The originator wrote
[i]Hi all,
I need some help.
My system seems to be infected with a virus Win32:Trojan-gen. {UPX!} (my Avast On-Access scanner picks it up).
The problem is that when it is detected (e.g. file name C:\DOCUME~1\MARKAD~1\LOCALS~1\Temp\winF.tmp) and I delete it, the same virus is detected again and again just in a different .tmp file.
I have tried running a boot scan and also the latest version of Ad-Aware SE. I take all the suggested action and the system appears to be clean. But everytime I open Internet Explorer, the virus is detected again.
WHAT DO I DO!!!?
Thanks in advance for your help!
(p.s. I am running Windows XP and IE version 6.)
(p.p.s. I am afraid I am not very technically minded and so I’ll need straight forward instructions)
[/i]
========================================================
[b]I think/hope that I have just got this off my system, I did it by deleting, in DOS, a file named XEJHE.EXE in the root directory of the main system drive C:. NOTE I am running W98SE, I don’t know how you would do the equivalent under XP.
I discovered it via a combination of three utilities
- avast! which was reporting the problem as described above (Win32:Trojan-gen. {UPX!})
-sysinternals Process Explorer which showed XEJHE starting up & stopping and I knew not what it was
-Metaproduct’s StartUp Organiser reported a peculiar new entry in the registry 3MyFqGXrc with the path to the XEJHE.EXE this was placed in Registry/AllUsers/Run, I removed this entry and then IMMEDIATELY exited to DOS and deleted the aforementioned file.
Hopes this helps, oh I suspect the filename XEJHE.EXE might be randomly generated i.e. it might be GT9JK.EXE on your system, same with the registry tag, but it was the latter with it’s reference to XEJHE.EXE that confirmed my suspicions.
I am running a full thorough scan at the moment all those dodgy files in the temp directories are being picked up, but be killing the XEJHE.EXE file I think I eliminated the program that was spawning the “virus” infections into the temporary directories.
Hope this helps
rgds PhilD
[/b]