W32/Blaster.Worm - Purchase "Privacy Protection" Scam

View previous topic View next topic Go down

W32/Blaster.Worm - Purchase "Privacy Protection" Scam

Post by Nellabelle76 on Tue 08 Nov 2011, 12:25 pm


I am using a different computer as the infected one cannot connect to the internet.

I am getting a warning that the computer is infected with a W32/Blaster.Worm and that I need to use "Privacy Protection" to repair the problem, then it takes me to a website to purchase this item (which, I am glad to say, I was not stupid enough to do!).

The worm has locked me out of all files, I can't download anything (no internet) or copy any files from a CD and dont have a USB to try.

I have tried putting the system into safe mode but when I press F8 the safe mode screen comes up and freezes and I have to shut the computer down again to get out of it.

I have looked online for a repair but no one seems to have the same problem as me (the safe mode screen freezing and no internet) so I am still not able to repair my system.

I am extremely computer illiterate and really need some help please.



Posts : 1
Joined : 2011-11-08
Operating System : Vista

View user profile

Back to top Go down

Re: W32/Blaster.Worm - Purchase "Privacy Protection" Scam

Post by Gabethebabe on Thu 10 Nov 2011, 5:42 pm

Hi there Nellabelle76 and welcome to GeekPolice!

I am Gabethebabe and I will be helping you with this issue. Before we start some general remarks/rules:
  • Whilst Im helping you, please follow my instructions carefully and do not experiment on your own or accept help from other persons.
  • Feel free to ask questions! Especially if my instructions are not clear. Im here to help, not confuse you.
  • I will try and respond quickly, but please understand I do have a real life (job, wife, 3 kids, kinky hobbies).
  • Stick with me till the end. If your computer starts running better, doesnt mean it is clean yet!


Your computer is infected with rogueware. It is good that you have a clean computer available too, so you can download the tools we need and bring them to your infected computer with a USB drive. Please proceed with the following:

Please download RKill by Grinler from Download Mirror #1 and save it to your desktop.
Download Mirror #1 (rkill.exe)
Download Mirror #2 (rkill.scr)
Download Mirror #3 (rkill.com)
Download Mirror #4 (WiNlOgOn.exe)
Download Mirror #5 (uSeRiNiT.exe)
Download Mirror #6 (iExplore.exe)
Download Mirror #7 (eXplorer.exe)

  • Double click the RKill desktop icon (rightclick > Run as Administrator for Vista/WIN7).
  • A black screen will briefly flash indicating a successful run.
  • If this does not occur please delete that application and try using Mirror #2
  • Continue process until the tool runs.
  • Important: RKill only temporarily disables the malware. If you reboot the computer, it will be active again. So do not reboot until we kill the infection.


Please download OTL by OldTimer from here and save it to your desktop.
  • Close all windows and double click OTL.exe.
  • The Extra Registry setting should be Use Safelist
  • Copy and paste the following text into the Custom Scans/Fixes box:

%systemroot%\system32\config\systemprofile\*.dat /x
%PROGRAMFILES%\Common Files\*.*
%USERPROFILE%\My Documents\*.exe
%PROGRAMFILES%\Mozilla Firefox\*.exe
%systemroot%\system32\*.* /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.* /lockedfiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
  • Click the Run Scan button and allow it to run.
  • It will produce two logs for you, OTL.txt and Extras.txt. Please post both logs in this thread.
  • You may need multiple posts to get it all.


Tech Advisor
Tech Advisor

Posts : 1568
Joined : 2010-03-07
Operating System : WIN7 64bit, Ubuntu 12.04 LTS

View user profile

Back to top Go down

View previous topic View next topic Back to top

Permissions in this forum:
You cannot reply to topics in this forum