Showing posts with label Worms. Show all posts
Showing posts with label Worms. Show all posts

Tuesday, 25 January 2011

How to Remove W32.Blaster.Worm (Uninstall Guide)

W32.Blaster.Worm is one of the most wide spread worms ever that was first noticed in August, 2003. It spreads by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (BID 8205). This vulnerability was fixed, a patch is available here: Microsoft Security Bulletin MS03-026. This computer worm targets machines running Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003. Apple, Unix and other platforms can not be infected. When executed, the Blaster worm attempts to retrieve a copy of the file msblast.exe, penis32.exe, teekids.exe, mspatch.exe, mslaugh.exe or enbiei.exe from the host that compromised the computer. Downloaded file is saved in the Windows system folder. The infected computer then scans the internet and local networks looking for vulnerable computers.

Other variants of Blaster Worm:
  • W32.Blaster.A.Worm
  • W32.Blaster.B.Worm
  • W32.Blaster.C.Worm
  • W32.Blaster.D.Worm
  • W32.Blaster.E.Worm
  • W32.Blaster.F.Worm
On Windows XP W32.Blaster.Worm can cause the remote RPC service to terminate displaying a message "Windows must now restart because the Remote Procedure Call (RPC) Terminated Unexpectedly". The infected computer might restart every few minutes.



In order to remove Blaster worm from the infected computer you need to install Microsoft patch and then run W32.Blaster.Worm removal tool or remove the worm manually. Accidental computer shut downs prevents the required patch and removal tools from being downloaded and installed. Thankfully, there is an easy way to stop this. Please follow W32.Blaster.Worm removal instructions below.

Important! If you've got the following notification, your computer is infected with a rogue antivirus program and not the original W32.Blaster.Worm.





To remove the rogue antivirus program from your computer, please follow there removal guide here or this removal guide.
However, if you believe that your computer is infected with the W32.Blaster.Worm, please follow the removal instructions below.

Download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer.






W32.Blaster.Worm removal instructions:

1. Select Start -> Run (or press WinKey+R)
2. Type in: shutdown -a
3. Click OK or press Enter.



4. Download and install Microsoft patch MS03-039.
5. Then run W32.Blaster.Worm Removal Tool. You can choose one of these:
6. Restart the computer and re-connect to the internet. You should run Blaster Worm Removal Tool again to ensure that your computer is clean.

7. Download recommended anti-malware software (direct download) and run a full system scan to remove this worm from your computer.

The worm can download additional malware onto your computer. We have to make sure that your computer is not infected with other malicious software, specifically trojan downloaders.


W32.Blaster.Worm manual removal instructions:

1. Download and install Microsoft patch MS03-039.
2. Press Ctrl+Alt+Delete or Ctrl+Shift+Escape. You should now see the Windows Task Manager or a screen where you can select the Task Manager to be run.
3. Click on the Processes tab.
4. Look for a process(es) named msblast.exe, penis32.exe, teekids.exe, mspatch.exe, mslaugh.exe, enbiei.exe in the list
5. Click the process(es) to highlight it and then click the End Process button. Close Task Manager.
6. Open Windows Registry Editor (click Start -> Run. Type Regedit and click OK or press Enter).
7. Locate the HKLM\Software\Microsoft\Windows\CurrentVersion\Run entry.
8. In the right hand pane select windows auto update = msblast.exe and delete it.
9. Restart the computer and re-connect to the internet.

10. Download recommended anti-malware software (direct download) and run a full system scan to remove this worm from your computer.

The worm can download additional malware onto your computer. We have to make sure that your computer is not infected with other malicious software, specifically trojan downloaders.


W32.Blaster.Worm files and registry values:

Files:
  • C:\Windows\System32\msblast.exe
  • C:\Windows\System32\penis32.exe
  • C:\Windows\System32\teekids.exe
  • C:\Windows\System32\mspatch.exe
  • C:\Windows\System32\mslaugh.exe
  • C:\Windows\System32\enbiei.exe
Registry values:
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "windows auto update"="msblast.exe"
Share this information with other people:

Monday, 15 March 2010

How to remove Worm.Win32.Netsky (Free removal)

Worm.Win32.Netsky is a fake infection, false system security threat. Another commonly reported fake infection is Win32.Netsky.Q. You may find some references of infections called W32.Netsky or Email-Worm.Win32.NetSky on the Internet. These infections are real, but please note that "Worm.Win32.Netsky" is not related to them. It's fake infection that appears on fake security warnings that usually come from fake (rogue) anti-virus programs.

This fake alert may come in various forms. It is used by newly created malware, so there are many new fake alerts every day that reports Worm.Win32.Netsky infection in compromised infections. Usually, fake security warning appears with the following title:

"Security alert
Security Warning!
Worm.Win32.Netsky detected on your machine"

And it may look like this fake warning in the image below.



If you area reading this article, then your computer is probably infected with trojans or rogue program that display fake Worm.Win32.Netsky infection. Thankfully, there is a way to remove this infection from your computer for free using legitimate anti-malware programs.

Also note that trojan viruses that display this fake infection my also change your desktop background and disable Windows system tools such as Task Manager and Registry Editor or even block antivirus programs. That's why you will have to end malicious process related to Worm.Win32.Netsky first. That would be: winlogon86.exe and winupdate86.exe. Of course, there might be other malicious processes too, but these are most common ones. Now, please follow the removal instructions below. If you have any questions, don't hesitate and ask or leave a comment if you have something valuable to add. Good luck and be safe!


Worm.Win32.Netsky removal instructions:


1. Download iexplore.exe (NOTE: iexplore.exe file is renamed HijackThis tool from TrendMicro).
Launch the iexplore.exe and click "Do a system scan only" button.
If you can't open iexplore.exe file then download explorer.scr and run it.

2. Search for such entries in the scan results:
F2 – REG:system.ini: Shell=Explorer.exe logon.exe
F2 – REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe
O4 – HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
Select all such entries and click once on the "Fix checked" button. Close HijackThis tool.

3. Download the file LSPFix.zip and extract it into a folder on your PC.
Launch LSPFix. Place a tick in the "I know what I'm doing".
In the KEEP box select winhelper86.dll and press ">>" button.
Press Finish>> button. Wait while LSPFix removes winhelper86.dll and displays a summary. Press OK.

4. Download one of the following legitimate anti-malware applications and run a quick system scan. Don’t forget to update it first. All programs a free.
NOTE1: if you can't run any of the above programs you must rename the installer of selected program before saving it on your PC. For example: if you choose MalwareBytes then you have to rename mbam-setup.exe to iexplore.exe, explorer.exe or any random name like test123.exe before saving it.

NOTE2: if you still can't run the renamed file then you need to change file extension too not only the name.
1. Go to "My Computer".
2. Select "Tools" from menu and click "Folder Options".
3. Select "View" tab and uncheck the checkbox labeled "Hide file extensions for known file types". Click OK.
4. Rename mbam-setup.exe to either test123.com or test123.pif
5. Double-click to run renamed file.


Worm.Win32.Netsky files and registry values:

Files:
  • C:\windows\system32\winhelper86.dll
  • C:\windows\system32\winupdate86.exe
  • C:\windows\system32\winlogon86.exe
  • C:\windows\system32\AVR10.exe
  • C:\windows\system32\critical_warning.html
Registry keys and values:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe

Share this information with other people:

Thursday, 7 January 2010

What is Koobface and how to get rid of it?

Koobface is a computer worm that spreads via social networks site such as Facebook, Bebo or MySpace. The latest variant of this worm targets mostly Facebook likely because this site has more than 400 million members and the number grows each day. Koobface uses various misleading methods to fool people into installing it. Very often cyber criminals use fake video or greeting cards websites. The worm comes as a flash player update or a free greeting card. Once downloaded, it makes a copy of itself in %WINDOWS% (usually C:\Windows) directory. Koobface creates a file called freddy[RANDOM MUNBER].exe. For example:
  • freddy35.exe 
  • freddy36.exe
  • .....
  • freddy40.exe
  • freddy34.exe
  • .....
  • freddy79.exe
  • and so on.
As you can see the main process may be different in each compromised computer. Then Koobface worm connects to particular domains and downloads even more malware onto your PC. Finally, it starts sending malicious messages from your Facebook account. More information about this virus: detailed Koobface description and removal instructions.