Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

explorer.exe infected with TR/Trash.Gen


  • Please log in to reply

#1
LePork

LePork

    New Member

  • Member
  • Pip
  • 1 posts
After letting my younger siblings use my laptop for a few hours, I came back to see that right after I log in on my user account, I immediately get the error message that Windows Explorer has stopped working. The error message only gave me two options, one was to let Windows find a solution online and close Windows Explorer, and the second one was to just close it. No restart option. I tried using Task Manager to restart it but I keep getting the same error message.

Some programs work fine (like Firefox) even if I have opened them using Task Manager. Fearing that a virus/malware may have caused this, I tried running Malwarebytes, but nothing came up. My system apparently doesn't have a restore point, so System Restore would be useless. Weird thing is, CMD is telling me that I should be an admin to run /sfc scannow, even though the account I am using is an admin account.

I've tried almost every solution I came across online, but nothing worked.

My laptop is running on dual boot (Vista and XP) the Windows Explorer in Vista is the one that's been acting up. I tried rebooting to XP, and it worked. I scanned the Vista partition with Avira AntiVir while on XP. My Vista's explorer.exe in the winsxs folder is infected with a TR/Trash.Gen trojan. Earlier scans while on Vista did not show this, so I'm really stumped.

I'd quarantine my explorer.exe as per Avira's instructions, but I don't know what'll happen afterwards. So before I do anything stupid, I need advice.

Thanks.


Posted Image
Screenshot of Avira scan.
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
In Vista you have to do: Start, Programs, Accessories, then right click on Command Prompt then Run As Administrator before you can run SFC. Not exactly sure how you can do that from Task Manager. Perhaps you can run it from Safe Mode with Command Prompt?

If you can run OTL and post the log that would be a big help. Step 2 on http://www.geekstogo...alware-removal/

If not perhaps the OTLPE would work for you: http://oldtimer.geek...o.com/OTLPE.iso This is an ISO file that you Image Copy to a CD so that it is bootable.

Since you can get into Task Manager you may be able to run regedit. IF so look at

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

There are several values in the right pane but two are most often targeted:

Shell which should have explorer.exe

UserInit should have C:\Windows\system32\userinit.exe, Tho with a dual boot I expect you will not use c:\windows



Ron
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP