IPB

Welcome Guest ( Log In | Register )

12 Pages V  < 1 2 3 4 > »   
Reply to this topicStart new topic
> [Merged] False Positive...explorer.exe?, Worm.Win32.Huhk.c
Baz^^
post 20.12.2007 00:47
Post #21


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Word back from viruslab:

QUOTE
Hello, it is a false alarm. Will be fixed in the next update.


--
Best regards, Shvetsov Dmitry
Virus analyst, Kaspersky Lab.

e-mail: newvirus@kaspersky.com
http://www.kaspersky.com/





--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
__d_mode__
post 20.12.2007 00:48
Post #22


Newbie
*

Group: Members
Posts: 7
Joined: 20.12.2007




QUOTE(alanrew @ 20.12.2007 01:35) *
What's the easiest way to get this? Is there a built-in MD5 hash program in Windows, or Kaspersky? If not, where do I get the utility?

TIA

Alan


u can send explorer.exe to virustotal.com for scan,also it says md5 and sh1 hash like that:
http://www.virustotal.com/tr/resultado.htm...28c590feeea87bb

just kaspersky says infected worm
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 00:55
Post #23


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




If you still have use of the pc, you can restore the explorer.exe from the Kaspersky backup:

http://support.kaspersky.com/faq/?qid=198984858 -Version 6

http://support.kaspersky.com/faq/?qid=208279413 - Version 7



--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
GAtkinson
post 20.12.2007 00:55
Post #24


Newbie
*

Group: Members
Posts: 2
Joined: 20.12.2007




QUOTE(__d_mode__ @ 19.12.2007 21:48) *
u can send explorer.exe to virustotal.com for scan,also it says md5 and sh1 hash like that:
http://www.virustotal.com/tr/resultado.htm...28c590feeea87bb

just kaspersky says infected worm



===========================================================================

1st post here so apologies if I get the format, appropriacy wrong, etc.

After commiting the Kaspersky delete action against the explorer.exe, I get a blank desktop

Here's how I recovered:

From a blank desktop
Bring up task manager
Select file and run
CMD to the dos prompt
with a usb drive with a good copy of explorer from another machine plugged in
use DOS commands to copy to C:\Windows where it should live
Got my PC back
Will now need to disable Kaspersky until this is fixed

Any timescale on 'the next release' from Kaspersky - this is pretty much a show stopper.




Go to the top of the page
 
+Quote Post
alanrew
post 20.12.2007 00:55
Post #25


Member
**

Group: Members
Posts: 16
Joined: 20.12.2007
From: UK




QUOTE(__d_mode__ @ 19.12.2007 21:48) *
u can send explorer.exe to virustotal.com for scan,also it says md5 and sh1 hash like that:
http://www.virustotal.com/tr/resultado.htm...28c590feeea87bb

just kaspersky says infected worm



OK, my copy of explorer.exe has the MD5 hash
97bd6515465659ff8f3b7be375b2ea87

Win XP SP2, C:\windows\explorer.exe

Regards

Alan
Go to the top of the page
 
+Quote Post
Anthony1uk
post 20.12.2007 00:59
Post #26


Member
**

Group: Members
Posts: 19
Joined: 10.06.2005




QUOTE(Heathcliff Huxtable @ 19.12.2007 21:45) *
I now don't have Explorer running. I'm still trying to figure out how to get that back. If anybody knows how to do that quickly, I'd appreciate a pointer.

Just hold down Control + Alt + Deleate. (This should bring up task manager)

Go to File in the top left then click run.

Type in Explorer.exe

Then click OK.

_______________

I was using the internet all day without worries, turned my PC off for about an hour at 8.45pm. Came back now at 9.45 and got this trojan warning on Explorer.exe too.

I immediately assumed it was a FP but came here to be sure.

This post has been edited by Anthony1uk: 20.12.2007 00:59
Go to the top of the page
 
+Quote Post
bbk7
post 20.12.2007 01:01
Post #27


Newbie
*

Group: Members
Posts: 1
Joined: 20.12.2007




Hello,

I'm having the same problem as Malucarp. The Kaspersky error message shows up on the start up screen. Delete/skip does not work and the computer boots again automatically. Can you please tell me what to do?

Thank you,
Go to the top of the page
 
+Quote Post
Heathcliff Huxta...
post 20.12.2007 01:01
Post #28


Newbie
*

Group: Members
Posts: 2
Joined: 20.12.2007




QUOTE(MAPKOBKA^^ @ 19.12.2007 13:55) *
If you still have use of the pc, you can restore the explorer.exe from the Kaspersky backup:

http://support.kaspersky.com/faq/?qid=198984858 -Version 6

http://support.kaspersky.com/faq/?qid=208279413 - Version 7


Thank you
Go to the top of the page
 
+Quote Post
Malucarp
post 20.12.2007 01:04
Post #29


Member
**

Group: Members
Posts: 27
Joined: 31.07.2007
From: U.S.




QUOTE(MAPKOBKA^^ @ 19.12.2007 15:47) *
Word back from viruslab:



Thanks very much.

Mike
Go to the top of the page
 
+Quote Post
kaboro
post 20.12.2007 01:05
Post #30


Newbie
*

Group: Members
Posts: 1
Joined: 20.12.2007




After i ran the Kaspersky update today, i got this popping on my screen:

Running module contains virus and cannot be disinfected
Virus:
Worm.Win32.Huhk.c
Running module:
explorer.exe\Explorer.exe

I selected "delete" and a second warning popped up about same virus, selected delete again, after the second delete the PC restarted by itself.
When windows XP restarted, i had no desktop icons and no bottom taskbar anymore, tried restarting in safe mode and got only a black screen.
I accessed kaspersky from the ctrl-alt-del file menu and restored explorer.exe, that made my PC operative again.
Now the scan shows six instances of this Huhk.c worm, here are the locations:

1: detected: virus Worm.Win32.Huhk.c Running module: explorer.exe\Explorer.EXE

2: detected: virus Worm.Win32.Huhk.c File: C:\WINDOWS\Explorer.EXE

3: detected: virus Worm.Win32.Huhk.c File: C:\System Volume Information\_restore{79B739DD-F9C6-4DE4-9E6F-57736A2DF999}\RP62\A0011393.exe

4: detected: virus Worm.Win32.Huhk.c File: C:\System Volume Information\_restore{79B739DD-F9C6-4DE4-9E6F-57736A2DF999}\RP62\A0011394.exe

5: detected: virus Worm.Win32.Huhk.c File: C:\System Volume Information\_restore{79B739DD-F9C6-4DE4-9E6F-57736A2DF999}\RP62\A0011405.exe

6: detected: virus Worm.Win32.Huhk.c File: C:\windows\system32\dllcache\explorer.exe


Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 01:07
Post #31


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Hi, yes, they will carry on to show until the fix is rolled out via the updater. This will be very soon.


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 01:12
Post #32


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




If you have no icons/taskbar/menus/etc, you can try to restore explorer as follows:


Open task manager (CTRL+SHIFT+ESC)


click on file- New task (run)

Attached File  K_1.JPG ( 65.41K ) Number of downloads: 76


In the box that pops up, type in the path to your kaspersky installation and avp.exe,

Attached File  K_2.JPG ( 66.48K ) Number of downloads: 67


so for example, mine is located at

C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

Replace the \Kaspersky Anti-Virus 7.0\ with whatever version you are runnning, so for example, it could be
\Kaspersky Anti-Virus 6.0\
\Kaspersky Internet Security 6.0\
\Kaspersky Internet Security 7.0\


Click OK (you will have to repeat this process once more if you have disabled Kaspersky from starting up with Windows, to bring up the Kaspersky interface)


Kaspersky main window should pop open

Now, restore from the Kaspersky "backup" which can be accessed via "reports and data files" tab - backup

Attached File  K_3.JPG ( 67.7K ) Number of downloads: 49





Explanation of the backup tab:

Version 6- http://support.kaspersky.com/faq/?qid=198984858
Version 7- http://support.kaspersky.com/faq/?qid=208279413

This post has been edited by Igor Kurzin: 20.12.2007 12:17


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 01:23
Post #33


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




If you have lost taskbar/startmenu etc, try this method to get it back from the backup of Kaspersky:

http://forum.kaspersky.com/index.php?showt...st&p=503423


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Timodinho
post 20.12.2007 01:34
Post #34


Member
**

Group: Members
Posts: 14
Joined: 20.12.2007




Is this a real or a false virus ?
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 01:35
Post #35


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




If it is in C:\WINDOWS\Explorer.EXE,

Then at the moment it is a false alarm. It will be fixed shortly.


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Fred
post 20.12.2007 01:38
Post #36


Advanced Member
***

Group: KL France
Posts: 108
Joined: 11.04.2005
From: France




Hi Guys,
Virus Doctors informed about this, it should be solved in the next minutes if false-positive. wink.gif

Bye Fred


--------------------
Go to the top of the page
 
+Quote Post
Fred
post 20.12.2007 01:41
Post #37


Advanced Member
***

Group: KL France
Posts: 108
Joined: 11.04.2005
From: France




Ok Guys,
Reply from Virus Doctors :
"It is false alarm. It will be fixed as soon as possible. Thank you for your help"

Don't delete the Explorer.exe and do NOT format your system smile.gif

Bye Fred


--------------------
Go to the top of the page
 
+Quote Post
Baz^^
post 20.12.2007 01:42
Post #38


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Fred, you missed the train by about 5 mins laugh.gif


http://forum.kaspersky.com/index.php?showt...st&p=503379


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
Timodinho
post 20.12.2007 01:43
Post #39


Member
**

Group: Members
Posts: 14
Joined: 20.12.2007




QUOTE(MAPKOBKA^^ @ 19.12.2007 23:35) *
If it is in C:\WINDOWS\Explorer.EXE,

Then at the moment it is a false alarm. It will be fixed shortly.

Yeah its in that map, but it delete's my 'taakbalk'
taakbalk is dutch, I don't know the english word for it sorry...
and my computer is closing down by himself if I don't close my kaspersky virusscanner
Go to the top of the page
 
+Quote Post
Timodinho
post 20.12.2007 01:45
Post #40


Member
**

Group: Members
Posts: 14
Joined: 20.12.2007




The word that I mean is Task beam or something
Go to the top of the page
 
+Quote Post

12 Pages V  < 1 2 3 4 > » 
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 21.11.2009 19:42