Virus located in C:\Windows\explorer.exe

I am getting so many notifications about malware and rootkit, by Avast!. It says the location is in the C:\Windows\explorer.exe. Help me get rid of it plzzzzzz. Its really annoying…

follow the guide here and attach the logs

http://forum.avast.com/index.php?topic=53253.0

Malwarebytes’ Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8036

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

10/28/2011 11:28:55 PM
mbam-log-2011-10-28 (23-28-55).txt

Scan type: Quick scan
Objects scanned: 153594
Time elapsed: 4 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Backdoor.Agent) → Value: Shell → Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

can you attach aswMBR and OTL logs ?

:-\ Don’t even know what that is. Please guide me through it, I am new to this stuff. I’ll appreciate it.

it is all in the guide i gave you the link to above…

click the red OTL in the guide, download and save to desktop…just follow Essexboy instruction

same thing with aswMBR

then in you attach the logs here
see lower left corner > additional options > attach

Visit the first link Pondus gave, that gives information on the tools and how to use them.

Once you have run the tools - To attach a file, when you reply click on the Additional Options, that allows you to attach the log files.

Here are the logs.

Essexboy is notified…check back tomorrow :wink:

Thanx alot Pondus & DavidR…

You’re welcome

From my limited experience, the aswMBR scan indicates that you have either the zero access or conserv infection and will need essexboy to analyse your OTL.txt log and compile a fix

Whilst this is a bit of a pain with the alerts, avast appears to be stopping its spread.

Winlogon has been replaced so lets reset that first

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL O20 - HKCU Winlogon: Shell - (C:\Users\RAJA Umair Javed\AppData\Local\62073343\X) -C:\Users\RAJA Umair Javed\AppData\Local\62073343\X () [2011/10/28 03:27:44 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\Users\RAJA Umair Javed\taskmgr.exe [2011/10/28 03:27:42 | 000,000,000 | -HSD | C] -- C:\Users\RAJA Umair Javed\AppData\Local\62073343

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

.
THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Here is the log.

Could you attach the combofix log please

Combofix is not showing any log. I ran it like 5 times and nothing shows up. Why is that happening??

When you ran it could you confirm that Avast did not sandbox it

Are you still getting the alerts ?

By the way there are no more annoying notifications. ;D

What other problems are you experiencing ?