Solved Do I have the w32 Blaster?

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
@Prescottbob ...
  • Please download Autoruns http://download.sysinternals.com/files/Autoruns.zip and save it to your desktop.
  • Right click on the downloaded file and choose Extract All Files.
  • Once extracted, open the program named Autoruns.
  • Click on Options and then Hide Microsoft and Windows Entries.
  • Press F5 to refresh the startup list.
  • Next go to File -> Save and choose the file type to Text File (.txt).
  • Please attach the text file to your next reply.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
It will be a few minutes-I'm away from the office on my Ipad.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I downloaded AUTORUNS.zip. When I right clicked it, I then clicked on EXTRACT ALL. I now have a window to extract all to the desktop\autoruns. I click extract and an EMPTY autoruns folder comes up!? Guidance please.

The Adobe thing I clicked on sure didn't look like the HD thing. I swear it looked just like the regular update window that comes up to install updates--but this one came up in the middle of the screen when I was leaving the REAL CLEAR POLITICS website having clicked on a like the took me to an article on REAL CLEAR TECHNOLOGY. However, that morning JAVA and ADOBE update windows had been persistent and I probably clicked on this thing to stop the interruptions.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
I would suggest stop downloading things unless these good people request you to. Their will be no catching up with infections. You could be installing infection faster that these good people are removing them.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Sorry to interrupt your query, Prescottbob. :o

@Jacee,

On your post, #336:
C:\Program Files\Microsoft Security Client\MpSvc.dll --a---- 1555920 bytes [18:36 27/01/2013] [18:36 27/01/2013] 905601FFF40D8DA9FA82CBE77D1F5EB1

Thought you were just asking a question, until the "Good catch..." was mentioned. Couldn't figure that one out.

On:
C:\mpsvc.dll ------- 1011712 bytes [16:36 14/05/2013] [16:32 14/05/2013] CF318F60A84F15AF352439465A8D05F4

The link to that file was provided by one of our colleagues at BC. He also had an unusual entry on the FSS report.

You will not see mpsvc.dll placed in C:\ by any program, because that is just where I requested Prescottbob to save it.

From there, an FCopy was done to place it in C:\Program Files\Windows Defender\MpSvc.dll

The FSS run after the FCopy shows:
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit

That is all with the C:\mpsvc.dll. It could just be removed, but, prefer to not do so yet.



I'm lost again, though... :confused:
Just asking questions to find out what 'exactly' was quarantined, and why.

Quarantined??...Can you tell me by what program?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Laybackbear,

Prescottbob was instructed by Jacee to download Autoruns.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Prescottbob,

Please remove anything from Autoruns except the downloaded zipped file.
Right-click on the downloaded file and select: Extract to Autoruns\

It should create a folder on the Desktop also called Autoruns

In that folder, are there 4 entries, one of them being the application?
 

Attachments

  • Capture Autoruns.PNG
    Capture Autoruns.PNG
    25.5 KB · Views: 1

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
?? I'm only getting the Autorun.zip when the site downloads it.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Yes, that is fine.

Right-click on the downloaded file and select: Extract to Autoruns\

It should create a folder on the Desktop also called Autoruns

In that folder, are there 4 entries, one of them being the application?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Of course if I OPEN the zip it shows the 4 items but wont let me do anything with them individually.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
When I right click the autorun.zip the only extract option is EXTRACT ALL.... When I do that it creates the Autorun file with nothing in it. "folder is empty".
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
What happens if you right-click the autoruns application inside the folder and select: Run as Administrator?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Prescottbob try this

Right-click the zip archive file.

Select “Extract All…” from the pop-up menu.

Specify the name and location of the folder for the extracted files.

Click the “Extract” button or press the “Enter” key.

If the “Show extracted files when complete” box is checked a new folder window will be opened to display the unzipped files.
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Start > All Programs > Accessories
Open the Command Prompt

At the blinking cursor, copy/paste (with the mouse) the following:

C:\Users\Binnie\desktop\autoruns\autoruns.exe

Does it run?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Can you post a capture of what you have. Use the Snipping tool...

Looks as if you are using WinZip.
Got WinRAR archiver here.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
"show extracted files when complete" is checked and the new folder window is a AUTORUN folder with nothing in it.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Did I misunderstand this. Post #346

The Adobe thing I clicked on sure didn't look like the HD thing. I swear it looked just like the regular update window that comes up to install updates--but this one came up in the middle of the screen when I was leaving the REAL CLEAR POLITICS website having clicked on a like the took me to an article on REAL CLEAR TECHNOLOGY. However, that morning JAVA and ADOBE update windows had been persistent and I probably clicked on this thing to stop the interruptions.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top