blaster worm

S

setho

It seems that I have the blaster worm or something like it, and I'm
having a hard time getting rid of it. My computer (Windows XP Home,
SP1) periodically shows a message about a Remote Procedure Service
call and needing to restart, and then does restart. I have fairly
recent definitions for Norton Antivirus but that doesn't seem to help
since that program won't stay open for more than a few seconds. It
starts but closes again almost immediately. Same thing with regedit
and with the Microsoft patch WindowsXP-KB823980-x86-ENU that I'm
trying to use to take care of the vulnerability that got me into this.
Moreover, and perhaps unrelated, I am not able to turn on the
Internet Connection Firewall for my highspeed internet connection. I
see the option on the Advanced tab in the properties for that
connection, but it's greyed out and unresponsive. I do have
administrative priveleges. I have run the symantec blaster and welch
removal programs and both reported no infected files. I don't see
anything in task manager that is clearly identifiable as a blaster
process but my CPU usage displays as 100% with nothing running that
I've initiated so I suspect that something unsavory is happening. I
have run searches on the file names listed on the microsoft blaster
page (msblast, teekids, winlogin, penis32, win32sock, and a couple
others that I don't recall) and found nothing.

I think that's everyting that I've read on the various blaster
postings in this group and others, as well as on the symantec and
microsoft sites so it seems that I'm at the end of the road. Any
other suggestions would be greatly appreciated.
 
S

setho

I think I've fixed this. There was a file called syscf32.exe in my
WinNT/System32 directory and it had registry settings that launched it
at startup. When I disabled that using the backup SysConfig tool from
the kelly's korner website that gets referenced in a lot of blaster
notes, I found that NAV, regedit, and the ms patches worked when they
hadn't before. Having deleted that file and removed all references to
it from the registry, things seem to be working correctly. There were
a couple of other files in system32 that were exactly the same size as
syscf32 and modified in the last couple of days (winhlpp32.exe and
wupmgr.exe.poly) that I removed too although I couldn't find them in
the registry.

Seems wierd that NAV wouldn't find these. Maybe it's something new,
or maybe I've misinterpreted all of my results and I'm still infected,
having removed some vital system resource. If anybody knows whether
those files really were from a worm or virus I'd be glad to get some
confirmation on that.

I'm still not sure why I can't turn on my windows Internet Connection
Firewall so if anybody out there could give me some advice on that,
I'd be most grateful.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

RPC reboot - blaster worm 3
blaster worm 3
New Blaster Virus? 3
blaster again 5
Blaster Worm Relapse????? 7
Blaster worm 5
blaster worm 2
XP and Blasted Blaster Worm 2

Top