PDA

View Full Version : MSBlaster or something else?????


Kevn
27 Aug 2003, 07:27 PM
A friend recommended I come to this forum with my recent enclave of computer issues.

I was getting that whole RPC service termination message about two weeks ago. I ran Symantec's Fix Blast (which told me I didn't have the virus) and it seemed to go away. A couple of days ago, the messages came back. Last night, when I went to turn my computer (Dell Latitude notebook running XP Professionl), Windows started, but there were no icons or Start button on my screen. When I bring up the task manager and look at the processes, I find several items called "svchost.exe", but no "MSBlast.exe". When I try to end those processes, they keep reappearing and the same RPC service termination message appears.

I reinstalled Windows twice now. I tried doing all the things listed on Symantec's website. When I tried to install the XP Firewall, I got another error message. I ran the Fix Blast program again and it still said I didn't have the virus. But when I restarted, I went back to the blank screen with no icons.

Anyone have any ideas??

Thanks in advance,
Kevin

Timbuktu
27 Aug 2003, 07:45 PM
Weirdness. if the search blaster is coming up empty then you probably don't have it. i'd suggest doing two things.

not really sure what to say, except
1) make sure your virus definitions are current
2) make sure you've got a good program on your computer to find and remove spyware. Ad-Aware by Lavasoft is a good program for it. The basic build build is free and can be downloaded here:
http://www.lavasoftusa.com/support/download/

once you've got the ad-aware and your virus definitions are current, I'd recommend booting your machine in Safe mode (hit F8 right as the machine boots up and keep pressing it a couple times until you get the screen that gives you the option of running things in safe mode.)

once you're in safe mode, scan for any and all viruses, and then scan for any spyware.

i'd suggest trying that, or else just giving Dell a phone call

DogStarMan
28 Aug 2003, 11:56 AM
You probably got the Blaster worm's evil twin brother Welchia (http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html). It tries to fix the Blaster worm, but causes a host of other problems. The first thing you need to do before troubleshooting this stuff is make sure the virus definitions on your PC are current. Once that's done, then your virus scan should tell you what's going on. It sounds like your system is pretty hosed right now, and if it were me, I'd be pulling out the old delpart floppy and starting fresh. Dell support is your best bet, because, at this point, you're beyond casual message board help.

RichmondVA
28 Aug 2003, 12:23 PM
Almost everyone has multiple copies of svchost.exe on running on their machine. A lot of programs use that process. It's quite possible a virus is using svchost, but it could just as easily be nothing.

There's a MS Resource tool called tasklist or tlist that you can download. It gives you further info on what programs are using which processes (including svchost).

DogStarMan
28 Aug 2003, 12:33 PM
Yah, you are definitely right about the svchost RVA. I can't tell you how many users I get calls from freaking out about this service running.

From what I understand of Kevin's situation, he has installed Windows XP over top of itself a couple of times while a virus was still making itself at home and is now getting a blank screen. Even if he gets the op sys up and running again, I have a feeling that it will never be quite right. Sometimes trying to fix a MS op sys is harder than just wiping the drive and doing a re-install. That is, unless you have some valuable data on the hard drive that you want to hang on to. In that case, maybe a parallel install of XP on another drive might help you out of that mess. Either way, I think there's just too much going on here to even tell Kevin where to begin. Make the call to Dell and may god have mercy on your soul.

BTW....click (http://www.bbspot.com/News/2003/08/dell_tech_support.html)

Kwyjibo
28 Aug 2003, 08:16 PM
Originally posted by DogStarMan
BTW....click (http://www.bbspot.com/News/2003/08/dell_tech_support.html)

Somebody reads Fark...

I told Kev you guys would come through... thanks for not making me look silly. Now if he'd just post here now and then...

MissKitty
28 Aug 2003, 09:15 PM
Kev is a friend of Kwyj? Hell yeah, you MUST post more often matie.

DogStarMan
29 Aug 2003, 07:58 AM
Originally posted by Kwyjibo
Somebody reads Fark...
I read Fark (http://www.fark.com) from time to time, but I read BBSpot (http://www.bbspot.com) every week. I like geek jokes better than poop jokes. :D

Kevn
29 Aug 2003, 01:50 PM
I would love to post here more often. It would help if I can get my POS laptop to work first. :(

Kevin

Kevn
02 Sep 2003, 04:53 PM
So calling Dell was about as useful as tits on a bull. They kept me on hold for 25 minutes, then tried to transfer me to a "software specialist," but before I could speak to said specialist, I would have to buy a support package since my problem is "software-related." It looks like the entire thing needs wiped out and started over. I tried the repair option in windows setup, but it just sent me to a c:/windows> dos prompt. I have no idea what to do from there.

Should I just damn the torpedos and start the whole friggin thing over?? I managed to get all the data I "need" onto another hard drive, so that's really not a concern right now. I also have a "ResourceCD For Reinstalling System Software" from Dell that I haven't played with yet. I have been using the Windows XP CD. Any ideas???

Thanks a lot for all your help!

Kevin

RichmondVA
02 Sep 2003, 08:32 PM
If you've backed up your data, start all over.

If thing I've realized is that the more people know about fixing PC's, the more they are prone to simply reformat rather than try to repair. It's just not worth the hassle.

Kevn
02 Sep 2003, 10:46 PM
I'm a little dumb when it comes to reformatting a hard drive. I really have no idea how to go about doing it. If someone could either walk me through it over email (mrmain18@yahoo.com), AIM (AutogphHnd), or direct me to a website that would give me decent instructions, I would greatly appreciate it.

Thanks a lot (once again),
Kevin

DogStarMan
03 Sep 2003, 10:26 AM
Bring it over to my house, I work for beer :D

Or, you could look here. (http://pcsupport.about.com/library/weekly/aa082602a.htm)

RichmondVA
03 Sep 2003, 10:34 AM
Or "Format c:" Why, of course you're sure! Would you have typed it if you weren't sure? Hell no so shut your sassy hole. :P

Seriously, you want to follow the steps on DogStarMan's url. The process itself is very simple, you just want to make absolutely certain you have everything you need before you erase your whole drive.

Kevn
03 Sep 2003, 11:11 PM
So I'm a WHOLE LOT dumb when it comes to this reformatting thing. I tried following the instructions on that website. I couldn't create a startup disk. Do I even need it since I have the drivers and utilities disk from Dell?? Will a simple "format c:" do the trick??? I can bring a cooler of beers if someone can help...

Kevin

RichmondVA
03 Sep 2003, 11:26 PM
Yeah dude. You need that startup disk.

"Format c:" works in the sense that it will reformat your drive. Unfortunately you can't do anything on a blank formatted drive. That's where the startup disk comes in.

When you format your drive, you wipe out your Windows operating system and also key information about your system (because those things were stored on the drive you just erased). The startup disk lets you boot up your machine and enter simple commands.

jccalhoun
04 Sep 2003, 07:52 AM
If you have a fairly recent computer it may boot from teh cd. Put the cd in the conputer and reboot, if it starts up narmally, then it doesn't. If it starts the reinstall/reformat then it does and you don't need a boot disk.