Americas

  • United States

Fixing infected Windows boxes

Opinion
Aug 25, 20032 mins
Networking

Several of our Windows computers have been acting strange, and we suspect we’ve been compromised by MSBlast or some variant. Can you elaborate on the root kits you mentioned last week – what do they do? And is the only fix for this attack to reformat the

Several of our Windows computers have been acting strange, and we suspect we’ve been compromised by MSBlast or some variant. Can you elaborate on the root kits you mentioned last week – what do they do? And is the only fix for this attack to reformat the computer?

One root kit we found had installed an mIRC client that was sniffing passwords off the network and sending them back to an IRC channel. The system was riddled with copies of Trojans based on klandoor and aristotles.

Symantec, McAfee, Microsoft and others have tools that clean up a system without reinstalling everything, when starting from scratch is not an option. Look for and remove anything named msblast.exe from the hard drive and from the registry. Get stinger from www.nai.com and run that. Get the W32Blast removal tools from Symantec and run that. Get TheCleaner from Moosort and run that. Install the Microsoft RPC patch. Install all your critical Windows updates. Install the MS RPC patch again. Back up everything. Update your virus software. Boot into safe mode, run a virus scan and search your computer for new directories under system and system32.