Jump to content


Photo
- - - - -

Trojan Dropper bc miner

trojan

  • This topic is locked This topic is locked
24 replies to this topic

#21 shmimtown

shmimtown

    New Member

  • Members
  • Pip
  • 14 posts

Posted 24 June 2012 - 04:36 PM

not finding that either, tried to manually start windows firewall and it start/stopped. started windows defender but still getting a red ms security essentials saying that the service is stopped

#22 shmimtown

shmimtown

    New Member

  • Members
  • Pip
  • 14 posts

Posted 24 June 2012 - 04:50 PM

Just tried uninstalling and reinstalling microsoft sec essentials. It is now saying that it is on and up to date, however windows firewall and windows defender services are still off. here is another log file from Farbar:

Farbar Service Scanner Version: 24-06-2012
Ran by Shmim (administrator) on 24-06-2012 at 16:48:30
Running from "C:\Users\Public"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

#23 shmimtown

shmimtown

    New Member

  • Members
  • Pip
  • 14 posts

Posted 25 June 2012 - 12:40 AM

ok I did some research thru the MS forums and was able to fix windows defender and the firewall. It appears that everything is working ok. Is there anything else you would like to look at?

Shmim

#24 Maniac

Maniac

    Forum Deity

  • Experts
  • PipPipPipPipPipPip
  • 17,441 posts
  • Gender:Male
  • Location:Bulgaria, EU

Posted 25 June 2012 - 03:46 AM

Good work! No, that's all! :)

Please run OTL and click on CleanUp button. Next, manually delete Farbar Service Scanner.

Some malware prevention tips:
http://forums.malwar...=0


Safe surfing! :)
My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#25 Maurice Naggar

Maurice Naggar

    Eradicator de logiciels malveillants

  • Moderators
  • PipPipPipPipPipPip
  • 13,598 posts
  • Gender:Male
  • Location:USA
  • Interests:Security, Windows, Windows Update, malware prevention

Posted 30 June 2012 - 05:51 AM

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!
Maurice Naggar
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

I close my threads if there is 5 days without a response.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users