eBlaster Description:
Eblaster tracks email, instant messaging
usage, and keystrokes. Periodically, this Spyware
will send email containing the logged information
to a predefined email address.
When the installer for Eblaster is executed, it
does the following:
- Creates the following files:
- %System%\nvrcr32.dll
- %System%\rmashlex.dll
- Creates these registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad\XmLdrKLocation =
{0C887F38-5178-43DA-B9F0-B856141FCDA4}
HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{6A6A1EAE-13E1-4DC7-8014-B7677EF6D47A}
HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{0C887F38-5178-43DA-B9F0-B856141FCDA4}
HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{2BE166ED-F16C-46DE-B623-3575FD985D6D}
When Eblaster runs, it monitors email messages
and instant messaging communication. This spyware
does not indicate that it is running.
eBlaster Automatic Removal:
Using Spyware Doctor
to remove eBlaster AUTOMATICALLY!
Sponsored Links:
eBlaster
Manual Removal:
Follow these steps to remove EBlaster from
your machine. Begin by backing up your
registry and your system, and/or setting a
Restore Point, to prevent trouble if you make a
mistake.
- Kill these running processes with Task
Manager:
eblaster.exe
ebsetup.exe
msrac32.exe
- Unregister these DLLs with Regsvr32, then reboot:
systemroot+\system\mstv9swin.dll
systemroot+\system\mswebhlp.dll
mserrtrc.dll
msrac32.dll
msu00mwin.dll
mswebhlp.dll
rmtcore.dll
- Remove these registry items (if present)
with RegEdit:
HKEY_CLASSES_ROOT\clsid\{6314e760-e667-11d2-ba98-0080c8e9491a}\ole\shell\commands
HKEY_CLASSES_ROOT\clsid\{deca39c1-f713-11d2-ba99-0080c8e9491a}\inprocserver32
- Remove these files (if present) with Windows
Explorer:
systemroot+\system\mstv9swin.dll
systemroot+\system\mstv9swin.ocx
systemroot+\system\mswebhlp.dll
systemroot+\system\winmstv9swin.drveblaster.exe
ebsetup.exe
mserrtrc.dll
msrac32.dll
msrac32.exe
msrevgwin.ocx
msu00mwin.dll
msu00mwin.ocx
msu00mwin.rcv
new.reg
rmtcore.dll
shdocew.chm
system.dat
system.ini
user.dat
windows explorer.lnk
wininit.ini
winmstv9swin.drv
winmsu00mwin.drv
More
Removal Instructions for Adware/Spyware Programs -
'E'
|