>
> Date: Tue, 12 Aug 2003 16:38:28 +1200
>
> It's a virus (apparently quite new). I have a client that has the same
> problem (known as W32.Blaster.Worm at Symantec site).
>
> You need to install the Windows XP Security Patch as follows.
>
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
> bulletin/MS03-026.asp
A strong suspicion of something being loaded during startup prompted me to
check the Startup List. It did show up a strange name "msblaster.exe". There
was also an accompanying "pf" file deposited under "\Windows\Prefetch\" so I
deleted them both manually. The virus probably still has a stealth payload
which caused the system to continue re-booting after sometime. My suspicion
is that the "routine" has to do with accesing the ports-- so, I installed a
Firewall and the MS Patch.It did block the ports concerned.. end of problem!
Thanks to all those who replied and offered information.
Greg
Do you want to signoff PCSOFT or just change to
Digest mode - visit our web site:
http://freepctech.com/pcsoft.shtml
|