A dropper trojan has been detected in explorer.exe - please help!

When I logged in a few days ago, there was no desktop and the screen was entirely black, with just the cursor visible. I opened task manager and no applications were running, so I tried to run explorer.exe and got the error message:

C:\Windows\explorer.exe

Operation did not complete successfully because the file contains a virus.

After this I did a boot scan and it informed me that explorer.exe was infected with Win32:dropper-gen [Drp]

I’ve tried several different antivirus software to try to fix this problem. I’ve also done a system restore to a point earlier in the week (before I had this problem), but ultimately I’ve had to come here as my efforts have had no effect.

The odd thing about this message is that it doesn’t always appear. When the message appears (and the desktop does not show up), restarting the computer seems to magically fix the symptoms.

Please help!

Hi what is the VPS version of Avast ? It should be 140310-0, also do you use windows7 button software or something similar

The version is 140310-0 .
What do you mean by button software?

I've tried several different antivirus software to try to fix this problem.
Does this mean you have more then one AV installed?

Theme software that changes the start button on windows. As there was a false positive on this a few days ago… Is it still alerting

@Pondus: By this I mean I’ve run mbam, tdsskiller, emsisoft emergency kit etc.

@essexboy: Yes - I changed the start button a very long time ago! Is it safe to assume this is the cause, then?

It is possible could you let me know what file Avast has put in the virus chest. Also right click that file and select scan, does it still report it as infected

Since I did a system restore to a point before I got the message (and therefore before I did the boot scan), I’m not certain that the virus chest would still contain the item. I’ll do another boot scan right now to make sure, so my next reply may take a while.

The items currently in the chest are:
cleanup.bat (BV:KillAV-EC [Trj])
FileSYstem_Steam.dll (no virus)
Unconfirmed 962796.crdownload (Win32:InstalleRex-BH [PUP])
vtex.exe (no virus)

Ok, I have finally completed the boot scan. No items were moved to the chest, however the detailed report of the boot scan reports the following items with Win32:Dropper-gen [Drp]:

C:\Windows\explorer.exe
C:\Windows\explorer_backup.exe
C:\Windows\explorer_backup_w7sba.exe
C:\Windows\explorer_edit_w7sba.exe

EDIT: Just now, while on my PC, Avast stopped explorer.exe and claimed that explorer.exe in winlogon.exe was infected with the dropper virus.

Hmm I thought that was fixed

Could you right click those files in the virus chest and send them to the virus labs as a false positive

I don’t think any of these are to do with the explorer.exe trojan report. The only one that could be linked to it by date would be cleanup.bat:

cleanup.bat was transferred on 08/03/2014
FileSystem_Steam.dll was transferred on 05/08/2012
Unconfirmed 962796.crdownload was transferred on 14/02/2014
vtex.exe was transferred on 10/01/2014

Those files appear to be related to chrome and steam … Do you use both programmes

I do.
The files which were to do with steam are apparently clean now.
I have no idea what the chrome download was, but it claims to be infected.
I don’t know where cleanup.bat came from.

Cleanup bat could in reality be used by any programme to tidy up after updating etc…

Is Avast still alerting on explorer ?

Just this morning I had the same black screen symptoms with explorer not running because it “contains a virus”.

Are you experiencing any other problems apart from that ?

If not then upload all versions of explorer in the virus chest to Avast as false positives

Then place an exception for explorer

No, I’ve had no other problems.

I can’t move explorer.exe to the chest, but the other explorers (backups and edit) have been moved and uploaded as false positives.

Thanks for your help. I wish I’d come to you first instead of spending almost 4 days straight trying to fix a problem that wasn’t there! :slight_smile:

No problem, it is an unusual one this as it appears that the heuristics do not like some element of the programme

Test the files in the chest every few days and hopefully fairly soon they will show as clean