Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Do I have the w32 Blaster?

06 May 2013   #11
cottonball

Windows 7 Home Premium
 
 

Prescottbob,

Please run RogueKiller once again:

•Quit all programs
•Right-click the RogueKiller file and select: Run as Administrator
•Wait until the Prescan finishes
•Press: Scan
•Once the scan is done, press the [Delete] button.

Please post the new RKreport (Mode: Remove) in your reply, just like you did before..
The report is created on the Desktop


My System SpecsSystem Spec
.

06 May 2013   #12
cottonball

Windows 7 Home Premium
 
 

When done with RogueKiller, please download the free version of Malwarebytes' Anti-Malware (MBAM):
Malwarebytes : Malwarebytes Anti-Malware removes malware including viruses, spyware, worms and trojans, plus it protects your computer

Save to the Desktop.

MBAM may make changes to the Registry as part of its disinfection routine.
If using other security programs that detect Registry changes, they may interfere or alert you.
Let your security program(s) allow the changes that MBAM makes. It is a safe program.
Double-click the downloaded file to run MBAM.

When the installation begins, follow the series of setup wizard prompts pressing Next, and on the last prompt, press: Install
When done with this phase, press: Finish
However, uncheck: Enable free trial of Malwarebytes Anti-Malware Pro


MBAM automatically starts and takes you to the main console and to the Scanner tab.
On the Scanner tab:
Make sure the Perform Full Scan option is selected.
Then click on the Scan button.

The scan may take some time to complete, so please be patient.

When the scan is finished, a message box shows: The scan completed successfully. ..etc.
If anything is found, click Show Results to display all objects found.
Click OK to close the message box and continue with the removal process.
Make sure that everything is checked, and click: Remove Selected

When removal is completed, a report opens in Notepad.
(The log is automatically saved and can also be viewed by clicking the Logs tab).

Please post the MBAM log in your reply.
My System SpecsSystem Spec
06 May 2013   #13
cottonball

Windows 7 Home Premium
 
 

Take your time.

Will be back @ about 4:00PM CST, USA to check.


Edit:
Also, reboot after running RogueKiller, and see if you can run Malwarebytes in normal Windows (not in Safe Mode).
My System SpecsSystem Spec
.


06 May 2013   #14
Prescottbob

Windows 7 home premium 64 bit
 
 

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : RogueKiller - Geeks to Go Forums
Website : Download RogueKiller (Official website)
Blog : tigzy-RK
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Safe mode with network support
User : Binnie [Admin rights]
Mode : Remove -- Date : 05/06/2013 11:33:38
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 10 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Internet Security (C:\Users\Binnie\AppData\Roaming\amsecure.exe) [-] -> DELETED
[HJPOL] HKLM\[...]\System : DisableTaskMgr (0) -> DELETED
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ] HKLM\[...]\Internet Settings : WarnOnHTTPSToHTTPRedirect (0) -> REPLACED (1)
[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST31500341AS +++++
--- User ---
[MBR] 565cafce03e31579f24341c0c8632f3e
[BSP] cead95340ba2d9af9313cc5fd7a1a309 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 15000 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 30801920 | Size: 1415758 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[3]_D_05062013_02d1133.txt >>
RKreport[1]_S_05062013_02d0850.txt ; RKreport[2]_S_05062013_02d1130.txt ; RKreport[3]_D_05062013_02d1133.txt

Report after delete. Now should I leave safe mode?
My System SpecsSystem Spec
06 May 2013   #15
Prescottbob

Windows 7 home premium 64 bit
 
 

Rebooted, went to malwarebytes, downloaded free version, a virus was detected in the download and was deleted. Internet IE is working again. Windows security center is alerting but won't start.
My System SpecsSystem Spec
06 May 2013   #16
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Did you run Malwarebytes or did your antivirus think it was a virus and stopped you from downloading?
My System SpecsSystem Spec
06 May 2013   #17
Prescottbob

Windows 7 home premium 64 bit
 
 

Did not run malwarebytes, it stopped loading at99 percent with the virus detected message.
My System SpecsSystem Spec
06 May 2013   #18
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

disable your virus for time being until it downloads.
My System SpecsSystem Spec
06 May 2013   #19
Prescottbob

Windows 7 home premium 64 bit
 
 

VistaKing:

Same result with McaFee shut off.
My System SpecsSystem Spec
06 May 2013   #20
VistaKing

Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
 
 

Ah ... McAfee Uninstall that program . Reinstall MSE

McAfee Removal Tool
http://download.mcafee.com/products/...tches/MCPR.exe

MSE download
Microsoft Security Essentials - Microsoft Windows

On the Drop down menu choose " Windows Vista / Windows 7 64-bit " and click on Download now
My System SpecsSystem Spec
Reply

 Do I have the w32 Blaster?




Thread Tools





Similar help and support threads
Thread Forum
W32 Blaster Worm
Hello, My computer has caught this worm and is driving me crazy, it starts with the spyware protection software which tells me I have many viruses. Im aware its a scam but i cant seem to resolve the problem in safe mode using spybot & uniblue registry cleaner. Please could someone help me,...
System Security
No, it isn't the Blaster Worm
No, it isn't the Blaster Worm ~ Security Garden
Security News
blaster.worm help
my laptop wont do anything. I keep getting a message saying blocked by w32/blaster.worm. Can you please pretty please help me
System Security
Facebook blaster pro
Hi,recently i have remove facebook blaster pro.but when i start my pc a pop up of it show up.it run firefox from himself.Plz help me?
Software
worm blaster
my husbands computer got the worm blaster. the computer was working fine in the am.and i had only searched walmart .com. at noon when he turned it on it said it was infected and wouldnt let us go to anything. i am running avg(updated) and mcfee on it. now all of his desktop icons are gone and i...
System Security
Sound Blaster
My sound chip on my motherboard seem to have gone kaput, got a Creative Sound Blaster Audigy SE. Apparently it don't work with Win7, yet its all right on my Vista partition. Trying to find a driver that will make it compatible with 7. Anyone had that problem.
Sound & Audio

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 07:53.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App