Advertisement
Promo

Security management Toolkit

Networks must counter triple threat

John McCormick

Published: 21 Aug 2003 12:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Symantec has also made available a free Blaster removal tool that deletes instances of the worm files and eliminates the registry values it adds. Other vendors' sites with removal instructions or tools include F-Secure, McAfee, and Trend Micro.

For those who can read this report but can't stay online long enough to download either the patch or one of the removal tools, here is some hands-on help offered by Global Hauri, which markets ViRobot Experthi.

Global Hauri's Blaster removal instructions

    Disconnect your computer from the network.
    Reboot the computer in Safe mode by hitting the [F8] function key (top row of the keyboard) while rebooting and choosing the Safe Mode option.
    Wait until boot process is completed in Safe mode.
    Open Task Manager by simultaneously pressing [Ctrl][Shift][Esc] and then select the Processes tab.
    Find and highlight msblast.exe from Processes tab.
    To kill msblast.exe, click the End Process button in the bottom of the Processes window.
    Click Start and select the Search button. (It looks slightly different in WinNT, Win2K, and WinXP.)
    Choose All Files and Folders, type msblast.exe, and then search the entire hard disk. (If you have more than one drive, search them all.)
    Delete all msblast.exe instances from the search window.
    Reboot in Normal mode and plug in to the network.

Now you will be able to install antivirus software (or update the latest antivirus definitions) and the Microsoft security patch. For advanced users, Global Hauri recommends this extra step: Go to the registry and remove the key reg. msblast.exe from
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
184 out of 358 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a Teufel Cinebar 50 system

Win a Teufel Cinebar 50 system

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters