WiredWX Hobby Weather ToolsLog in

 


Trojan: SHeur2.gnw

3 posters

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
I have a XP disc, but if I remember correctly its not the one I installed from..

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
So it's recovery disc?
It might work.

Put it in and let me know what letter it uses as a drive.

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
I have two win xp disks here, but I think this OS installed is from a disk at my former employer..

Last edited by ronsonol on 19th January 2009, 11:50 pm; edited 1 time in total

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
Okay, if it's a recovery disk, it might work.
Put it in and let me know what letter it uses as a drive.

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
That would be H

Btw: my AVG just told me avenger is a threat. Im guessing that is bogus?

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
Thanks.
Open the CD as a folder, is there an i386 folder on the CD?

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
Aye

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
That is "yes" in auld english, or so I've been taught.. Smile...

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
Hello.
Haha, yeah. I'm from good ole England, the land of sheep and dirt.
Just seen your edit, yes it's bogus. AVG have detected a second tool now, I got it too.
Trojan.Downloader.Banload

Alittle while ago, it detected OTMoveIt as generic backdoor. AVG is going down the drain.

Now lets fix this problem.

Press Start > Run
Type in cmd and press enter.
Once the command opens, type this in:

expand H:\i386\userinit.ex_ c:\windows\system32\userinit.exe

Press enter.

Now delete the avenger.exe from your Desktop, along with DDS.
Delete this folder:
C:\avenger

What problems remain?

Last edited by Belahzur on 20th January 2009, 12:19 am; edited 1 time in total

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
Done.
cmd says: "no destination secified for H:\i386\userinit.ex_ c:\windows\system32\userinit.exe

is that good or bad?

and the infection is still there according to avg

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
Did you put a space between _ and C?

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
nope. ill try again. (btw that space is alomst impossible to see for the naked eye)

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
copied

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
Okay, everything should be fine now. The malware is gone and userinit is replaced.

Any problems remaining?

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
now; this file is used to log on to windows am i right? we dont really know if this was a success until i reboott and see if i can still log onto the system?

1,5 min 'til scan is complete

descriptionSolvedRe: Trojan: SHeur2.gnw

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum