Win32/worm blaster

Solved/Closed
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011 - Apr 4, 2011 at 08:19 AM
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 - Jun 29, 2014 at 07:27 AM
Hello,



I had a message on spyware protection come up saying I had win32 worm blaster virus and upgrade to stop threat.

I didn't upgrade as it seemed a bit dodgy.

Im running on PC windows xp.

I can't boot in safe mode and I cant run any .exe programms. I cant even run system restore. I cant download any programmes to stop it as they dont open. The only thing I can do is use internet explorer.

Any ideas welcome please

38 responses

jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 5, 2011 at 06:18 AM
If you get me back in shape, I'll get you a night with the lady herself lol

Cucumber sandwiches are horrid tea and scones are what its all about
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 5, 2011 at 06:21 AM
In explorer go to windows system 32 and tell me if you see:

%SystemDir%\msblast.exe
or any another msblast file

If you do, blast it away

I'm taking a 5 minute break
0
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 5, 2011 at 06:29 AM
Sorry mate I dont know what you mean by go to windows system 32 how do I do that ?

I have internet explorer open ggole as my homepage
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 5, 2011 at 06:43 AM
Click right on start

Click left on explorer

Left pane scroll down to windows and then to windows 32

Click on windows 32 and in the right pane, see is you find msblast
0

Didn't find the answer you are looking for?

Ask a question
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 5, 2011 at 06:53 AM
I click left on explorer went to my computer, then c drive, then all I can see is a folder called WINXP. Instide that there is a system32 and twain_32 older but that it ?

Am I looking in the wrong place ?

Sorry to be a pain
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 5, 2011 at 06:55 AM
Jonboy,

I am called to duty, family that is, I will return on line at 2100 hrs your time. Presently 7h53 AM here.

If you cannot mblast file, try running the following from your desktop and if not working from the pendrive. It is very potent medecinal compound:

A very powerfull antidote that is able to kill and send any virus to the glue factory. It is of very last resort and should not be abused of, as matter of a fact, once you have used it, I suggest you delete it from your system.

To keep your system safe, you must follow the instructions hereunder to the letter:

First step, boot your system in safe mode with networking

1. Download Combofix to your desktop.

http://www.combofix.org/download.php

2.Close all open Windows including this one.

Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix.

3. Double click on the ComboFix icon.

Windows is issuing this prompt because ComboFix does not have a digital signature. This is perfectly normal and safe and you can click on the Run button to continue.

4. Accept the disclaimer and the recovery

5.You should now press the Yes button to continue. If at any time during the Recovery Console installation you receive a message stating that it failed to install, please allow ComboFix to continue with the scan of your computer.

ComboFix will disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.

While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings.

If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.

During the process, please do not mouse click nor must you tap on the keyboard. Let the tool run.

Once you are done, report to me on how your system is behaving.

Good luck

Ambucias
0
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 5, 2011 at 07:25 AM
Problem is I cant boot in safe mode. Think im just going to get it formated and start fresh. Thanks or trying
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 5, 2011 at 03:42 PM
Please run combofix in normal mode
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 5, 2011 at 04:51 PM
Jonboy,

I got your reply to late when asked you to delete that file in Windows

When you scrool down, open the folder system32, the file should be in there
0
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 6, 2011 at 03:15 AM
Hey mate just before I took my computer to be done. I tried that combomix in normal mode I thought my computer has crashed but then when I restarted it AVG kicked back in and I can run exe. files again. AVG keeps saying I have the following

win32 - trojan gen
ZHPDIAG2.TMP
0
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 6, 2011 at 03:28 AM
AVG has picked up and quarenteened about 30 things so far. Is there something I should run now to make sure everything has really gone. It feels too good to be true ! Combofix did the trick I think thanks mate for all your help glad I didnt give up lol
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 6, 2011 at 03:41 AM
Just to make sure that you are clean

I must make a diagnostic and to do so, I require a log.

Open this link and download ZHPDiag :

https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html


Register the file on your Desktop.

Double click on ZHPDiag.exe and follow the instructions.

the tool created two icons ZHPDiag and ZHPFix (we will use ZHPFix at the next step).

Double click on the short cut ZHPDiag on your Destktop.

Click on the Magnifying glass and run the analysys.

Wait for the tool to finished (maybe a long time)

Close ZHPDiag.


To transmit the report, click on this link :

https://authentification.site

Click on Parcourir and search the directory where you installed ZHPDiag (usually C:\Program Files\ZHPDiag).

Select the file ZHPDiag.txt.

Click on "upload ยป

Copy the url and post it here
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 6, 2011 at 03:42 AM
Oh don't forget my invitation to the Royal Wedding
0
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 6, 2011 at 03:52 AM
https://authentification.site/files/27809980/ZHPDiag.txt

Its already in the post mate ;) Ill post you a cucumber sandwich aswell hehe
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 6, 2011 at 03:54 AM
Stand by for the analysis
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 6, 2011 at 04:21 AM
Okay, the system is clean as whistle but there is a lot of junk and if I were you, I would stay away from sweetim a perfect place to get a virus, as matter of a fact I would get rid of it.

You can now delete the logs and empty the AVG quarantine folder

To get rid of the junk download, install and run the following:

https://ccm.net/downloads/security-and-maintenance/4555-ccleaner/

For the registry:

https://ccm.net/download/download-13339-eusing-free-registry-cleaner

After the clean-up, I strongly recommend that you create a brand new restore point, a place you will know it's safe to go back to in case of trouble. You can name it Ambucias if you wish.

See you in Tipperary and God save the Queen
0
jonboy2011 Posts 19 Registration date Monday April 4, 2011 Status Member Last seen April 6, 2011
Apr 6, 2011 at 04:30 AM
Thanks mate appreciate all your help.

One last question what is sweetim ? Just so I know to keep away
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 6, 2011 at 04:40 AM
It's a site you have been on which can hyjack your browser. It may also have been in an e-mail.

I forgot after you create the restore point, defragment your hard disk, after all this, things need to be put back where they belong.
0
Hmm dont know when I went on that site. I save alot off pictures from google images maybe it was a link in there.

Thanks once again

Will defo be thinking of u when they get married lol, Ambucias the guy who saved my ass
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Apr 6, 2011 at 05:02 AM
You are totally welcome

Lets create a chain... now you help someone else, it can be something simple, like help an old lady to cross the street...donate blood or...a kidney

Cheers
0
wow - this ambucias is really helpful...almost saint-like lol. I believe I have the same issue, Will try the above solution when I get home tonight. Fingers crossed!
0
I am pretty sure I have the same issue only thing is I cant open the internet either...I managed to create another user account on this computer where the virus is not present but I have no idea how to get Combofix to start on my other user account :/...help me please!!!
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Jul 30, 2011 at 05:03 AM
IneedHelp15

Try running it after putting Combofix on a flashdrive.
0
I ran combofix under the other user account and it cleaned all the accounts !!! Thank you!!!
0
ComputerIlliterate
Aug 8, 2011 at 02:01 PM
Hi I have the exact same virus! I don't have pen drive or AVG (I don't actually know what AVG is, I'm an idiot when it comes to computers). What will ComboFix do to my computer? Will it delete everything off of it?
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Aug 11, 2011 at 03:48 PM
Combofix will not delete everything, just the malware
0
jpt4116 Posts 11 Registration date Saturday August 13, 2011 Status Member Last seen August 15, 2011
Aug 15, 2011 at 11:46 AM
ambucias Your the best man i have had this problem for so long combofix did the trick thanks man your like awesome i am so happy <(^.^<) (>^.^)>!!!!!!!
0
Arghhh I have this problem tooo, I've tried every step that you have put on here (I may add I can't even open a web browser on the infected comp) so I've been downloading from my laptop onto a pendrive and attemtping to run the mentioned programmes on my computer. Even combofix when I click open on my pendrive just comes up as infected in the taskbar :/ Any ideas as to where I go from here? I can't start up in safe mode, can't open any programmes, seems like I have the same as the person who had their problem solved by combofix. Do I need there to be an internet connection for combofix to be able to work on the infected computer? :(:( pleeease help
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Aug 15, 2011 at 04:55 PM
@bailey

To help you, I must make a diagnostic and to do so, I require a log.

Open this link and download ZHPDiag :

https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html


Register the file on your Desktop.

Double click on ZHPDiag.exe and follow the instructions.

the tool created two icons ZHPDiag and ZHPFix (we will use ZHPFix at the next step).

Double click on the short cut ZHPDiag on your Destktop.

Click on the Magnifying glass and run the analysys.

Wait for the tool to finished (maybe a long time)

Close ZHPDiag.


To transmit the report, click on this link :

https://authentification.site

Click on Parcourir and search the directory where you installed ZHPDiag (usually C:\Program Files\ZHPDiag).

Select the file ZHPDiag.txt.

Click on "upload ยป

Copy the url and post it here
0
Kind Mr. Ambucias,
I have stumbled upon this thread after having become quite desperate in finding a solution to fix/cure my PC. The following in a lengthy description of all the steps I have gone through in an attempt to rescue my PC (Windows 7 Home Premium, Service Pack1 x64 Dell Inc Inspiron One) .
Yesterday I had noticed that an automated scan from my antivirus (COMODO) had started, but the automated scan which should have started at the same time from Malwarebytes Anti-Malware had not.
I checked and it wasn't showing minimized in the tray either. Thinking it odd I tried to open it by double clicking its desktop icon and then by doubleclicking its exe file in its source folder. Each time it said "C:\...cannot be run in Win32 mode."
Almost every application/program I tried to open said "... cannot be run in Win32 mode". (In the meantime Comodo had finished the scan and found nothing and shut down by itself). I panicked and tried disinfecting by any means that I could
think of by aid of my laptop and USB memory stick.
From my Usb memory stick I had managed to install on my evidently infected PC (in Safe Mode - it was the only way it let me): SuperAntiSpyware Professional, a Professional version of Malwarebytes, Spybot Search & Destroy, Webroot SecureAnywhere, Trojan Killer and CCleaner.
I ran each of them in Safe Mode, in that order. Clicked the fix/delete command depending on each one, and got rid of the files they had found as suspicious or infected. Then I ran all the scans a second time for verification and they no longer found anything/ any other results to display.
Even so, when starting windows Normally, neither one of these security/cleanup programs would not run and that "... cannot be run in Win32 mode" message would always appear (despite having selected for each the option to launch at system startup in hopes to bypass the damned virus that wouldn't let me open/run exe files). After some time only Webroot Secure Anywhere started and after finishing its scan found nothing; to my great dismay.
I had also noticed that the virus blocked my Administrator privileges. It wouldn't let me force run anything in administrator mode. Nor alter user settings in control panel nor uninstall programs. In SafeMode I managed to regive myself Administrator status and set a password.
After much searching, I had found your thread "Win32/worm blaster" and the instructions you gave jonboy2011. I did run rkill (in Safe mode - it wouldn't let me otherwise) and it said it found no malware. I ran a Malwarebyte scan again and it didn't have any results to display.
The first time I ran FixBlast.exe it died on me and dissappeared halfway through the scan.
Then I downloaded ComboFix and when I tried to run it, it told me to disable Comodo Antivirus. I disabled it then clicked OK, but ComboFix still said Comodo Antivirus was running and had to be closed. I closed ComboFix and uninstalled Comodo. Even after uninstalling it, when I tried to run ComboFix again it still said that Comodo Antivirus is running and needs to be disabled. I manually searched for and deleted any stray files I could find that had anything to do with Comodo, and tried again. Same message.
Becoming quite concerned and desperate that I couldn't use the only thing that had helped jonboy2011, I tried as final attempts a scan with Avast antivirus and then a scan with Kaspersky via its RescueDisk 10 which I had saved and made work onto a bootable USB stick. Both Avast and Kaspersky had found a (different) file with a long name string of letters and numbers which were in a Comodo Quarantine folder apparently and I deleted them upon instruction and warning of high risk from Kaspersky and Avast.
It was 4.30 AM at that time, my memory was rather clouded around that time. Anyway, even after all that, when starting window in Normal Mode the situation remained the same "cannot be run in Win32 mode".
So ultimately, in Safe Mode again, I ran ComboFix without being able to disable anything and saved the log.txt on my USB stick and now I have uploaded it here in hopes that you would please help me and read it and make sense of it and save my PC with your knowledge.
I also ran FixBlast.exe after. This time it did not crash midway - it completed and said "W32.Blaster.Worm has not been found on your computer."
As of the moment of this writing, when starting windows Normally (after typing in the new password) the only programs that start automatically are DriverReviver, Avast, SuperAntiSpyware and Webroot SecureAnywhere. A message saying "The C:\Program Files\CCleaner\CCleaner64.exe application cannot be run in Win32 mode" appears. No Malwarebytes in sight. When I try to run it, it says "The C:\Program Files(x86)\Malwarebytes Anti-Malware\mbam.exe application cannot be run in Win32 mode". Trojan Killer gets the same "cannot run in Win32 mode" message. ComboFix the same. And trying to run FixBlaster.exe it tells me "You do not have Administrator rights to run the tool". I am stumped. I am at a loss. I am desperate. Please help me, sir, because I don't know what else to do to fix/cure my PC.

I apologize for my very long post, but I hoped that maybe by seeing all the steps I had gone through would help find out who the culprit/what kind of damned virus it is and what course of action can be taken.

Thank you very much for taking the time to read my message. I will be eternally grateful if you can help me with this difficult situation.

Kindest Regards,
Irina

P.S. I could only send the rkill and ComboFix logs I got after scanning in Safe Mode.
I tried to run ZHPDiag2.exe and it said "ShellExecuteEx a echoue ; code 129. the %1 application cannot be run in Win32 mode". Tried again in Safe Mode, installed it, opened it - it gave some sort of error message that dissappeared in a second and then it started and I could run the scan. Maybe there is hope after all.

http://www.speedyshare.com/uuvSF/log.txt
http://www.speedyshare.com/zzDRq/Rkill.txt
http://speedy.sh/99Hnf/ZHPDiag.txt
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,167
Jun 29, 2014 at 06:39 AM
Hello Irina

Please stand by, 2011N2 will address your issue.
0
2011N2 Posts 13352 Registration date Saturday January 29, 2011 Status Security contributor Last seen December 24, 2016 39
Jun 29, 2014 at 07:12 AM
Hello,

Please create a new topic : https://ccm.net/forum/viruses-security-7/new
Then, paste the link here and I'll go answer you.

Thanks.

Gabriel.
0
Irina01 Posts 13 Registration date Sunday June 29, 2014 Status Member Last seen September 6, 2014
Jun 29, 2014 at 07:14 AM
Hello! So my message did get posted. I didn't see it when I refreshed the page - so I made an account. Thank you so much for taking notice of my situation/problem. I'm here. What can I do? I await your instruction.
0
Irina01 Posts 13 Registration date Sunday June 29, 2014 Status Member Last seen September 6, 2014
Jun 29, 2014 at 07:15 AM
Alright Mr. Gabriel. Will try right now.
0
Irina01 Posts 13 Registration date Sunday June 29, 2014 Status Member Last seen September 6, 2014
Jun 29, 2014 at 07:22 AM
I clicked the link you provided, I wrote a title and a message but when I click submit to post it, it says in red letters:
Caution!
The discussion in which you try to access does not exist!
Am I doing something wrong?
0