WIN32:expiro-EE infection

Solved
seduesed Posted messages 7 Status Membre -  
seduesed Posted messages 7 Status Membre -
Hello,
My computer has been infected for 2 days.
After trying to fix it myself by following the procedure proposed by king06 (adwcleaner + junkware removal tool then malwarebytes), I apparently got rid of WIN64:expiro-Q and win32:vitro, but avast keeps alerting me about WIN32:expiro-EE.

What surprises me is that a scan with malwarebytes doesn't report anything, and I also did a "custom" scan on the windows\system32, windows\winsxs\, windows\ehome\, and windows\microsoft-net\ folders that avast flagged as infected during a boot scan.

Additional question: I have 5 items in malware quarantine, many in avast's, most of which come from C\windows\, as well as a game program called "purbleplace," which a child here enjoys playing.
Will the procedure also clean these items or should I restore them to their original location?

Thank you for your help.
This computer is an HP Pavilion g7, running Windows 7.

9 réponses

Malekal_morte- Posted messages 178136 Registration date   Status Modérateur, Contributeur sécurité Last intervention   24 711
 
Hi,

AdwCleaner etc. are useless, it's a real virus.

Check out this thread: https://forums.commentcamarche.net/forum/affich-30513808-pc-infecte-par-win32-expiro-bu

Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
0
seduesed Posted messages 7 Status Membre
 
Hi,
thank you for your response, I'm trying with the two links you mentioned.

What about the quarantined items, should they be permanently deleted?
0
Malekal_morte- Posted messages 178136 Registration date   Status Modérateur, Contributeur sécurité Last intervention   24 711
 
It's a virus that infects executables, so if you've quarantined files, you might have applications, or even Windows components, that will stop functioning.

You have to hope that Kaspersky or Dr. WEB can repair the files (that they remove the malicious part), otherwise you'll have to format without keeping any executables, otherwise you'll end up restoring everything.
0
seduesed Posted messages 7 Status Membre
 
Ok, which means that I leave everything in quarantine hoping that the tools will clean them up.<br />I started Kaspersky, I'll keep you posted but thanks already.
0
seduesed Posted messages 7 Status Membre
 
That said, Avast identifies it as a rootkit. But perhaps it’s just a matter of wording?
0
seduesed Posted messages 7 Status Membre
 
Kaspersky remove tool removed...a trojan and I still have the alert message from Avast, except that the virus has changed its name: WIN32:evo-gen[susp]!
Well, I'll try with Dr Web.
0
Malekal_morte- Posted messages 178136 Registration date   Status Modérateur, Contributeur sécurité Last intervention   24 711
 
If Kaspersky found only one trojan, it means the infection is not very widespread.
WIN32:evo-gen[susp] was found in which file?

--
Comme l'ange que tu es, tu ris en créant une légèreté dans ma poitrine,
Tes yeux me pénètrent,
(Ta réponse est toujours 'peut-être')
C'est alors que je me suis levé et suis parti.
0
seduesed Posted messages 7 Status Membre
 
Hello,
it's always the same file, at startup and when I close a program:
C\windows\system32\svchost.exe
Furthermore, at startup, this notification appears: and this program opens:
What does it correspond to, what should I do?
0
Malekal_morte- Posted messages 178136 Registration date   Status Modérateur, Contributeur sécurité Last intervention   24 711
 
Ah, some messes.

Do a cleanup with the Live CDs.
Otherwise, you're headed for a format.

--
Comme l'ange que tu es, tu ris en créant une légèreté dans ma poitrine,
Tes yeux me pénètrent,
(Ta réponse est toujours 'peut-être')
C'est à ce moment que je me suis levé et suis parti.
0
seduesed Posted messages 7 Status Membre
 
OK, here we go

Um, um, the procedures seem very complicated for me. If you think there is no urgency, (I have access to essential programs without any issues), rather than diving in, I would prefer to wait for my brother who was a computer scientist by profession.
0