This is an easy fix if you know whats going on.
It is known in the industry as MS03-026 and it is bad. To make a long story short an unpatched machine is open for access on TCP port 135 which is the RPC (Remote Procedure Call) port that is used by Windows for administration tasks.
How To Fix It:
If you have a firewall appliance or program make sure port 135 is not open to traffic of any kind. There are very few reasons why 135 should have to be open to the internet and NONE of them involve any home user tasks.
Second - even if you have a firewall you still need to patch your system. Firewalls are good but not flawless. I have provided the links for all the operating systems affected below. Simply click on it and click "Download" in the box on the upper right side of the page. Once the file is downloaded install the patch.
Windows NT4
Windows 2000/2000 Server
Windows XP (All versions)
Windows 2003 Server
More info about MS03-026 can be found here.
You should also periodically run an update via Microsoft. You can do so by going to:
http://windowsupdate.microsoft.com
The process is almost entirely automated and self-explanatory. You only need to worry about the updates that fall under the "Critical" section.
Additionally - if you surf the internet (whether it is via broadband or dial-up) you need a firewall of some kind. If you are not running behind a router (ie: Linksys, Netgear, D-Link, SMC, etc.) or running a software firewall GET one. ZoneAlarm is a good start and it is free.
Keep in mind that if you have a hardware firewall/router you DO NOT need a software firewall.
How to perminately get rid of this worm:
DO THE FOLLOWING:
1) Turn Off System Restore:
A.) Click Start > Right Click My Computer > select Properties.
B.) Click "System Restore"
C.) Put a check in "Turn Off System Restore"
2.) Extend the Automatic Reboot from 1 Minute to 25 Minutes
A.) Click Start > Run > Type "Services.msc"
B.) Locate and Double Click Remote Procedure Call (RPC)
C.) Select The Recovery Tab
D.) Click "Restart Computer Options..."
E.) Change the "Restart Computer after _ minutes" to 25 minutes This will allow you to download the fix.
3.) Download the Patch from Microsoft's web site (You will need to be in normal mode to do this)
A.) Go to
http://download.microsoft.com
B.) Click "Blaster Worm: Critical Security Patch for Windows XP" which is #4
C.) Click "Download" in the Gray box in the Top Right Corner.
D.) Select to download the file and save it to the desktop.
4.) Completely Disconnect from the Internet.
(Note: If you are connected via Broadband or DSL, Physically disconnect the network cable)
5) Reboot the Computer
6) End MSBLAST from Processes in Task Monitor
Press CTRL+ALT+Delete and highlight MSBLAST.EXE in Processes and press "END PROCESS"
7) Delete MSBLAST.EXE
A.) Go to "C:\Windows\System32"
B.) Locate and Delete MSBLAST.EXE
8.) Remove MSBLAST from Msconfig.
A.) Click Start, Click Run
B.) Type MSCONFIG
C.) Click on the Startup tab.
D.) Locate and remove the check from MSBLAST.EXE
E.) Click Apply, then OK.
9.) Run the Patch that you downloaded.
10.) Reboot the computer
11.) Verify that MSBLAST is no longer running
A) Pressing CRTL+ALT+DEL
B) Verify that MSBLAST is not listed in Processes.
12.) Turn System Restore back on.
A) Cick Start, Right Click on "My Computer"
B) Click the "System Restore" Tab
C) Remove the Check from "Turn Off System Restore"
DONE.