Win64:Dropper-Gen[Drp]

Ok, system restore complete and internet access is back.

I’ve attached the ComboFix.txt

OK time to remove manually

Could you now run a fresh OTL scan please, ensure that all users is selected

There will only be one log this time

Sorry, do you mean another quick scan or the scan you mentioned earlier with

netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir “%systemdrive%*” /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT

Just a quick scan as I have seen the data from the script, just ensure that all users is checked :slight_smile:

Not sure if I did something wrong, I still got two logs.

Both are attached.

I got this same exact problem today. The computer booted fin this morning and I did not do anything noteworthy with the system. This evening it wouldn’t open explorer.exe.

I reverted back to my week old backup (full system image), it would boot fine, then as soon as it updated the virus detection database, avast wouldn’t let explore.exe open. I tried to scan my month old backup of explorer.exe, Avast still detects Win64:dropper-gen.

I figured it’s one of two things:

  • I’ve been running the virus all this time and only now has avast! started detecting it
  • it’s a false positive

I used a couple of other scanners (including combofixer), none detect a problem with explorer.exe, so I whitelisted it. Everything seems perfect.

I’m starting to thing I did a bad move coming back to avast… It let me down once, many years ago, and no, fortunately, it didn’t let my system get infected, but I’m not too happy about this.

@Morbus could you start your own thread please

OK I can see what adwcleaner did now

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF


:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=ds&q={searchTerms}&installDate=19/10/2013
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=ds&q={searchTerms}&installDate=19/10/2013
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=ds&q={searchTerms}&installDate=19/10/2013
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=hp&installDate=19/10/2013
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=ds&q={searchTerms}&installDate=19/10/2013
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=ds&q={searchTerms}&installDate=19/10/2013
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=ds&q={searchTerms}&installDate=19/10/2013
IE - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = http://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPB1BE246B-8474-43EC-A585-B1520C31887D&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch"
FF - prefs.js..browser.search.defaulturl: "http://websearch.soft-quick.info/?l=1&q="
FF - prefs.js..browser.search.order.1: "WebSearch"
FF - prefs.js..browser.search.order.1,S: S", "WebSearch"
FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch"
FF - prefs.js..keyword.URL: "http://feed.snapdo.com/?publisher=Somoto&dpid=Somoto&co=CA&userid=ce917bfa-2d26-d2b1-b4f3-bd2e4720613a&searchtype=ds&installDate=19/10/2013&q="
[2014/01/26 00:23:02 | 000,119,670 | ---- | M] () (No name found) -- C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\z2o2e9yv.default\extensions\jid1-mqCpKcAruymyAA@jetpack.xpi
[2013/12/02 12:23:56 | 000,494,053 | ---- | M] () (No name found) -- C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\z2o2e9yv.default\extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi
[2014/02/26 14:51:01 | 000,957,290 | ---- | M] () (No name found) -- C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\z2o2e9yv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000\..\Toolbar\WebBrowser: (no name) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No CLSID value found.
O4 - HKU\S-1-5-21-3854713794-3905390332-3595074850-1000..\Run: [LoL Summoner Information] C:\Program Files (x86)\LSI\LoLSummonerInfo.exe File not found

:Files
C:\ProgramData\Tarma Installer
C:\Program Files (x86)\MyPC Backup
C:\Windows\SysWOW64\AI_RecycleBin
C:\Users\Jason\AppData\Local\blekkotb_031
C:\Users\Jason\AppData\LocalLow\Conduit
C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\z2o2e9yv.default\searchplugins\conduit-search.xml
C:\Windows\System32\Tasks\Your File Updater
C:\Windows\System32\Tasks\YourFile Update

:Commands
[resethosts]
[emptytemp]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Here’s the result of the quick scan; 1 file this time.

How is the computer behaving now ?

Computer seems great, although I have put the explorer.exe in File Systems Shield exclusions.

Is it still alerting then ?

Yes.
I previously disabled avast for the scans allowing me to open explorer, but the alert was still there when I re-enabled avast.

Hmm I do not believe this to be a false positive as it is not alerting on my system

Please download Malwarebytes AntiRootkit and save it to your desktop.

Full instructions how to use MBAR
Please note: This is a beta version so please be sure to read the disclaimer and note of it.

• Unzip/unrar MBAR in a folder to your Desktop and MBAM shall run …

• Click on Next > then on Update button to download fresh definitions.

https://dl.dropboxusercontent.com/u/73555776/mbar_update.JPG

• When database updates click Next

• In the following window ensure “Targets” scan for Drivers; Sectors; System are ticked. Then select “Scan button”

https://dl.dropboxusercontent.com/u/73555776/mbarscan.JPG

• If an infection/s are found ensure “Create Restore Point” is checked, then select the “Cleanup Button” to remove threats.
Or if you are sure any entries should be kept, just untick them. A list of infected files will be listed.

• The Clean up procedure will be Scheduled for process.
• When complete pop-up will show you. Select the Yes button and the system should re-boot to complete the cleaning process.

Please attach the two following logs from the mbar folder:

system-log.txt
and
mbar-log-year-month-day (hour-minute-second).txt.

The scan finished and no malware was found

I also made sure to check the three boxes Drivers, Sectors, and Systems

For what it’s worth, and I do know I should make a separate thread or whatnot (but considering this is the first hit on google when I search for the issue, so…), I also ran that test and nothing was found. My computer is totally clean. It’s a 1 month old install anyway, and I don’t install crap and am extremely security-conscious (adblock, no-script, no plugins and whatnot, and no piracy).

Just thought I’d post after googling same problem. I use a fresh image from 6/9/2013 - Win 7 Pro x64, which I continually update. Re-applied that image yesterday, was fine. Today, after Avast update, ‘explorer.exe’ contains virus. VirusTotal confirms 0/49. This surely must be a 'False/Positive".

It simply means that somehow, there is more than one version of explorer.exe on Windows. I have a version of explorer.exe that has been modified from the stock version of explorer.exe. The Virustotal scan detects no threats other than from Avast.

linking all the threads together:

http://forum.avast.com/index.php?topic=147308 (this thread)
http://forum.avast.com/index.php?topic=147328
http://forum.avast.com/index.php?topic=147333
http://forum.avast.com/index.php?topic=147339

I have also alerted Avast of the file (although the last time I did this they took >3 months to reply…)

Hi all, I believe I have found the source of the problem (the reason for my patched explorer.exe). The culprit is Windows 7 Start Button Changer which modifies explorer.exe to change the start button.
virustotal scan: https://www.virustotal.com/en/file/6c92965feb7f901b56d3b949ee2cdace9c9fc9f4ebf7cdf46056a62581f60371/analysis/1394257968/
considering that I have bbLean as my shell and have not even seen the W7 taskbar in months, I unpatched my explorer.exe (with the program) and the problem disappeared.

If you had knowingly modified explorer.exe (with a program such as W7SBC) and trust that program, then you may whitelist explorer.exe in Avast for now.
Of course, there is still the chance that explorer.exe is malware. So do it at your own risk.

I, too, use Windows 7 Start Button Changer. Odd that Avast thinks is is fine for 6 months of usage, now detects as trojan.