Solved Do I have the w32 Blaster?

lol
laughing.gif
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Don't know if this will help or if your problem is worse, but I had this same problem over the weekend and wasn't able to shake it off until I rebooted in safe mode and deleted the app. McAfee full scan did not detect it. But I found the sucker in my Users/user/AppData/Roaming folder (your path may be different due if you log on with a different name). It was an app with the name "amsecure" and a green shield logo. I deleted it early Sunday morning, rebooted, and it hasn't returned since. But I never clicked the box to purchase the product so I don't know if that caused additional complications for you. BTW when I hovered over it it showed the File Description was ALPass and the company was ESTsoft Corp. That may be a bogus company.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 32bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Home Premium 32bit
Antivirus
McAfee
Browser
IE
Doug, thanks for the interest. I'll let cottonball digest that.

cottonball, jacee's scan just completed ( 6 hrs ). I've got evening appointments that can't be forestalled.

Will be back tomorrow.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
This may be of some relevance ...
MpSvc.dll can be infected by virus Backdoor:PHP/C99shell.J which spreads through social network Flickr to download and install malware Movavi Screen Capture Personal on the affected machines.

Once infected, the file path of MpSvc.dll will be re-set as:
C:\WINDOWS\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c\

Your FSS Log shows:
Farbar Service Scanner Version: 14-04-2013
Ran by Binnie (administrator) on 11-05-2013 at 15:25:02
Windows 7 Home Premium Service Pack 1 (X64)
************************************************
======== Search: "MpSvc.dll" =========
C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpSvc.dll
[2009-07-13 16:54] - [2009-07-13 18:41] - 1011712 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c\MpSvc.dll
[2009-07-13 16:54] - [2009-07-13 18:41] - 1011712 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Program Files\Windows Defender\MpSvc.dll
[2009-07-13 16:54] - [2009-07-13 18:41] - 1011712 ____A () D41D8CD98F00B204E9800998ECF8427E
====== End Of Search ======
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Yep, read the same stuff...:D

That is why Prescottbob is getting a new MpSvc.dll, and with CF and an FCopy:: all three of those will get a new life:

C:\MpSvc.dll | C:\Program Files\Windows Defender\MpSvc.dll

C:\MpSvc.dll | C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpSvc.dll

C:\MpSvc.dll | C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c\MpSvc.dll


Just need to confirm that the C:\MpSvc.dll is in the right place...
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
This is what this Trojan Backdoor:PHP/C99shell.J does to an infected computer .. Encyclopedia entry: Backdoor:PHP/C99shell.J - Learn more about malware - Microsoft Malware Protection Center

These are the most dangerous, and most widespread, type of Trojan.
Backdoor Trojans provide the author or ‘master’ of the Trojan with remote ‘administration’ of victim machines. Unlike legitimate remote administration utilities, they install, launch and run invisibly, without the consent or knowledge of the user. Once installed, backdoor Trojans can be instructed to send, receive, execute and delete files, harvest confidential data from the computer, log activity on the computer and more.

If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.

They should be changed by using a different computer and not the infected one, if not an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified of the possible security breech.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
trash Post #307 I didn't do something right!
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
After this computer is clean. This might be asking to much but if someone could post what infections were found and where in the system.

What programs or methods removed the problems.

My thoughts are this nasty Backdoor Trojan planted itself in Windows Defender and kept turning Windows Defender on so the torjan could do it nasty things. What a great way to hide a infection; inside a security program.
 

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Prescottbob,


Part I:

Please open Notepad: (Start > All Programs > Accessories > Notepad)

Copy/paste the entire content inside the quote box below to Notepad (Do not copy the word 'Quote'):

FCopy::
C:\MpSvc.dll | C:\Program Files\Windows Defender\MpSvc.dll
C:\MpSvc.dll | C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306\MpSvc.dll
C:\MpSvc.dll | C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c\MpSvc.dll
ClearJavaCache::

In Notepad, click: File (upper left) > Save As...
Save the file to the Desktop
Name it: CFScript.txt
Click: Save


-->>Both the CFScript.txt and the ComboFix program icon must be on the Desktop, or this will not work.<<--


Make sure all AntiVirus and AntiMalware programs are disabled, so they do not interfere with the running of ComboFix.
Info: http://www.bleepingcomputer.com/forums/topic114351.html


Now, drag the CFScript.txt into ComboFix.exe as shown below:



CFScript.gif



This action starts ComboFix again.


If the program asks to reboot, please do so.

When done, please attach the new Combofix.txt in your reply.







Part II:

Can't remember if you have MBAM installed or not. If not, please download Malwarebytes' Anti-Malware:
http://www.malwarebytes.org/mbam-download-exe.php
Save to the Desktop.


MBAM may make changes to the Registry as part of its disinfection routine.
If using other security programs that detect Registry changes, they may interfere or alert you.
Continue disabling these programs, or permit them to allow the changes.


Right-click the MBAM file, and select: Run as Administrator

When the installation begins, follow the prompts.


Make sure both of these are checked:
Update Malwarebytes' Anti-Malware
Launch Malwarebytes' Anti-Malware
Click: Finish


MBAM automatically starts and you are asked to update the program.
If an update is found, the program will automatically update itself.
Press the OK button to close that box and continue.


On the Scanner tab:
Make sure the Perform Full Scan option is selected.
Then click on the Scan button.


If asked to select the drives to scan, leave all the drives selected.
Click on the Start Scan button.


The scan may take some time to complete, so please be patient.


When the scan is finished, a message box shows The scan completed successfully. Click 'Show Results' to display all objects found
Click OK to close the message box and continue with the removal process.


Back at the main Scanner screen:
Click on the Show Results button to see a list of any malware found.
Make sure everything is checked, and click: Remove Selected


When removal is completed, a report opens in Notepad.
The log is automatically saved and can be viewed by clicking the Logs tab.


Please copy/paste the entire contents of the MBAM report in your reply.
Exit MBAM when done.


Note: If MBAM encounters a file that is difficult to remove, you are asked to reboot the computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Failure to reboot normally (not into safe mode) prevents MBAM from removing all the malware.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
cottonball, my head is in crash mode. Do I drag the file to the combo shortcut icon, and how do you turn off mse?
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Never mind, combos running.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
MBAM is running
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
When done with MBAM, and you post its result, please run Farbar Service Scanner once again.

Make sure the following options are checked:
  • Internet Services
  • Windows Firewall
  • System Restore
  • Security Center
  • Windows Update
  • Windows Defender
Press: Scan

Please post the new FSS.txt.
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
Sure hope MBAM is not still running!!! :shock:
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
MBAM is still running. 4 hrs. -600k objects-
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Hollie schmollie!! 600,000 ??? or 600 ???

Like what kind of stuff?
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
620k scanned. 0 objects detected. I think the detections on a previous scan didn't show up until the 700 plus area.
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell studio xps 8100
OS
Windows 7 home premium 64 bit
Back
Top