blaster worm terrorizing my comp!

hitchhiker13

New member
Local time
10:34 AM
Messages
10
Out of nowhere, my computer got the blaster worm. I can't open any programs, antivirus protectors, or removal tools unless I'm in safe mode. Apparantly, the most popular way to get rid of it is to use malwarebytes in safe mode (no network). I did this, but the problem persists. What now?
 

My Computer

OS
Windows 7 Home Premium x64
Give this tool a try. Read the entire article, save/print the instructions, then d/l the tool & run it.

W32.Blaster.Worm Removal Tool

W32.Blaster.Worm Removal Tool | Symantec

This tool is designed to remove the infections of:

W32.Blaster.Worm
W32.Blaster.B.Worm
W32.Blaster.C.Worm
W32.Blaster.D.Worm
W32.Blaster.E.Worm
W32.Blaster.F.Worm

Important:
W32.Blaster.Worm exploits the DCOM RPC vulnerability. This is described in Microsoft Security Bulletin MS03-026, and a patch is available there. You must download and install the patch. In many cases, you will need to do this before continuing with the removal instructions. If you are not able to remove the infection or prevent re-infection using the following instructions, first download and install the patch.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various

My Computer

Computer Manufacturer/Model Number
Hopalong/ Godzilla
OS
Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
CPU
Intel Core i7-870 Lynnfield 2.93GHz LGA 1156 95W Quad-Core
Motherboard
ASUS P7P55D-E PRO
Memory
8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GB
Graphics Card(s)
ASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit GDDR5
Sound Card
VIA Onboard
Monitor(s) Displays
Asus VS248H-P 24"; Samsung SyncMaster 941BW 19"ws
Screen Resolution
1920x1080; 1440x900
Hard Drives
Samsung 830 120GB SSD
Intel 320 120GB SSD
Western Digital Caviar Black WD7501AALS 750GB 7200 RPM SATA 3.0Gb/s
Western Digital Caviar Black WD6401AALS 640GB 7200 RPM SATA 3.0Gb/s
PSU
COOLER MASTER Silent Pro RS850-AMBAJ3-US 850W Modular
Case
COOLER MASTER HAF 932 RC-932-KKN5-GP Black
Cooling
Scythe "Mugen-2 Rev.B" (2 ScytheKaze-Jyuni PWM fans)
Keyboard
Logitech K-320
Mouse
Kensington
Antivirus
Avast Inernet Suite
Browser
IE 9 ; Chrome
Give this tool a try. Read the entire article, save/print the instructions, then d/l the tool & run it.

W32.Blaster.Worm Removal Tool

W32.Blaster.Worm Removal Tool | Symantec

This tool is designed to remove the infections of:

W32.Blaster.Worm
W32.Blaster.B.Worm
W32.Blaster.C.Worm
W32.Blaster.D.Worm
W32.Blaster.E.Worm
W32.Blaster.F.Worm

Important:
W32.Blaster.Worm exploits the DCOM RPC vulnerability. This is described in Microsoft Security Bulletin MS03-026, and a patch is available there. You must download and install the patch. In many cases, you will need to do this before continuing with the removal instructions. If you are not able to remove the infection or prevent re-infection using the following instructions, first download and install the patch.

Didn't do me any good. It says i need network administrator permission. Even though i am the administrator. And the virus made it so there is no option of running it as administrator.
 

My Computer

OS
Windows 7 Home Premium x64
I also tried using R-Kill and SuperAntiSpyware in safe mode, but that didn't help either.
 

My Computer

OS
Windows 7 Home Premium x64
Hi,

Can you post the log of when you ran Malwarebytes in Safe Mode?

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 8090

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

11/5/2011 11:56:35 AM
mbam-log-2011-11-05 (11-56-35).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 29295
Time elapsed: 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{6AE00F2C-62F7-41B5-83A6-B0CC6959CBC4} (Adware.ShopToWin) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{15C039C3-F230-4706-9CAA-DE476AAB02AC} (Adware.ShopToWin) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{59D4DC90-68D2-4321-988D-625E118F7DE6} (Adware.ShopToWin) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FCSB000063943.Shopping.1 (Adware.ShopToWin) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FCSB000063943.Shopping (Adware.ShopToWin) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6AE00F2C-62F7-41B5-83A6-B0CC6959CBC4} (Adware.ShopToWin) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{6AE00F2C-62F7-41B5-83A6-B0CC6959CBC4} (Adware.ShopToWin) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6AE00F2C-62F7-41B5-83A6-B0CC6959CBC4} (Adware.ShopToWin) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\program files (x86)\shop to win 21\shop to win 21.dll (Adware.ShopToWin) -> Quarantined and deleted successfully.
c:\Users\Sheil\AppData\LocalLow\fcsb000063943\Toolbar\shoppingbho.dll (Adware.ShopToWin) -> Quarantined and deleted successfully.
 

My Computer

OS
Windows 7 Home Premium x64
Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 8090

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

11/5/2011 1:22:17 PM
mbam-log-2011-11-05 (13-22-17).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 420707
Time elapsed: 38 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cd Tools updater (Trojan.Agent) -> Value: cd Tools updater -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msi system tune (Trojan.Agent) -> Value: msi system tune -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\default drivers checker (Trojan.Agent) -> Value: default drivers checker -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Sheil\AppData\Local\Temp\0.8942148782947734.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.
c:\Users\Sheil\AppData\Local\Temp\ikstun.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Sheil\AppData\Local\Temp\gnstvn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Sheil\AppData\Local\Temp\rhgpv.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 

My Computer

OS
Windows 7 Home Premium x64
This is not the blaster worm, it's a plain trojan/scareware/virus infestation.
 

My Computer

Computer Manufacturer/Model Number
Asus N73SV
OS
Windows 7 x64 Ultimate SP1
CPU
Core i7-2630QM
Motherboard
Intel HM 65
Memory
6 GB DDR3
Graphics Card(s)
Nvidia GT 540M / Intel HD 3000 - Optimus switching
Sound Card
HD Audio (Intel Azalia/Realtek) ALC269
Monitor(s) Displays
LED flat panel
Screen Resolution
1920 x 1080
Hard Drives
2x Seagate Momentus 640 GB - 1,28 TB in total
Internet Speed
4 MB/256 kbps
Other Info
External HDs

WD Elements 1,5 TB
WD MyBook 500 GB
but it says that it is a blaster worm. The fake privacy protection program pops up as soon as I log into my computer, and at the bottom on the tool bar, a constant stream of popups appear saying that ".....isn't working due to Win32_blaster worm."
 

My Computer

OS
Windows 7 Home Premium x64
"Rogue programs like Trojan Agent are used to scare people into buying unneeded programs because they claim your computer is at risk, or give falsified scan results and put their own malware in your system, according to Malware Bytes."
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
Please download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

Next, flush the DNS cache and restore MS's Hosts file

Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop. Right click on the flush.bat file to run it as Administrator. Your computer will reboot itself.

Update and run a full scan with MBam and post the results.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top