Author Topic: Win32:Injecter-x and Win32:Trojan-gen(other) can't delete, move etc.  (Read 4151 times)

0 Members and 1 Guest are viewing this topic.

crisnee

  • Guest
Hi,

Helping a friend get his computer working, I found Win32:Injecter-x (in msupd28466.exe, Documents and settings folder) and Win32:Trojan-gen(other) (in cabviewv.dll, system32 folder). I could not do anything with them, not delete, move etc. Nor would it delete on restart. I even tried the unlocker program to rename it on restart, no luck.

I noticed that msupd28466.exe was listed in msconfig startup. I unchecked it thinking it would let me deal with it on reboot but it had checked itself again during the reboot. Does msupd stand for microsoft update?

Anybody have any idea of what is going on with this virus/trojan and how to get rid of it. I did check the box in Avast to have a report sent to Avast, but my friend has dial up and his system is so slow (because of the trojan?) that I don't know if it actually got sent.

Thanks for any ideas or help.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Win32:Injecter-x and Win32:Trojan-gen(other) can't delete, move etc.
« Reply #1 on: September 17, 2009, 07:29:25 AM »
Hi crisnee,

First try a boot time scan with avast! Right click the scanner screen, select 'schedule a boot time scan' and reboot when requested. (Or open the tab at the top left of the scanner screen and select the boot time option from there.)

Try a scan with DrWeb CureIT!

Try the usual free adware/spyware scanners.

SUPERAntiSpyware Free
Malwarebytes' Anti-Malware

Download, install and update the programs.
Always select the option to quarantine any malware found rather than delete it, then you will be able to restore files or registry entries wrongly identified as malware- a rare but not unknown event for any malware scanner.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: Win32:Injecter-x and Win32:Trojan-gen(other) can't delete, move etc.
« Reply #2 on: September 17, 2009, 12:14:28 PM »
in addition to what Freewheelinfrank
1. try to kill the process:"msupd28466.exe"
in the dos promot:taskkill /f /im msupd28466.exe
2.download the program"autoruns"from ........ then scan in it for the name msupd28466.exe and uncheck it.
3.next restart enter safe mode and search for  msupd28466.exe  and delete it.
4.empty every temp folder.
restart
that is for  Win32:Injecter-x
Dreams don't die, they just fall asleep.

crisnee

  • Guest
Re: Win32:Injecter-x and Win32:Trojan-gen(other) can't delete, move etc.
« Reply #3 on: September 19, 2009, 07:36:40 PM »
Thanks for in the info. I've tried most of what FreewheelinFrank said already and I'll give superhacker's advice a shot next time I see my friend. I'll report back the results. Thanks again.