VIRUS explorer.exe

sonia -  
 sonia -
Hello,
I have a virus called explorer.exe. What should I do to remove it? My antivirus (Avira) keeps detecting it but doesn't delete it. Please help me, it’s very urgent.
Configuration: Windows XP Internet Explorer 8.0

7 answers

  1. Anonymous user
     
    Hello,

    • Download and install UsbFix

    (!) Connect your external data sources to your PC (USB flash drive, external hard drive, etc...) that may have been infected without opening them

    • Double-click on the UsbFix shortcut present on your desktop.

    • Choose option 1 (Scan)

    • Let the tool work.

    • Then post the UsbFix.txt report that will appear.

    • Note: The UsbFix.txt report is saved at the root of the drive. (C:\UsbFix.txt)

    ( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )

    • Note: "Process.exe," a component of the tool, is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
    It is not a virus but a utility designed to terminate processes.
    In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert from these antivirus programs.

    • Tutorial: http://pagesperso-orange.fr/NosTools/usbfix.html
    --
    See you later
    1
    1. sonia
       
      Hello, here is the report:

      ############################## [ UsbFix V3.017 # Scan ]

      # User : user (Administrators) # ETS-1CF03A92B9C
      # Update on 06/05/09 by Chiquitine29, C_XX & Chimay8
      # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
      # Start at: 21:08:54 | 06/05/2009

      # Processor Intel Celeron
      # Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 2
      # Internet Explorer 8.0.6001.18702
      # Windows Firewall Status : Enabled
      # AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]

      # A:\ # 3.5 inch Floppy Disk Drive
      # C:\ # Local Hard Drive # 19.53 GB (10.39 GB free) # NTFS
      # D:\ # Local Hard Drive # 19.53 GB (16.78 GB free) # NTFS
      # E:\ # Local Hard Drive # 19.53 GB (14.28 GB free) # NTFS
      # F:\ # Local Hard Drive # 18.08 GB (10.8 GB free) [New name] # NTFS
      # G:\ # CD-ROM Drive
      # I:\ # Removable Drive # 986.04 MB (221.43 MB free) [SONIA] # FAT32

      ############################## [ Active Processes ]

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\TUProgSt.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\program files\Internet Download Manager\IDMan.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\program files\Internet Download Manager\IEMonitor.exe
      D:\Program Files\Winamp\winampa.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      I:\memory.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
      D:\software\Rav antivirus\rav.exe
      E:\Program Files\USB Disk Security\USBGuard.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\GUARDGUI.EXE
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## [ Registry # Startup ]

      HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
      HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
      HKCU_Main: "Start Page Redirect Cache"="https://www.msn.com/fr-fr?ocid=iehp"
      HKCU_Main: "Start Page Redirect Cache_TIMESTAMP"=hex:10,2e,be,3e,18,b1,c9,01
      HKCU_Main: "Start Page Redirect Cache AcceptLangs"="fr"
      HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      HKLM_logon: "DefaultUserName"="user"
      HKLM_logon: "AltDefaultUserName"="user"
      HKLM_logon: "LegalNoticeCaption"=""
      HKLM_logon: "LegalNoticeText"=""
      HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      HKLM_Run: !AVG Anti-Spyware="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
      HKLM_Run: WinampAgent="D:\Program Files\Winamp\winampa.exe"
      HKLM_Run: TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      HKLM_Run: explorer=C:\WINDOWS\BackUp\explorer.exe
      HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
      HKCU_Run: IDMan=C:\program files\Internet Download Manager\IDMan.exe /onboot
      HKCU_Run: msnmsgr="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

      ################## [ Information ]


      ################## [ Files # Infectious Folders ]

      Found ! C:\explorer.exe
      Found ! I:\explorer.exe

      ################## [ Registry # Infectious Run Keys ]

      Found ! HKLM\software\microsoft\security center\\ "AntiVirusOverride"
      # -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
      Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Explorer"
      Found ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

      ################## [ Registry # Mountpoints2 ]

      HKCU\Software\Microsoft\....\MountPoints2\{18519191-2d93-11de-bbf7-00e04c78f735}\Shell\AutoRun\command
      HKCU\Software\Microsoft\....\MountPoints2\{18519191-2d93-11de-bbf7-00e04c78f735}\Shell\explore\Command
      HKCU\Software\Microsoft\....\MountPoints2\{18519191-2d93-11de-bbf7-00e04c78f735}\Shell\open\Command
      HKCU\Software\Microsoft\....\MountPoints2\{8a811751-18af-11de-bbc0-00e04c78f735}\Shell\AutoRun\command
      HKCU\Software\Microsoft\....\MountPoints2\{8de94b42-050b-11de-bb82-00e04c78f735}\Shell\AutoRun\command
      HKCU\Software\Microsoft\....\MountPoints2\{8de94b42-050b-11de-bb82-00e04c78f735}\Shell\open\Command

      ################## [ ! End of report # UsbFix V3.017 ! ]
      0