Help - Search - Members
Full Version: [Merged] False Positive...explorer.exe?
Kaspersky Lab Forum > English User Forum > Virus-related issues
Pages: 1, 2, 3, 4, 5
Whizard
You can discard the warnings safely.
Flags
QUOTE(Whizard @ 19.12.2007 17:55) *
>>How do I update the signatures????
You will need to consult the settings of your program, as I was unable to locate the main website of your particular utility, which is a Kaspersky clone by the way.


Hi and i did the up date and restarted and scaned again and it was fixed and yes Defender Pro does work with Kaspersky Labs or should say go's thru Kaspersky Labs and i have been useing Defender Pro for years and so in that case you should look more better guess i know alittle more about Defender Pro so i hope anybody useing Defender Pro just let the Virus update "update" it's self and it will be fixed and then reboot your computer and it is fixed and the websit to Defender Pro is http://defender-pro.com/ so anybody that wants to go see there it is and check it out.

Sincerely,Flags
Whizard
Hello Flags,

Defender-Pro is based on a very old version of Kaspersky 5.xx product just simply rebranded. Please note that that product has reached end of life and is no longer supported. You can find more information here:
http://support.kaspersky.com/supported_home

Therefore, all support queries will have to be forwarded to Defender-Pro. I would encourage you to install full Kaspersky product. You can find comparison here http://kaspersky.com/compare
sproket
QUOTE(Whizard @ 19.12.2007 20:34) *
You need an original disk not an OEM, which customized by the manufacturer.
Media Center Edition, usually has XP Professional as the base install.



All of my disks are original WMCE straight from microsoft for the full price. Basically the system keeps asking for my original discs, but it doesn't like them. They are 100% microsoft ONLY not OEM. Whatever happened during repair, hosed a bunch of DLLs.


Thanks for trying to help but i'm out of alternatives. Just going to wipe and start over. It's the only way I can be assured I'm back to a 100% stable system.
Whizard
Sorry to hear that sproket. I hope you have backups handy smile.gif
Sniper Elliott
QUOTE(MAPKOBKA^^ @ 19.12.2007 21:37) *
Hi guys,

Will raise this with viruslab as a matter of urgency.... it would help if someone could grab a copy of explorer.exe, and send it to newvirus@kaspersky.com with "false positive" in the title.

Try to update, because my defs are not flagging.



Have tried to send you an e-mail with explorer.exe attatched. Hope it gets through ok. Sent it to add as above.

Swampy
Whizard
Hello Swampy,

There is no need for any additional samples. Please update your signatures manually and you should be set!
death.by.huhk.c.
Hi, my first post so please bear with me!

I can’t do anything on my affected computer. No programs will start. I can’t even backup anything. Windows recommended I run CHKDSK, but that didn’t help.

When I follow Markovka's instructions I get the error message: "The application failed to initialize properly (0xc0000005). Click on OK to terminate the application.

What can I do?

My OS is Windows XP Home Edition SP2
Baz^^
QUOTE(By-Tor @ 20.12.2007 00:54) *
Worm.Win32.Huhk.c virus

Here is how you clear this shitty bug out. Hopefully the KAV updates will fix this bullshit.

1. Start Windows. When it “loads” do a CTRL + ALT + DEL to open task manager.
2. In task manager, click FILE , New Task (Run) , Go to ( C ): Kaspersky , AVP.exe and click OPEN.
3. Close task manager and go to the now open Kaspersky. (I had to do this twice before KAV opened)
4. In KAV, go to Service,Data Files,Backup,Files and restore the “explorer.exe” in C;/Windows/
5. Restart your PC


Voila! When I restored, it automatically put the file in the correct place, but keep your eyes open anyway.

Hope this helps somebody!

UPDATES SHOULD BE IN!!! CROSS YOUR FINGERS!!!



1) Watch your language, we prefer to talk in a civilised way here, even if there is a problem.

2) That is exactly the same "fix" I posted on page #2 of this thread

3) The signature was corrected a few hours ago.



Please also bear in mind the time differences. It is 2AM here, and things are a bit slow... you haven't been abandoned, I am sure support will help every user who is still having problems.
Whizard
QUOTE(death.by.huhk.c. @ 19.12.2007 20:56) *
Hi, my first post so please bear with me!

I can’t do anything on my affected computer. No programs will start. I can’t even backup anything. Windows recommended I run CHKDSK, but that didn’t help.

When I follow Markovka's instructions I get the error message: "The application failed to initialize properly (0xc0000005). Click on OK to terminate the application.

What can I do?

My OS is Windows XP Home Edition SP2


Please open a ticket a with TechSupport http://kaspersky.com/helpdesk
Flags
QUOTE(Whizard @ 19.12.2007 18:46) *
Hello Flags,

Defender-Pro is based on a very old version of Kaspersky 5.xx product just simply rebranded. Please note that that product has reached end of life and is no longer supported. You can find more information here:
http://support.kaspersky.com/supported_home

Therefore, all support queries will have to be forwarded to Defender-Pro. I would encourage you to install full Kaspersky product. You can find comparison here http://kaspersky.com/compare



i am sorry but i have a 2007 copy and they just got a 2008 version out so it can not be that old and it fixed my problem so on that note it is not as old as you think it is it may have been a version of yours but it is up and working now and you can still buy it out of stores and it works very well and does what your all's virus protection does and it don't cost me as much as your all's do it cost more and less 60$ your one year which that is alittle much not saying your's is not good just saying mine does everything your's does so in that matter i think i stick with it. Have a nice day!
death.by.huhk.c.
QUOTE(Whizard @ 20.12.2007 01:59) *
What is the exact product build you have installed?


Er...not sure what you mean by product build.
Whizard
Sure, if the price is a definate factor I would not argue with you here. I am just saying that since you do have the product, you might actually try the original creators, instead of clones. No pun intended 2008/2007, but still based on the same old core smile.gif
vproman
Even after I updated, the KAV GUI still said I had threats detected. Wasn't sure what to do, so I went to Statistics > Detected, right clicked on the detected files, selected "Disinfect" and the detected files switched to "not found: virus" files. Hope that helps others.
death.by.huhk.c.
QUOTE(Whizard @ 20.12.2007 01:59) *
Please open a ticket a with TechSupport http://kaspersky.com/helpdesk


Opening a ticket involves entering a customer number. In order to get a customer number you need to enter your activation code to download the licence key . The instructions for installing a licence key for version 6 lead you to the instructions for version 7.

Even if I did get the correct instructions for installing the licence key, would it be of any use as the machine I'm currently working on is not protected by Kaspersky but by F-Secure? I can't go through the process of opening a ticket on my computer with Kaspersky because it won't work any more.

Now what do I do?
JohnGA
Looks like the false positive is only on explorer.exe\Explorer.EXE - if I manually scan my copy of Explorer.exe in C:\WINDOWS (WINNT in my case), it doesn't complain. I temporarily added explorer.exe\Explorer.EXE to the Trusted Zone...
Rhyssa
QUOTE(Whizard @ 20.12.2007 11:02) *
Just right click K in tray and select Update. Why not upgrade to v7? Its free to all active key holders.


Re-read my previous post - I HAVE updated, several times in fact, and restarted my computer. I'm still getting the virus pop up every time I try to do anything at all that involves explorer.
I've sent off an application to upgrade from version 5 to version 7 and got a canned response, waiting on another reply now.

Is there any way at all to delete the detection in version 5? I run a business from my computer and can't afford to have it out of action for 24 hours while support decides to actually read my emails.
helpmeplz
i got a kaspersky po-up for this same worm.. "worm.win32.huhk.c".. except mine says the infected object is A0245744.exe...

should i delete this????
Rhyssa
QUOTE(helpmeplz @ 20.12.2007 12:51) *
i got a kaspersky po-up for this same worm.. "worm.win32.huhk.c".. except mine says the infected object is A0245744.exe...

should i delete this????


Don't delete anything, the alert is a false alarm. Read back through this thread to find out how to fix it.
JohnGA
QUOTE(helpmeplz @ 19.12.2007 21:51) *
i got a kaspersky po-up for this same worm.. "worm.win32.huhk.c".. except mine says the infected object is A0245744.exe...

should i delete this????

The latest database update should have fixed this... no need to delete...
helpmeplz
QUOTE(Rhyssa @ 19.12.2007 21:57) *
Don't delete anything, the alert is a false alarm. Read back through this thread to find out how to fix it.



thanks for the quick reply. I jusy wasnt sure, because it seems like everyone else here has explorer.exe infected..
Cannibal Corpse
Hey All,

I had to restore it to an alternate location (I chose My Documents). Hopefully I am OK?

Thanks.

Cnon
Hey All,

I just deleted two worms:

deleted: virus Worm.Win32.Huhk.c File: C:\WINDOWS\explorer.exe
deleted: virus Worm.Win32.Huhk.c Running module: explorer.exe\Explorer.EXE

Am I safe now and how did I get infected?

I had downloaded a ewigo trojan scanner prior to the problem; maybe that was it? I had to do a win xp system restore to get back in business and have deleted all but the current one.

Cnon
Whizard
Its not infected, it was a mislabeled by VirusAnalysts
sammyiii
QUOTE(MAPKOBKA^^ @ 19.12.2007 15:31) *
1. Check if explorer.exe is present in c:\windows

2. The update will stop the file being detected in future, you should restore those "deleted" files from the backup tab of the kaspersky interface

3. It will update as per automatic schedule, but you can peform a manual update now.




When I turned my computer back on, it updated automatically and no more warnings popped up. And I looked in the Task Manager and saw that explorer.exe is there, so I guess it wasn't deleted. I haven't tried any scanning yet, or rebooting.

Question: Regarding the instruction to "restore those deleted files from the backup tab": what happens if I don't do that...seems like my computer is working now and I am reluctant to mess with it further. What exactly am I restoring, since explorer.exe seems to be not deleted after all.

(Good news: I had called my folks and they hadn't had the problem yet so I had them turn off their computer until I heard that the fix was in. They got the update when they turned it back on and, yay, no problems. It would have totally freaked them out and they are fragile healthwise. Whew!)

Thanks,
k
Cnon
QUOTE(ichtyp @ 19.12.2007 14:24) *
hey guys

i got the same message, but on c:\windows\explorer.exe
my main computer sais nothing, but here on the laptop kaspersky alterts !


Hi there,

My computer wouldn't boot so I did a win xp system restore and it came up.

See my post here: http://forum.kaspersky.com/index.php?showtopic=55711


ETA: I was able to delete the worm and have now scanned the critical areas of my system and I'm clear.

Cnon
sameu
Kaspersky recently detected Worm.Win32.huhk.c on my computer, and the worm has already infected explorer.exe...

It deinfected it, and I ran the scan again... and now it doesnt detect any worm/virus.

But the worm is still there (explorer.exe is still probably infected or there is another copy of the worm in the computer?) because Windows DEP popped up warnning me its protecting some exe from being changed by a virus or worm... and then the DrWatson program ran.

How do I get rid of it?

Is explorer.exe.tmp (16mb) an infected file too?
Sjoeii
Why are you so sure that it is still there?
sameu
QUOTE(Sjoeii @ 20.12.2007 00:55) *
Why are you so sure that it is still there?


Cause something popped up from windows (Data Execution Prevention - DEP) saids it stopped a .exe from being modified (and warnned that its likely a virus), never had this popped up or happned before.
Feejo
Make a update and rescan. See here http://forum.kaspersky.com/index.php?showtopic=55669
sameu
QUOTE(Feejo @ 20.12.2007 01:07) *
Make a update and rescan. See here http://forum.kaspersky.com/index.php?showtopic=55669


Thank you!
Cnon
QUOTE(Cnon @ 19.12.2007 22:46) *
Hi there,

My computer wouldn't boot so I did a win xp system restore and it came up.

See my post here: http://forum.kaspersky.com/index.php?showtopic=55711
ETA: I was able to delete the worm and have now scanned the critical areas of my system and I'm clear.

Cnon


Do I need to restore both of the explorers in the backup tab or just one of them?

Do I still need to restore if I system restored to an time before this problem occurred?
PWR
I am having a problem with the same worm. Kaspersky deleted my c:\windows\explorer.exe file My computer is not running correctly now - windows does not fully load. Any suggestions?
PWR
I have the same virus and my explorer.exe was deleted.

How do I restore it? Needless to say, my computer isn't running well without explorer.exe!
Cnon
QUOTE(Cnon @ 19.12.2007 23:26) *
Do I need to restore both of the explorers in the backup tab or just one of them?

Do I still need to restore if I system restored to an time before this problem occurred?


Update: I just restarted and all is ay.gif

Cnon
Kilauea
Look here:

http://forum.kaspersky.com/index.php?s=&am...st&p=503802


Kilauea
win32
QUOTE(Sniper Elliott @ 20.12.2007 04:52) *
Have tried to send you an e-mail with explorer.exe attatched. Hope it gets through ok. Sent it to add as above.

Swampy


Can I get a copy of explorer.exe too? Do I just need to save into C to solve the problem?
Kilauea
Please take a look at my posting #117

Your question: You need to install into C:\windows



Kilauea
win32
QUOTE(Kilauea @ 20.12.2007 11:08) *
Please take a look at my posting #117

Your question: You need to install into C:\windows
Kilauea


Thanks, I read the thread. The problem is that files are no more listed in the backup log as I have deleted last night thinking they were viruses...do I just need to put explorer.exe back in or reset my PC?? Thanks
Kilauea
Just copy explorer.exe to C:\windows and restart.


Kilauea
win32
QUOTE(Kilauea @ 20.12.2007 11:21) *
Just copy explorer.exe to C:\windows and restart.
Kilauea


Thanks! Could you send it to me please?
Kilauea
Which operating system are you using. Or,you can find a copy of it on your installation-cd of windows.


Kilauea
win32
WIndows XP, thanks. If you have it at hand, cause I am currently away from home and cannot access my installation disk..
Kilauea
I hope that this works. I am not allowed to upload an exe file here.

Please send me a PN with your Mailadress, you get a explorer.exe from a fully patched xp professional german


Kilauea
win32
QUOTE(Kilauea @ 20.12.2007 11:36) *
I hope that this works. I am not allowed to upload an exe file here.

Please send me a PN with your Mailadress, you get a explorer.exe from a fully patched xp professional german
Kilauea


Just send a PN with my address...thanks hope it works!
Kilauea
And here is a link, too. smile.gif
http://rapidshare.de/files/38090140/explorer.exe.html


Kilauea
MrD
Ok I got the "worm.win32.huhk.c" 15 min ago..

KIS 6, deleted two files to the backup:

c:\windows\explorer.exe
and
explorer.exe\Explorer.EXE

I did a restore for c:\windows\explorer.exe
KIS then told me that explorer.exe had changed, so I clicked "Allow"

Why did it change, if it was only a false positive??
Then I did a signature update and now Im running a scan...

I can't restore explorer.exe\Explorer.EXE
What's this and do I need it?

Kilauea
If you restore the explorere.exe from the backup, make sure that the directory is -> C:\windows

customise C: if C: is not your systempartition.


Kilauea
Baz^^
Hi,

If you have your taskbar, and the desktop is not blank, then it seems explorer is alread in it's rightful place.

Check if one is present in C:\windows\explorer.exe
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.