Author Topic: [solved] False Alarm user32.dll Win32:Trojan-gen  (Read 14355 times)

0 Members and 1 Guest are viewing this topic.

Bima

  • Guest
[solved] False Alarm user32.dll Win32:Trojan-gen
« on: January 14, 2008, 10:48:16 AM »
I think it's a false alarm because I looked on two computers (both Windows XP SP2)

The first computer gave the alarm after waking up from hibernating and updating Avast, the other computer didn't do anything after stating and updating only when I scanned the file the alarm came.

On both computer the dll was changed in March 2007 (if there's a virus in there Avast has a problem if it only recognizes it after such a long time)

It's in C:\windows\system32\user32.dll

Just try this: scan the file with Avast (right click on file and scan)


So my real question is if this is a real trojan or just as it looks like a false alarm?



After the latest update a few minutes ago no alarm anymore when I scan the file.
« Last Edit: January 14, 2008, 02:13:38 PM by Bima »

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: False Alarm? user32.dll Win32:Trojan-gen
« Reply #1 on: January 14, 2008, 11:06:24 AM »
it's a false positive in some language versions of windows valid library user32.dll.. the dutch version was fixed already and the german version will be fixed with next VPS update.. sorry for the annoying situation..

Bima

  • Guest
Re: False Alarm? user32.dll Win32:Trojan-gen
« Reply #2 on: January 14, 2008, 11:22:49 AM »
Good to hear  :)

Better one false alarm then one virus slipped thru.

machines

  • Guest
Re: False Alarm? user32.dll Win32:Trojan-gen
« Reply #3 on: January 14, 2008, 11:57:52 AM »
hello avast!-team !

we have a few customers, where windows wants to have the installation-cd
in order to fix the user32.dll.

there are a lot workstations (15) and so i donĀ“t want to go to every workstation
and use the installation-cd ...

with the next vps-update ... will it automatically restore the moved user32.dll, or
do i still have to fix it with the windows-cd ?

thanks for soon reply.

greetings marco.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: False Alarm? user32.dll Win32:Trojan-gen
« Reply #4 on: January 14, 2008, 12:01:37 PM »
you can repair the library from chest or from default windows file protection service... the restoration from CD is also possible...

Offline lukor

  • Administrator
  • Super Poster
  • ***
  • Posts: 1884
    • AVAST Software
Re: False Alarm? user32.dll Win32:Trojan-gen
« Reply #5 on: January 14, 2008, 12:18:10 PM »
If you are using ADNM, you can find this in the Client side task / Auxiliary task / Virus Chest -- restore all uninfected files.

bornheim

  • Guest
Re: [solved] False Alarm user32.dll Win32:Trojan-gen
« Reply #6 on: January 14, 2008, 02:41:03 PM »
To restore the dll in the chest directory, means
i have to get this file on a 2nd computer first,
since windows wont boot.

Hmmm. Ubuntu and USB stick maybe?
I'll try.

who made this thread "solved" btw?
« Last Edit: January 14, 2008, 02:43:20 PM by bornheim »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: [solved] False Alarm user32.dll Win32:Trojan-gen
« Reply #7 on: January 14, 2008, 02:44:41 PM »
since windows wont boot
Unbelievable that they don't allow a way to restore files from Chest at boot time. If avast can work at boot time, maybe a countdown message before logon (like some defragmenting tools) will allow to access the Chest and restore any file needed to boot.
The best things in life are free.

pgfreund

  • Guest
Re: [solved] False Alarm user32.dll Win32:Trojan-gen
« Reply #8 on: January 12, 2009, 10:07:31 PM »
I am getting an alarm that says this user32.dll has a [wrm] and have tried scanning it multiple times to remove it.  Each time the scan returns a "file is read only" and will not allow it to be deleted, repaired or moved to the chest.

What do I need to do to remove it?  I've read the discussion in the thread and am still uncertain as to what to do.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: [solved] False Alarm user32.dll Win32:Trojan-gen
« Reply #9 on: January 12, 2009, 10:11:41 PM »
It's a necessary file to boot.
Maybe you need to restore it from Windows CD\DVD using the command:
sfc /scannow

I'm not sure... but there is long threads about this problem in the forums.
The best things in life are free.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: [solved] False Alarm user32.dll Win32:Trojan-gen
« Reply #10 on: January 12, 2009, 10:11:59 PM »
you're probably talking about Win32:SysPatch [Wrm]... it is not a false positive..

pgfreund

  • Guest
Re: [solved] False Alarm user32.dll Win32:Trojan-gen
« Reply #11 on: January 12, 2009, 10:37:29 PM »
Yes, how do I get rid of the Win32:SysPatch [Wrm]?


Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: [solved] False Alarm user32.dll Win32:Trojan-gen
« Reply #12 on: January 13, 2009, 09:36:15 AM »
someone told, that a simple renaming and letting windows re-create the file would help.. the other way is to use DrWeb CureIt or to replace the file with a clean one from the recovery console of your OS setup CD..