W32.Blaster.Worm Removal Instructions

W32.Blaster.Worm, and its modifications:  W32.Blaster.B.Worm, W32.Blaster.C.Worm, W32.Blaster.D.Worm, W32.Blaster.E.Worm, W32.Blaster.F.Worm is a self-replicating program aimed at promoting commercial releases of malicious programs like spyware. To the purposes of this infection review we further use W32.Blaster.Worm name only for all the modifications.
W32.Blaster.Worm performs its malicious tasks and is replicated thanking to DCOM RPC system vulnerability. The removal of W32.Blaster.Worm should be executed taking into account its attempts to terminate the removal process. Click here to remove W32.Blaster.Worm using the tool designed to get rid of W32.Blaster.Worm even if it would resist to the attempt of its removal, as well as to get rid of similar parasites.

Automatic removal of W32.Blaster.Worm:

Malware is likely to be accomponied by a group of numerous relatives and assisting programs. That is why we recomend to scan computer for malware and viruses if  W32.Blaster.Worm is your computer resident. The scan is 100% free. After the scan, you can remove W32.Blaster.Worm in a safe mode as fast as your PC perfomance permits. Click here to scan your computer for free and get rid of W32.Blaster.Worm.

If W32.Blaster.Worm blocks remover download:

Where W32.Blaster.Worm attempts to evade its removal and terminates or disallows true antispyware downloading, the problem is usually resolved when you run your OS in safe mode. To start Safe Mode session, please restart your computer and before Windows starts loading press F8 and hold it until you enter Windows Advanced Options Menu; by using your keyboard choose the following option: Safe Mode with Networking, and let Windows start in Safe Mode. Try to download the antispyware of your choice again. If W32.Blaster.Worm still blocks remover download – act as follows:

Step 1: click Start at the left bottom corner of your monitor
Step 2: choose Run in its menu
Step 3: type “command” in the line and click OK or press Enter
Step 4: in the window that is to appear type “notepad”
Step 5: once notepad is open, insert the following text into Notepad by copy and paste:

Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
[-HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]

[HKEY_CLASSES_ROOT\.exe]
@=”exefile”
“Content Type”=”application/x-msdownload”

[-HKEY_CLASSES_ROOT\secfile]

Step 6: save the resulted file as “exefix.reg” (no quotes) at the Desktop. When saving, please choose All Files at the “Save As” drop-down list. Open “exefix.reg” file (on your Desktop) and press “Yes”. After that you can download Spyware Doctor and other legitimate anti-spyware applications.

Download Spyware Doctor to remove W32.Blaster.Worm malware

Share it:


Did you enjoy this post? Why not leave a comment below and continue the conversation, or subscribe to my feed and get articles like this delivered automatically to your feed reader.

Comments

Whatever I do the message I get is xxx.exe is infected by the W32/Blaster.worm

whatever program i try to run (removal file included) it says the program is infected and cannot be opened. HELP!!!!

The notepad procedure worked OK an let me use the uniblue program I’ve already installed and it was blocked by this worm.
Thank you

It will not let me use the notepad command! HELP!!!

it will not let me get into notepad either :(
oh my what a nightmare !

I had this exact problem.
And none of the fixes worked.
If you enable hidden files go to:
C:\Users\AppData and delete conhost.exe also
C:\Users\AppData\Roaming and delete defender.exe
defender.exe could also be in
C:\Users\AppData\Roaming\Windows

open the registry and delete
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

It has a random name but the string is %Users%AppData\conhost.exe
and it all seems to be working normally :)

In fact this is most probably the virus you have :D
thanks

When you start your computer, pres F8 and go to “safe mode” then you can Insall it or remove it. it workey fine for me so.

Leave a comment

(required)

(required)