Andy I was so busily laughing it my pussy slip I forgot to answer your ?.

To be honest I didn't fix it, the IT specialist at the school my wife use to teach at fixed it he used the malwarebytes program you guys suggested.

Thanks for all your help.

Stew
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: Divided he ad on April 08, 2011, 06:03:09 AM
  :lol: 
Quote
Sorry Andy I was so busily laughing it my pussy slip I forgot to answer your ?.
   :lol:


And  I thought that it couldn't get funnier.... Stew you're a star  :thumbup:








Ralph.
Title: Re: Help my lap tops bin infected with W32 Blaster worm
Post by: John Swift on April 08, 2011, 08:49:23 AM

Hi  sbwhart

after reading your post I've had a look at my computers

and on both ,the adobe FP_AX_CAB_installer was infected  :(

I used  stinger10101504   from mcAfee


http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/stinger.aspx


the report for my machine - the scan took several hours !!!

Scan initiated on Fri Apr 08 00:20:04 2011
C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
     Found the FakeAlert!fakealert-REP trojan !!!
C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe is infected with the FakeAlert!fakealert-REP virus !!!
C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe could not be repaired.
  Number of clean files: 1302528
  Number of infected files: 1



looking in the "windows folder" on the C drive

its in the folder " downloaded  programs files "

the file is {E288E8F-427F-9522-AC9BF37916A7}

its use while installing the PDF reader

now fixed , I uninstalled the old reader and now have the latest :-  adobe reader x


thanks for the alert

     John