IPB

Welcome Guest ( Log In | Register )

12 Pages V  « < 6 7 8 9 10 > »   
Reply to this topicStart new topic
> [Merged] False Positive...explorer.exe?, Worm.Win32.Huhk.c
Kilauea
post 20.12.2007 11:21
Post #141


German Forum Moderator
*************

Group: Moderators
Posts: 4768
Joined: 14.04.2005
From: germany




Just copy explorer.exe to C:\windows and restart.


Kilauea


--------------------
Go to the top of the page
 
+Quote Post
win32
post 20.12.2007 11:25
Post #142


Member
**

Group: Members
Posts: 15
Joined: 20.12.2007




QUOTE(Kilauea @ 20.12.2007 11:21) *
Just copy explorer.exe to C:\windows and restart.
Kilauea


Thanks! Could you send it to me please?
Go to the top of the page
 
+Quote Post
Kilauea
post 20.12.2007 11:27
Post #143


German Forum Moderator
*************

Group: Moderators
Posts: 4768
Joined: 14.04.2005
From: germany




Which operating system are you using. Or,you can find a copy of it on your installation-cd of windows.


Kilauea


--------------------
Go to the top of the page
 
+Quote Post
win32
post 20.12.2007 11:29
Post #144


Member
**

Group: Members
Posts: 15
Joined: 20.12.2007




WIndows XP, thanks. If you have it at hand, cause I am currently away from home and cannot access my installation disk..
Go to the top of the page
 
+Quote Post
Kilauea
post 20.12.2007 11:36
Post #145


German Forum Moderator
*************

Group: Moderators
Posts: 4768
Joined: 14.04.2005
From: germany




I hope that this works. I am not allowed to upload an exe file here.

Please send me a PN with your Mailadress, you get a explorer.exe from a fully patched xp professional german


Kilauea


--------------------
Go to the top of the page
 
+Quote Post
win32
post 20.12.2007 11:39
Post #146


Member
**

Group: Members
Posts: 15
Joined: 20.12.2007




QUOTE(Kilauea @ 20.12.2007 11:36) *
I hope that this works. I am not allowed to upload an exe file here.

Please send me a PN with your Mailadress, you get a explorer.exe from a fully patched xp professional german
Kilauea


Just send a PN with my address...thanks hope it works!
Go to the top of the page
 
+Quote Post
Kilauea
post 20.12.2007 11:40
Post #147


German Forum Moderator
*************

Group: Moderators
Posts: 4768
Joined: 14.04.2005
From: germany




And here is a link, too. smile.gif
http://rapidshare.de/files/38090140/explorer.exe.html


Kilauea


--------------------
Go to the top of the page
 
+Quote Post
MrD
post 20.12.2007 12:03
Post #148


Member
**

Group: Members
Posts: 20
Joined: 20.12.2006




Ok I got the "worm.win32.huhk.c" 15 min ago..

KIS 6, deleted two files to the backup:

c:\windows\explorer.exe
and
explorer.exe\Explorer.EXE

I did a restore for c:\windows\explorer.exe
KIS then told me that explorer.exe had changed, so I clicked "Allow"

Why did it change, if it was only a false positive??
Then I did a signature update and now Im running a scan...

I can't restore explorer.exe\Explorer.EXE
What's this and do I need it?

Go to the top of the page
 
+Quote Post
Kilauea
post 20.12.2007 12:07
Post #149


German Forum Moderator
*************

Group: Moderators
Posts: 4768
Joined: 14.04.2005
From: germany




If you restore the explorere.exe from the backup, make sure that the directory is -> C:\windows

customise C: if C: is not your systempartition.


Kilauea


--------------------
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 12:07
Post #150


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Hi,

If you have your taskbar, and the desktop is not blank, then it seems explorer is alread in it's rightful place.

Check if one is present in C:\windows\explorer.exe


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 12:13
Post #151


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Hi,

I assume you already have read this thread: http://forum.kaspersky.com/index.php?showtopic=55669


It was unfortunately a false positive sad.gif


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
MrD
post 20.12.2007 12:18
Post #152


Member
**

Group: Members
Posts: 20
Joined: 20.12.2006




QUOTE(Kilauea @ 20.12.2007 09:07) *
If you restore the explorere.exe from the backup, make sure that the directory is -> C:\windows

customise C: if C: is not your systempartition.
Kilauea

Yes I understand that, as I wrote, KIS was succesful in restoring the first file to c:\windows

But the second file is not from i directory.. it follows an exe-file
explorer.exe\Explorer.EXE

To my knowledge there should not be a file named "Explorer.EXE" with capital letters from a Windows XP install.
I dont understand where this file came from?
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 12:20
Post #153


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Hi, thats fine, no need to restore it.


the explorer.exe\Explorer.exe, is the same file as C:\windows\explorer.exe, but it was a running module at the time, which is why Kaspersky has not specified a location. As long as you have restored the one in C:\Windows, you should be fine.


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Cnon
post 20.12.2007 12:53
Post #154


Advanced Member
****

Group: Members
Posts: 407
Joined: 17.04.2006




QUOTE(MAPKOBKA^^ @ 20.12.2007 02:13) *
Hi,

I assume you already have read this thread: http://forum.kaspersky.com/index.php?showtopic=55669
It was unfortunately a false positive sad.gif


Oh yes and I'm okey dokey now. b_punk.gif
Go to the top of the page
 
+Quote Post
GAtkinson
post 20.12.2007 12:59
Post #155


Newbie
*

Group: Members
Posts: 2
Joined: 20.12.2007






I currently have a systen running as I copied another explorer.exe to the C:\windows directory on my damaged system
Needless to say I want the original back.

Unfortuneately Kaspersky/Backup/Restore does not complete the restore and gives me an access denied message for the file when I do try to restore it.

Please confirm this is going to be fixed with the imminent fix or how I can get hold of that original explorer.exe/get kaspersky to release it by other means....
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 13:02
Post #156


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Hi,


I think that is because windows will not allow you to replace the explorer.exe already in place there on top of another explorer.exe.

You can try to rename the explorer.exe in place now, or move it to another location and then use the method i discribed to get the original back in place.



--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 14:51
Post #157


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Animated FAQ of my fix, now available on Kaspersky Website:

http://support.kaspersky.com/viruses/computers?qid=208279581


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
win32
post 20.12.2007 16:40
Post #158


Member
**

Group: Members
Posts: 15
Joined: 20.12.2007




QUOTE(GAtkinson @ 20.12.2007 12:59) *
I currently have a systen running as I copied another explorer.exe to the C:\windows directory on my damaged system
Needless to say I want the original back.

Unfortuneately Kaspersky/Backup/Restore does not complete the restore and gives me an access denied message for the file when I do try to restore it.

Please confirm this is going to be fixed with the imminent fix or how I can get hold of that original explorer.exe/get kaspersky to release it by other means....


Hi!

Had the same problem. See the post #147 adn download the explorer.exe from there. Now the system is up and running again with toolbars and everything.
Go to the top of the page
 
+Quote Post
win32
post 20.12.2007 16:42
Post #159


Member
**

Group: Members
Posts: 15
Joined: 20.12.2007




QUOTE(win32 @ 20.12.2007 11:39) *
Just send a PN with my address...thanks hope it works!


Thanks for your help! I solved the problem.
Go to the top of the page
 
+Quote Post
rjbsec
post 20.12.2007 17:02
Post #160


Advanced Member
***

Group: Members
Posts: 54
Joined: 19.06.2005




Well I'm glad everyone is happy that everything has been fixed mad.gif
Last night my laptop reported the Worm32.Huxxx infection with a popup warning me that my PC was infected and prompting me to delete ... it then went on to delete my desktop and corrupt my Acronis Backups on the laptop and associated external USB drive.
My laptop was unuseable and I was unable to restore my backup!
By good fortune I had upgraded my drive a few days ago so I had a 'backup', albeit a few days old, so I am able to continue - without the old drive I would be stuffed.
These events could have been disasterous for me and I would like to know what I can do in order to prevent something like this happening again - I bought and trusted Kaspersky to protect my PC, in fact this week it's probably done more to cause me problems than a virus would have done!
Go to the top of the page
 
+Quote Post

12 Pages V  « < 6 7 8 9 10 > » 
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 22.11.2009 10:26