praxis22 opened this issue on Aug 12, 2003 ยท 81 posts
Darboshanski posted Tue, 12 August 2003 at 7:41 PM
Hi All, I was hit by this virus also. It is called W32 Blaster worm or Lovsan worm and infects your system threw your internet connection at port 135 on window based systems such as ME, NT, Win 2000 and XP. It is a global virus that was launched yesterday and has effected thousands and has invaded many ISPs. You will get these error window messages: "Generic Host Process for WIn32 Services has encountered a problem and needs to close". "This shutdown was iniatiated by the NT AUTHORITY/SYSTEM windows must restart now because the Remote Procedure Call(rpc) serivice terminated unexpectingly". This virus causes your machine to crash and reboot over and over until the virus is removed and you have downloaded and installed the latest security patch from Mircosoft. Here are some links which may help: You can download the latest security patch here: http://www.microsoft.com/security/incident/blast.asp This site has a very good removal tool for this blaster worm virus: http://securityresponse.symantec.co...aster.worm.html http://us.mcafee.com/virusInfo/default.asp?id=lovsan If you use any removal tools please remeber that the System restore option must be turned off in WinXP before you run the removal tool. If not the virus will no be removed and will continue each time you boot up. Also, getting the patch is very recommended Zone Alarm does effectively block port 135 (if you keep it enabled). If you would like to test that port, to be sure, go to GRC.com and run the ShieldsUp program. Hope this helps and best of luck! Miche