Author Topic: i have anew viurs i want soulition please help me  (Read 7450 times)

0 Members and 1 Guest are viewing this topic.

Offline ahmed_rezk

  • Newbie
  • *
  • Posts: 2
i have anew viurs i want soulition please help me
« on: March 13, 2009, 07:29:54 PM »
i have anew viurs  i want soulition please help me the name of the viurse
  i have anew viurs  i want soulition please help me the name of the viurse (fexwfz.exe )
 
my story i do scan by my avast pro bout its not removing it and no rading originaly why i want rason and soulition please help me?
the link of imeg viurs:
« Last Edit: March 14, 2009, 03:09:27 PM by ahmed_rezk »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 85941
  • No support PMs thanks
Re: i have anew viurs i want soulition please help me
« Reply #1 on: March 13, 2009, 08:00:02 PM »
Why is it not removing it (you should be sending it to the chest), what errors were displayed ?

If you have XP, vista32bit or Win2k, you could enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, a memory scan will take place followed by the opening of the Simple User Interface, Menu, 'Schedule boot-time scan...' Or see http://www.digitalred.com/avast-boot-time.php.

Or are you saying avast isn't detecting it ?

If so - If you haven't already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 21.9.2494 (build 21.9.6698.703) UI 1.0.672/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline ahmed_rezk

  • Newbie
  • *
  • Posts: 2
Re: i have anew viurs i want soulition please help me
« Reply #2 on: March 14, 2009, 11:21:00 AM »
thanks for replay but alrady i do scan with  new update but the my programe cant remove it and the new programe( malwarebytes )cant it  i use windows xp 32bit my avast prof 4.8 i want soulition please  help me thanks for all replay me

and my cause harm and dmage not  headien and dmage data exe   and i change my windows  for cpu   


download vuirs link:hXXp://rapidshare.com/files/209062484/pmp_usb.rar.html

« Last Edit: March 14, 2009, 03:24:49 PM by kubecj »

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3695
  • If at first you don’t succeed; call it version 1.0
Re: i have anew viurs i want soulition please help me
« Reply #3 on: March 14, 2009, 12:27:58 PM »
OK, this appears to be the real deal.
I suggest not to download and run the file unless you know what you're doing.
http://www.virustotal.com/analisis/f286e44f9f606291e66760fd4fd47833
The package contains and executable, a .ini, and an xml file titled "winamp_cache_0001.xml"
The .exe properties list it as "document folder" and file version 5.0.0.4, and language Chinese (Singapore).
Asquared detects it as "Packed.Win32.Klone!IK", and is able to quarantine the standalone exe, not sure about how it would go if the thing had done whatever it does when all files are unpacked/run. (Not prepared to try: This is my main machine, with no virtual partition, and I don't really know enough to do more than this.)

Ahmed
, try using Asquared to quarantine it. http://www.emsisoft.com/en/software/free/

Windows 10,Windows Firewall,Firefox w/Adblock.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31302
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: i have anew viurs i want soulition please help me
« Reply #4 on: March 14, 2009, 02:52:47 PM »
NEVER put a link on this webboard to (suspected) malware!!!
Delete the files Tarq mentioned

Also search for (and if found delete) winuqw32.dll

Open the registry editor and navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell
The value should be: "explorer.exe"
If it is not, restore it.
Close everything and reboot.
Run CCleaner and let it check/fix registry errors.
Reboot