The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Blaster worm won't let me use restore partition...now what?

    Discussion in 'Security and Anti-Virus Software' started by Mitlov, May 20, 2013.

  1. Mitlov

    Mitlov Shiny

    Reputations:
    2,681
    Messages:
    5,689
    Likes Received:
    909
    Trophy Points:
    281
    A couple days ago, while conducting some benign searches on the internet (NOT adult content...I was looking for comparison reviews between two .357 revolvers), I seem to have picked up a W32 blaster worm on my Duo 11. Windows Defender didn't prevent it from downloading and installing itself it seems. Now I can't open any program, and Windows Defender is not picking it up on virus scans. It's throwing warnings about a W32/blaster.worm, but it's not actually able to pick it up when it does a full scan of the system. What looks to me to be a fake/malicious screen meant to look like antivirus scanner starts up whenever I boot my machine.

    And to make matters worse, when I try to use the Windows Reset function or whatever it's called (return to factory defaults), it says some or all of the necessary files are missing from the recovery partition. Well, without a DVD drive to make or use recovery media, I was counting on the restore partition.

    Now what?
     
  2. Rodster

    Rodster Merica

    Reputations:
    1,805
    Messages:
    5,043
    Likes Received:
    396
    Trophy Points:
    251
    Dumb question but is your software malicious tool from MS up to date? Try executing the program because that's what it's good for.

    Free Malware Removal Tool | Anti-Malware Scan Software

    The Microsoft Malicious Software Removal Tool is an anti-malware utility that checks computers running Windows 8, Windows 7, Windows Vista, Windows XP, Windows 2000, Windows Server 2012, Windows Server 2008, and Windows Server 2003 for infections by specific, prevalent malicious software—including Blaster, Sasser, and Mydoom—and helps remove malware and any other infections found.

    EDIT: start RUN command and enter MSRT. That will manually start the program. You could also try Malwarebytes
     
  3. Mitlov

    Mitlov Shiny

    Reputations:
    2,681
    Messages:
    5,689
    Likes Received:
    909
    Trophy Points:
    281
    Screenshot:

    [​IMG]

    EDIT: Thanks Rodster, I'll check it out.
     
  4. Rodster

    Rodster Merica

    Reputations:
    1,805
    Messages:
    5,043
    Likes Received:
    396
    Trophy Points:
    251
    I can't expand the picture, so can't read what's on the screen. What OS W7 or W8? ;)

    In the future you should elevate UAC to the highest setting. You will get more prompts from the OS.
     
  5. Mitlov

    Mitlov Shiny

    Reputations:
    2,681
    Messages:
    5,689
    Likes Received:
    909
    Trophy Points:
    281
    Windows 8. As for the winking face, yes I know you hate Windows 8, but is it relevant to whether I would have gotten this malware or what I do to get rid of it?

    Nothing exciting was happening on the edges of the screen--what I wanted to focus on was the "Internet Security: designed to protect" window which I think is part of the malware (I use Windows Defender, not anything called "Internet Security") and the bubble saying that "ThumbnailExtractionHost.exe is infected by W32/blaster.worm Please activate Internet Security to protect your computer"

    ...which now that I think of it, makes me think that the entire blaster worm thing is a false flag. Because that pop-up in the bottom left is part of the malware too, and what malware would ever properly identify itself?
     
  6. Rodster

    Rodster Merica

    Reputations:
    1,805
    Messages:
    5,043
    Likes Received:
    396
    Trophy Points:
    251
  7. Mitlov

    Mitlov Shiny

    Reputations:
    2,681
    Messages:
    5,689
    Likes Received:
    909
    Trophy Points:
    281
    I followed your link and it's running right now...been running for about fifteen minutes so far (doing the full scan, of course). Thanks for that link.

    The Malicious Software Removal Tool didn't catch it but Malwarebytes did. Thanks very much for the tip. And now Malwarebytes has a loyal paying customer.
     
  8. Rodster

    Rodster Merica

    Reputations:
    1,805
    Messages:
    5,043
    Likes Received:
    396
    Trophy Points:
    251
    Glad to hear you got it sorted, also good to know that MS malicious software tool doesn't really do anything. It was a while back but I got hit with a virus trying to watch a car repair video. That's why I now set UAC to it's highest level.