Her er en instruktion jeg fandt og filen der kan fjerne den kan du hente her
http://download.bullguard.com/Antimsblast.exe Symantec.com har vist også en
hjælpe side.
Jeg har dog ikke selv haft virusen så jeg kan desværre ikke være til mere
hjælp.
Held og lykke - Søren
Symptoms
Once executed, the worm creates a mutex called "BILLY" to signal its
presence in the system, installs itself in %SYSTEM%\MSBlast.exe (e.g.
C:\Windows\System32) and creates a key registry in
HKLM\Software\Microsoft\Windows\CurrentVersion\Run called "windows auto
update" which points to copied file in order to remain in computer's memory
each time it is restarted.
Technical description
It spreads exploiting Microsoft Windows DCOM RPC vulnerability. When detects
a vulnerable system it issues via the exploit a TFTP command on it to fetch
a copy of the worm, which afterwards is executed.
As payload the worm initiates denial of service (DoS) attacks on
windowsupdate.com after the 15th of August.
In its body there are included two strings, namely "I just want to say LOVE
YOU SAN!!" and "billy gates why do you make this possible ? Stop making
money and fix your software!!" which are not used.
The worm was written in C and compiled with LCC-Win32.
Removal instructions
Automatic removal:
Let BullGuard delete the infected files it finds
Manual removal
Press CTRL+ALT+DEL and open Task Manager, and terminate msblast.exe process.
Delete %SYSTEM%\MSBlast.exe file.
Delete HKLM\Software\Microsoft\Windows\CurrentVersion\Run\windows auto
update registry key using regedit.
Restart your computer.