What is this?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nunnycat21, Aug 20, 2004.

  1. nunnycat21

    nunnycat21 Private E-2

    I am having a problem that I hope someone will be able to help me with.

    My virus scan pops up and says that I have some type of worm virus. The problem is that when I try to either quarantine this virus or delete it an error message pops up that says "RPC service terminated unexpectedly. NT authority \system initiated shutdown". It restarts my computer and I don't know how to get rid of it. I ran a regular virus scan and it showed nothing. It also says "Generic host process for Win32 has encountered a problem and needs to close". I don't know what that is either. Any help would be appreciated.

    Michelle
     
  2. Hipster Doofus

    Hipster Doofus MajorGeek

    Microsoft have a patch for it. To get it though (there is another way but I can't remember) you will have to get a firewall & turn it on. That will stop it.

    In Xp right click network on the desktop or in the control panel then properties. Right click your ISP then properties. Go to Advanced. Turn it on.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. nunnycat21

    nunnycat21 Private E-2

    The firewall inside Windows XP is on. It shuts itself down about every 30 minutes. I do not know much about computers and I have no clue as what this could be or what to do to stop it. Thanks for you replies.

    Michelle
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First fix the MSblast problem. See my message below.
     
  6. nunnycat21

    nunnycat21 Private E-2

    I downloaded all the updates I need and the tool to remove the worm,but when I try to run the tool a window pops up to stop me from continuing. It says something about me needing MS03-26. I don't know what to do to get rid of this thing. Thanks for any help.

    Michelle
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do this:
    To end the Blaster worm process

    • Press Ctrl+Alt+Delete.
    • Click the Task Manager button.
    • Click the Processes tab.
    • Click the Image Name column header to sort the processes alphabetically by name.
    • Look for a process named Msblast.exe. If you find it, click the name to select the process, and then click the End Process button.
    • Close the Task Manager
    And then run the tools.
     
  8. nunnycat21

    nunnycat21 Private E-2

    I did that but that name isn't in there. I don't know if it could be using a different name or what. Is there something else I could try? I appreciate the help you have given me. Thanks.

    Michelle
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome Michelle.
    What OS are you running and which tool did you run when you got that message about needing MS03-026?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oops I forgot, you mentioned WinXP and the firewall already.
     
  11. nunnycat21

    nunnycat21 Private E-2

    My OS is Windows XP home edition. I had just finished downloading the Blaster worm removal tool and when I went to open it that error message popped up. It says that I can't run the worm removal tool because I don't have a file/update called MS03-26. Maybe there is a way around that or something I can do to be able to open the worm removal tool. Thanks again.

    Michelle
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to be specific. Which tool, from which link? If you mean the one from MS, try the links I gave you on MGs specifically, this one: W32.Blaster.Worm Removal
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. nunnycat21

    nunnycat21 Private E-2

    I downloaded the Symantec Blaster Worm removal tool. It scanned everything and then a report popped up that it had deleted 2 infected files. I hope that fixed everything. Is there anything else you think I should do to prevent this from happening again or to clean my system? Thanks alot for all your help.

    Michelle
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What kind of connection to the internet do you have? Dial-up, ADSL, Cable?
     
  16. nunnycat21

    nunnycat21 Private E-2

    I have Dial-up.

    Michelle
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! This is why I asked. I wanted you to go here:
    http://v5.windowsupdate.microsoft.com/v5consumer/default.aspx?ln=en-us

    and click on Express Install, to check for High Priority updates required on your PC. I don't know how out of date you are. There could be a bunch and some could be large. You should check and start downloading some of them. You can choose which ones to do. If there are a lot of them, only choose one or two at a time. Observe their sizes as you do that. Choose security type updates first. Anything for Windows Media Player and DirectX you can wait to do later.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here are some simple steps you can take to reduce the chance of infection from a variety of malware in the future. I strongly encourage you to do them all.

    1) Visit Windows Update: (we are working on this one already)
    Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
    a. Windows Update: http://v5.windowsupdate.microsoft.com/v5consumer/default.aspx?ln=en-us

    Do this at least once a month.

    b. Never add any site to your Trusted Sites Zone.

    2) Anti Virus : make sure you have one and keep it updated. Here are some good free ones:
    http://majorgeeks.com/download1968.html Avast
    http://majorgeeks.com/download886.html AVG
    The top two hands down. Better than Norton or McAfee!
    Only run ONE AV!

    3) Firewall: if you don't have one get one of these below. The last two are free versions:
    Don't care if your on dial up or High Speed....you must have a firewall
    http://majorgeeks.com/download738.html Kerio Personal Firewall
    http://majorgeeks.com/download3356.html Sygate Personal Firewall Free
    http://www.majorgeeks.com/download388.html ZoneAlarmFree

    4) Get a Temp File/Cookies/index.dat cleaner
    http://majorgeeks.com/download4191.html CCleaner (Crap Cleaner)

    5) SpyWare Prevention (These prevent, they are not scanners. Scanners are listed later.)
    http://majorgeeks.com/download2859.html SpyWare Blaster
    http://majorgeeks.com/download3045.html SpyWare Guard

    6) SpyWare Scanners/Removers
    http://majorgeeks.com/download2471.html SpyBot (Use the Immunize feature. I don't activate the TeaTimer)
    http://majorgeeks.com/download506.html Ad-aware SE
     
  19. nunnycat21

    nunnycat21 Private E-2

    Thanks for the information. I am downloading the critical Windows updates I need. I am also going to download Zone Alarm and CCleaner. I already have Spybot Search and Destroy,Ad-Aware,Spyware Blaster,and my anti-virus program is AVG. You have been a great help. Thank you again.

    Michelle
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! Just double check to make sure your Ad-aware SE and SpyBot are up to date.

    You're welcome and good night!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds