How To Replace MSMPeng.exe For Defender After Trojan Attack???

Hi Will:
Thanks for being so understanding, and sounds like great news, there's headway being made, heres that log you wanted, and I'll be here waiting to hear whats next....Bobster52

2013-01-20 16:30:48 . 2013-01-20 16:30:48 558 ----a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-65559996.sys.reg.dat
2013-01-20 16:30:39 . 2013-01-20 16:30:39 108 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKLM-Run-NWEReboot.reg.dat
2013-01-20 16:30:38 . 2013-01-20 16:30:38 153 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Wow6432Node-HKCU-Run-WMPNSCFG.reg.dat
2013-01-20 16:28:18 . 2013-01-20 16:28:18 4,922 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2013-01-20 16:23:24 . 2013-01-20 16:23:24 51 ----a-w- C:\Qoobox\Quarantine\catchme.log

Oh By The Way, no Defender has been running fine, although It hasent recieved a new update yet, last was on the 18th, mostley concerned about the missing file.
 
Hi Bobster52,

We're all good here.

The msmpeng.exe file is not actually part of Windows Defender on vista. For Windows XP/Vista/7 this file is associated with Microsoft Security Essentials, Microsoft's own AV program. As you already have ESET installed, there is no need to install this or worry about the file. The association with Windows Defender is due to the recent release of Windows 8, Microsoft Security Essentials has been renamed Windows Defender, and is now bundled with new versions of Windows.

They share a lot of the same code and functionality, however the msmpeng.exe file is limited to MSE itself and Windows 8 versions of Windows defender. It can also be associated with other MS anti malware products, but not Windows Defender itself.
 
Will:
Just got your e-mail about the defender file....thats great news, now I don't need to worry about that anymore, and as its running on start-up from the services store, i guess it does'nt mater that it's not in the system configuration start folder anymore...Hey, then what was it doing in there in the first place???...Anyway, so whats next??? Think we got all of the rootkit out??? And what to do about cleanup....???....Theres a folder in my C:-Folder that ComboFix put there the first time....I'm sending you a copy of it so you can tell me where it belongs...Opps, cant copy it, it's named "boot", along with 3 other folders "MSOCache", "ProgramData", and "Qoobox" ...Where do these belong, do they get deleted??? Last night, I went into control panel and showed hidden files & Folders several times and all but "Boot"& "Qoobox" dissapeared...I was able to delete Qoobox, but boot won't budge, seems like it's some kind of language folder...Advise please, when you've got a chance...Thanks again for all the help.....Bobster52...
 
Bob,

Since Will has been involved with the latest part of the clean-up, let's wait for him. However, please do NOT delete Qoobox. There is a proper way of removing it and Will will provide those instructions.

In my reply to your questions yesterday, I explained that MSOCache is for the Microsoft Office 2007 installation on your computer. See Description of the Local Install Source feature in 2007 Office programs. The other folders are standard folders. C:\Boot contains your boot configuration data and C:\ProgramData is a folder where programs can store their data. It is the same as the C:\Documents and Settings\All Users\Application Data folder on Windows XP.
 
Hi Bobster52,

As Corrine says, those folders are perfectly normal. Qoobox is part of Combofix, and we'll delete it in the following steps. We can finish up here, as there are no longer any signs of a rootkit on board your system. As said before, it looks like most the infection was dealt with before posting - however ComboFix took out the last significant piece. The instructions below contain clean up steps for Combofix, as well as some general information to help protect your system.

------------------------------------------------------

Disconnect from the internet and disable your AntiVirus temporarily.

Go to Start -> copy/paste the following single line command into the Search box and press Enter:


ComboFix /Uninstall

This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points.

Re-enable your AntiVirus now. Reconnect to the internet at your leisure.
------------------------------------------------------

Any other downloaded tools can simply be deleted.

To help protect your computer in the future I recommend that you follow these steps and look into the following free programs:

MICROSOFT UPDATES

It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.

SOFTWARE
You need an antivirus that is continually updated and a good firewall. In Windows Vista and 7, the Windows inbuilt firewall is usually sufficient, but XP users are recommended to have a good 3rd party firewall. However, be very wary with any security software that is advertised in popups. They are not only usually of no use, but often have malware in them. If you ever have doubts about the legitimacy of an anti-spyware or anti-virus program, it is best to post your question in our General Security forum.

Remember never to install more than one AntiVirus program as they will conflict with each other.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam, and helps to protect your computer against online threats when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop

    WOT and has an add-on available for all major browsers.

  • Winpatrol is heuristic protection program, meaning it looks for patterns in codes that work like malware. It also takes a snapshot of your system's critical resources and alerts you to any changes that may occur without you knowing. You can read more about Winpatrol's features here. The Plus Version has more features, and you can read Winpatrol's FAQ if you run into any problems.

  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is the IP of your local computer. Windows Vista users see here, and Windows 7 users see here. Note that if you use a company provided HOSTS file you should not use the MVPS HOSTS file.

  • ERUNT will create daily complete backups of your computer's Registry. Whilst System Restore does the same thing, a corrupt registry file may prevent Windows from booting & this effectively renders System Restore unavailable by simple means. With ERUNT, you're able to restore the damaged Registry.

    Vista/Windows 7 users - see this link for proper setup of Erunt Automatically Backup your Windows Vista Registry daily using ERUNT - The Winhelponline Blog


Last of all, you may wish to read the following article to avoid infection in the future:
Think Prevention
 
Will, Corrine, and Richard;
Once again, Thank you all so much for all the time and effort and all the help you've given to me, makes me want to appreciate mankind again....You Guys are Great!!! Have a great evening...:thumbs_up:...Bobster52..
Oh, one last thing...I had already deleted the ComboFix.exe..So that command in search did'nt work....I will redownload it, open it up.....And then do it the right way...Thanks again...
 
Hi, Bob.

If all you did was delete ComboFix.exe from your desktop, just download a new copy to your desktop and then follow the instructions Will provided. You won't need to launch ComboFix.
 
Hello Again Corrine & Will;
Just when you thought you got rid of me....I noticed this evening that I have a issue going on in the pute...In Event Viewer I'm getting a message that "The following Boot-Start or System-Start Driver failed to load-Beep"...N-E-Way, ponder this for a while, and get back to me when you have the time, other than that, the computer is running fine...Thanks in advance for any insite you might afford me...Bobster52
 
Last edited:
Hi Guys;
Been doing a little research...seems like I'm missing a .wav file named Beep, and perhaps a driver by the same name...Any Idea where I might find thyese 2 items??? Thanks again, Bobster52
 
Hi Bobster52,

Event Log errors are normal, not everything that appears in them needs to be fixed. Let's do a search to see if beep.sys is on your system.

Please download SystemLook from the link below and save it to your Desktop.
Download Mirror #1
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:
    :filefind
    beep.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found at on your Desktop entitled SystemLook.txt
 
Will; By the way...All those files that I was questioning you and corrine about, were hidden files...I just had to open the properties and put a checkmark in the "Hide" box :banghead:...N-E-Way...been doing some research on Beep...According to microsoft, they stopped including system beeps with vista, however I'm confused, because in a Microsoft tech forum the instructions are to go to Device Manager, click view , show hidden items, and scroll down "Non-Plug & Play Drivers", click Beep, (which was'nt there by the way) right click on properties and click disable??? Another tech on the same forum said there is no driver in Vista, all you need to do is replace the Beep .wav file in the windows media folder, (which also is not there)??? At any rate, Now that I think about it, I never did hear a Beep from the System Speaker, But how do I fix Event viewer from reporting it as a driver not loading or a file not found, (having both error statments in the log)???

Thanks again....Bobster52
 
Hey Will;
Could'nt find anywhere to get the driver or the .wav file, but did find a way to stop event viewer from saying it was an error.....In the CMD type--C:\Windows\system32>sc config beep start= disabled---Presto-No more error...Sooooooooooo, thank you guys for your help, and I shall try to leave you alone...For a while , at least...Hugs and Kisses---Bobster 52 :wave:

Trying to re-enable the Bluetooth stack---Seems I did a little hidden damage trying to remove that rootkit...
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top