Author Topic: explorer.exe virus W32:Malware virus  (Read 22310 times)

0 Members and 1 Guest are viewing this topic.

jmelaniehunt

  • Guest
Re: explorer.exe virus W32:Malware virus
« Reply #30 on: October 17, 2010, 07:04:39 PM »
I ran the ComboFix and it said that it corrected two viruses (one in explorer.exe and another in some other file).   The machine then froze and I had to reboot.   I am running the virus again on Avast! to see if the viruses are cleared.   Do you want me to run ComboFix again.   I have to admit that I get nervous when I run it because I am afraid it might make the situation worse.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: explorer.exe virus W32:Malware virus
« Reply #31 on: October 17, 2010, 07:06:45 PM »
Yes please, but first see if there is a file called combofix.txt on your c drive 

jmelaniehunt

  • Guest
Re: explorer.exe virus W32:Malware virus
« Reply #32 on: October 17, 2010, 07:47:34 PM »
I downloaded combofix to my E drive (an external hard drive) so I presume the file would be there.  It isn't.   I will need to run combofix later because I have to go out now so you possibly won't get it until tomorrow your time.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: explorer.exe virus W32:Malware virus
« Reply #33 on: October 17, 2010, 08:05:51 PM »
No problem, but combofix must be run from the desktop.  Anywhere else and it will encounter problems

jmelaniehunt

  • Guest
Re: explorer.exe virus W32:Malware virus
« Reply #34 on: October 17, 2010, 08:11:37 PM »
Sorry I madea copy on the desktop and will run it from there later.   Thank you for all your help.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: explorer.exe virus W32:Malware virus
« Reply #35 on: October 17, 2010, 08:12:29 PM »
 ;D  Go out and have fun we will pick up when you get back

jmelaniehunt

  • Guest
Re: explorer.exe virus W32:Malware virus
« Reply #36 on: October 17, 2010, 10:43:34 PM »
Here is the CombiFix.txt file.   I think it has repaired the errors.  I ran the scan again and it said that there were no viruses but you can probably tell better than I.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: explorer.exe virus W32:Malware virus
« Reply #37 on: October 17, 2010, 11:39:15 PM »
Unfortunately it is returning - this is a very pernicious little variant

Download Dr Web from here http://www.freedrweb.com/?lng=en link on the top right of the page, tick the EULA and then download
 
It will download as an 8 digit file save it to your desktop

Restart in safe mode and run
Accept the enhanced version
Then run the quick scan
About halfway through you will be prompted to buy - just X the box closed
Once finished it will generate a log please attach that

jmelaniehunt

  • Guest
Re: explorer.exe virus W32:Malware virus
« Reply #38 on: October 18, 2010, 05:47:26 PM »
I tried to download the file and it told me it would take over 30 minutes to download.   At the present time I can only use the internet for a maximum of 30 minutes, so there is a reasonable chance that I will get halfway through the download and it will stop.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: explorer.exe virus W32:Malware virus
« Reply #39 on: October 18, 2010, 08:53:52 PM »
What is your download speed ? My system with 10Mb speed takes about 2 minutes

jmelaniehunt

  • Guest
Re: explorer.exe virus W32:Malware virus
« Reply #40 on: October 19, 2010, 06:31:25 PM »
We found a coupon for Best Buy where we bought our machine with a free check in the first year.  The year runs out tomorrow so we took it in and had it checked out.   They did a thorough check and said that it was now free of viruses.   Thank you for your help.   Hopefully we won't need you in the future.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: explorer.exe virus W32:Malware virus
« Reply #41 on: October 19, 2010, 09:16:57 PM »
No problem glad it was fixed

nbwriter

  • Guest
W32:Malware-gen (explorer.exe process) Tested Fix !
« Reply #42 on: January 12, 2012, 07:43:20 AM »
Dear Contributors,

As mentioned, this virus is "very pernicious" - I was in the same position as original poster.
I tried everything... (sailing close to the dreaded reformat!)

The reason I'm posting on this old thread is because I found a "breakthrough solution".

I did a (pretty wide) search on google image using the term "W32:Malware-gen" and happened upon a blogger who mentioned using Microsoft Update to solve this virus infection. (It didn't sound like a particularly "technical" solution to me, but good news this works!)

Here are the exact steps I followed to eradicate "W32:Malware-gen" explorer.exe process

Firstly, W32:Malware-gen appears to be bundled with other nasties that even Avast did not identify.

ESET Online Scanner found:

Win32:TrojanDownloader.Adload.NIQ
Win32 Toolbar Babylon

MalwareBytes found:

Trojan.BHO (2 instances in registry HKCR)

So, the general advice to run full scans using other AV engines seems sound. I also "immunized" with SpywareBlaster and found a nice "reg mod" that closes port 445.

Ok, back to the main plot:

1. I reinstalled MS Internet Explorer V8 (IE 8) while online
2. It will ask you to reboot once IE 8 is finalized. Please do that.
3. Reboot in Normal Mode, connect to the Internet.
4. Start IE v8 > Tools > Windows Update /windowsupdate.microsoft.com/
5. If IE v8 has installed correctly, you will see "checking for updates"
6. Then, you will see a full list of updates.

Here are the important ones:

All the KB "Security Updates" (all very small files)
The "Cumilative Update for XP" (6MB)

I installed 72 of these in all (critical ones) but not Service Pack 3- thats huge!

7. After download and install - system requires reboot. Please do that.

8. When I retested with Avast (running a scan in memory) after reboot - Joy of Joys! The W32:Malware-gen process explorer.exe virus had vanished!

Why re-install IE v8 ?

Combofix (which I admit not understanding at all) put 2 IE v8 icons on my desktop). It's also likely I just had a corrupt installation of IE v8 on my aging XP SP2 machine.

Why does the Microsoft Update Fix work?

I'd love feedback on this one! explorer.exe is essential to Windows, I think it's the shell or GUI that controls most of the fun stuff we see and use. So, its no wonder Avast decides not to delete this file when it finds a virus (somehow) attached to it.

Some viruses, apparently, "inject code" into the "address space" of very important processes like explorer.exe. (I have no idea what this really means, opinion welcomed). In this case, I don't know what really happened. I'm guessing Microsoft Update patches a vulnerablity related to explorer.exe.

Curiously, the "oldtech" method of just replacing "explorer.exe" with a system disk version had no affect in this case. "explorer.exe" appeared to be unmolested by the virus. (File versions, sizes matched)... So, the mystery is why did Avast spot this as a virus?

Hope this helps someone else (even the experts!) out there in Internet Land.

Kind Regards, NB  :D