Security Basics mailing list archives

Re: Purging Blaster.worm


From: Martchukov Anton <vhlist () yandex ru>
Date: Thu, 14 Aug 2003 01:17:33 +0400

On Tue, 12 Aug 2003 17:06:38 -0700
"Jose Guevarra" <jose () iquest ucsb edu> wrote:

Hi,

 Has anyone successfully purged the MSBlaster worm. There is a tool
 out
there that can do it but is it reliable?

thanx,

My friend just called me to help him purge it.
I don't know about a tool, but here is what I've done:

First, I've killed msblast.exe task in task manager, than I removed
msbalst.exe and scan registry for "msblast". There was a only one
item "windows update" in registry and I simply removed it. 

Next I set up firewall at-guard and disabled inbound trafic to ports
135-139 and 445. Since I've done it, I may go on-line safely. IMHO it
was very difficult to find and download a patch from microsoft's site,
but I did it. 

That's all, I hope the worm was purged.

-- 
Martchukov Anton aka VH ========================================      
---------------------------------------------------------------- 
E-mail: vhlist () yandex ru    
ICQ: 155279978                     Registered Linux User #323324
================================================================

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: