Solved Do I have the w32 Blaster?

Please remove MBAM.

It may be in Start > Control Panel > Programs and Features > Uninstall programs...

Now, go back to the MBAM website, and download it again.
When you see the downloaded file, save it to the Desktop, and in the Save prompt, rename it to: Mbob

Follow the previous instructions to install it, etc.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Same virus detected message received. McAfee virus protection is turned off.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Try downloading it in Safe Mode with Networking, and run it from there.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Nothing will complete downloading--am going back to Safe Mode to try them.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Did it work in Safe Mode with Networking?

Edit:
Try the next post, #27!

If still no-go, please access the RKill Download
Save to the Desktop.


If rkill.exe does not run, then download and try to run iExplore.exe (a renamed RKill.exe), or RKill.com
You only need to get one of these to run.


If your antivirus warns you about this tool, ignore the warning, or temporarily disable your antivirus.
Info: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - BleepingComputer.com


Right-click on the downloaded RKill file and select: Run as Administrator


When the tool runs, a black DOS box briefly flashes and then disappears. This is normal and indicates the tool ran successfully.

When the scan is done, Notepad opens with the RKill report.

Please post the RKill report in your reply


>>Do not reboot the computer after running RKill, as the malware programs will start again!

If the computer reboots, run Rkill again before continuing to the next step.<<

.



Next, download the free version of Malwarebytes' Anti-Malware (MBAM)...etc. as previously posted.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
MBAM, MCPR and MSE all fail to load in safe mode with networking. I'll stay in safe mode awaiting next thought.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
See Post #27, above!
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
To uninstall Programs in SafeMode .

Click on the :orb: button then type regedit inside Search programs and files box. Right click over the regedit under neath Programs (1) select Run as Administrator . Click on the Yes button inside the User Access Control

Inside Registry navigate to

Code:
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\

Right-click on the Mininal key and from the menu select New – Key:

Now name the new key MSIService and change the value to Service by double-clicking it

close Registry

Now open up the Command Prompt with Elevated Rights . Click on the :orb: once again type in CMD right click on CMD under neath Programs(1) choose Run as Administrator . On the UAC window click on the Yes button. Inside Command Prompt enter the command below

net start msiserver
press <ENTER>

Should get Service started Successfully . Close CMD by typing Exit

Retry to remove software.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
I'm in the process of doing the SAS retrieval. But will be a while before I get back to this machine.

Thanx for your patience.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Do I try to run SAS in SAFE MODE or reboot first?
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Try to run in SafeMode with networking update the definitions then run the program.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Actually, that defeats the purpose of the SUPERAntiSpyware Portable...

As described by the website, ...it is a single file you can copy to your USB drive without requiring installation, and also automatically gives you a random filename so the malware can’t detect it as easily.

In other words, it should work in the infected environment...
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
SAS still scanning. Has found Trojan.Agent/Gen-Injector(Fmt) and 54 tracking cooks.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Prescottbob,

Is SAS pointing to a file when giving the detection?

Also, are you running SAS from Safe Mode or normal Windows?
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
It's still scanning in safe mode. The screen only shows the Trojan nomenclature. However, I did notice SAS was scanning McAfee files when it appeared on the screen. Still scanning will SAS tell me to delete everything it lists?
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
It should list what it found as Threats Detected, and give you the option to place a check next to what you wish to delete.

As far as cookies go, that is up to you, however, any serious entry, click: Remove Threats button.

Also press View Scan Log, which should open in Notepad, and post its results.

It is also possible that SAS asks for a reboot in order to delete some files. Please do so.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Over 5 hours of scanning we have an SAS report. OOOPS! It was highlited and copied but when I hit paste it disappeared and never made it to the post. I'm rebooting now to see if things have improved.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Try copying it pasting the log again

Open up SUPERAntiSpyware and click View Scan Logs

Wrap log inside [CODE][/CODE] by clicking on the # symbol inside the message box
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Ultimate 32-Bit & Windows 7 Ultimat...Intel Core i7 CPU 950 @ 3.07GHzOCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 160...ATI Radeon HD 5700 Series
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
CPU
Intel Core i7 CPU 950 @ 3.07GHz
Motherboard
ASUS P6T DELUXE V2
Memory
OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
Graphics Card(s)
ATI Radeon HD 5700 Series
Sound Card
OnBoard
Hard Drives
WD6400AACS-00M3B0 (640GB SATA )
PSU
CORSAIR 850w
Case
NZXT LEXA
Cooling
Intel Stock Heatsink Fan
Keyboard
Microsoft Wireless Laser Keyboard 7000
Mouse
Microsoft Wireless Laser Mouse 7000
Back
Top