Jump to content

Possible New Threat


Recommended Posts

I am running Windows Vista Ultimate and got infected with the fake Windows 2010 Antivirus which I was able to finally isolate and get rid of after a few attempts.

A few days later I start to notice when I boot up my PC, the windows installer window pops up briefly and then goes away, and then today while in the Computer window my drives won't display and then I get the error that Windows Explorer has stopped working and it restarts and my drives will not show and each time I refresh I get the same Windows Explorer error.

I ran Super Anti-Spy which found the root Trojan file fcpmex.sys(733 bytes in size) in my Windows\System32\drivers folder - it quarantined it and asked to reboot to finalize it's deletion. Upon restarting my PC, it was still there - I then scanned again using MBAM - same thing happened. I then scanned using Avanquest Fix It Utilities 10 - same thing.

I have researched steps on how to delete a sys file, but it will not go away, and I searched the Net for the file name and nothing comes up.

Any suggestions on how to kill this?

Barry

Here's what I tried to change the attributes and also to rename it

c:\Windows\System32\drivers>attrib -h fcpmex.sys

Unable to change attribute - C:\Windows\System32\drivers\fcpmex.sys

c:\Windows\System32\drivers>attrib -r fcpmex.sys

Unable to change attribute - C:\Windows\System32\drivers\fcpmex.sys

c:\Windows\System32\drivers>attrib -S fcpmex.sys

Unable to change attribute - C:\Windows\System32\drivers\fcpmex.sys

c:\Windows\System32\drivers>ren fcpmex.sys bad.dat

A device attached to the system is not functioning.

c:\Windows\System32\drivers>

Link to post
Share on other sites

Hi bcbg -

This is our latest version of a fix for A/V 2010 - Hope it helps -

If you think that you are still infected we will go over your system for you - Just follow the advice below -

We don't work on Malware removal or diagnostics in the general forums.

Please print out, read, and follow the directions here, skipping any steps you are unable to complete. Then post a NEW topic here.

One of the expert helpers there will give you one-on-one assistance when one becomes available.

After posting your new post make sure under options that you select Track this topic and choose one of the Email options so that you're alerted when someone has replied to your post.

Alternatively, as a paying customer, you can contact the help desk at support@malwarebytes.org

Thank You - B)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.