Author Topic: Possible False Positive Win32:Explor-DU [Trj]  (Read 8912 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible False Positive Win32:Explor-DU [Trj]
« Reply #15 on: December 14, 2012, 03:13:01 PM »
Looks like it has already been fixed from that report

YellowFox

  • Guest
Re: Possible False Positive Win32:Explor-DU [Trj]
« Reply #16 on: December 14, 2012, 04:06:02 PM »
Looks like it has already been fixed from that report

Decided to try a hunch and scanned the folder where all the files are located leave the computer for 10 minutes and I come back to find out it bluescreened. I'm tired of this laptop being the annoyance it's been and will be taking it into the shop tomorrow. Another fact the computer only bluecreen's when I'm running Avast anti-rootkit on anything but a quick scan.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible False Positive Win32:Explor-DU [Trj]
« Reply #17 on: December 14, 2012, 04:12:02 PM »
Is that the aswMBR programme ?  As that will sometimes cause a blue screen on some systems

YellowFox

  • Guest
Re: Possible False Positive Win32:Explor-DU [Trj]
« Reply #18 on: December 14, 2012, 04:22:41 PM »
Is that the aswMBR programme ?  As that will sometimes cause a blue screen on some systems

Yes it was that program. The bluescreen code was 109 it has to do with Kernel Corruption. I looked it up and something in the (IDT) is messing it up.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible False Positive Win32:Explor-DU [Trj]
« Reply #19 on: December 14, 2012, 04:32:47 PM »
aswMBR uses a totally different routine to Avast and is primarily aimed at the MBR.  So it does dig deep

What other problems are you have as they may be easily resolved 

YellowFox

  • Guest
Re: Possible False Positive Win32:Explor-DU [Trj]
« Reply #20 on: December 14, 2012, 04:40:25 PM »
aswMBR uses a totally different routine to Avast and is primarily aimed at the MBR.  So it does dig deep

What other problems are you have as they may be easily resolved

Only the bluescreening from a full scan with the rootkit scanner other than that it's running somewhat O.K. The computer has taken a hit before that caused some files to go missing from the HDD. I had a box near the computer and accidentally backhanded it, the box hit the computer and then a few seconds later the whole screen went haywire (Every object on screen had a Green, Red, Blue outline and were extremely fuzzy) I hit the power button forced the computer off and rebooted it so far from what I've seen the computer has lost performance and could be missing some files. The computer itself comes with a restore feature that has 3 modes Software restore (Intact) Basic Restore (Restores key files needed for operation while keeping other files [Corrupt: Anytime I use this all text is missing and the computer bluescreens after a few seconds with a text saying Font Missing] And finally Full Restore (Restores to any backed up image and restores to initial status) [Corrupt: It feels like this restore option is sluggish and missing files I had used it before with only Avast and ended up getting a message from Avast about a rootkit after that I had to format and reinstall]. So far this computer doesn't randomly crash however it used to be able to run games with no effort and now cant even run anygame without some small lagspikes every 10-15 seconds.
« Last Edit: December 14, 2012, 04:52:17 PM by YellowFox »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible False Positive Win32:Explor-DU [Trj]
« Reply #21 on: December 14, 2012, 07:38:37 PM »
OK run an elevated command prompt

Go Start > All Programs > Accessories
Right click Command Prompt and select Run as Administrator
Type in the following command and press enter :

sfc /scannow

Let me know if that gives an improvement