BleepingComputer.com: Effects after Antimalware Doctor

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

Effects after Antimalware Doctor

#16 User is offline   ookami 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 14
  • Joined: 19-April 11
  • Gender:Female
  • Location:United States, New York

Posted 26 April 2011 - 12:37 AM

I'm running the scan and an alert came up. A virus was detected 'Virus.Win32.Exiro.w' and it's asking me to Disinfect, Delete or Skip. What do I do?

#17 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 26 April 2011 - 02:23 AM

use Disinfect on any of them
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#18 User is offline   ookami 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 14
  • Joined: 19-April 11
  • Gender:Female
  • Location:United States, New York

Posted 26 April 2011 - 05:47 PM

I ran it and it was doing fine until 9% and my computer shut down and restarted. That report is incomplete and too long to post here, but I'm waiting on the one I'm running now. They don't have the 'disinfect' option, it's either Delete or Skip.

#19 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 26 April 2011 - 06:19 PM

ok try it again then
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#20 User is offline   ookami 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 14
  • Joined: 19-April 11
  • Gender:Female
  • Location:United States, New York

Posted 26 April 2011 - 08:12 PM

The scan is now complete. Here is the report you wanted:

Autoscan: completed 2 minutes ago (events: 256, objects: 9594, time: 03:46:02)
4/26/2011 5:19:56 PM Task started
4/26/2011 5:27:15 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\DRWTSN32.EXE
4/26/2011 5:27:52 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\DRWTSN32.EXE Skipped by user
4/26/2011 5:28:18 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\EXPLORER.EXE
4/26/2011 5:28:54 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\EXPLORER.EXE Skipped by user
4/26/2011 5:29:56 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\USERINIT.EXE
4/26/2011 5:30:01 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\USERINIT.EXE Skipped by user
4/26/2011 5:31:15 PM Detected: Trojan.Win32.Sasfis.bhrv C:\WINDOWS\system32\ITLNFW32.DLL
4/26/2011 5:31:19 PM Untreated: Trojan.Win32.Sasfis.bhrv C:\WINDOWS\system32\ITLNFW32.DLL Skipped by user
4/26/2011 5:32:38 PM Detected: Virus.Win32.Expiro.w C:\Program Files\QuickTime\QTTask.exe
4/26/2011 5:32:46 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\QuickTime\QTTask.exe Skipped by user
4/26/2011 5:33:32 PM Detected: Virus.Win32.Expiro.w C:\Documents and Settings\EREN\Application Data\Microsoft\Windows Media\12.0\WMPACM.EXE
4/26/2011 5:33:47 PM Untreated: Virus.Win32.Expiro.w C:\Documents and Settings\EREN\Application Data\Microsoft\Windows Media\12.0\WMPACM.EXE Skipped by user
4/26/2011 5:35:36 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\DUMPREP.EXE
4/26/2011 5:35:56 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\DUMPREP.EXE Skipped by user
4/26/2011 5:37:34 PM Detected: Trojan.Win32.Agent.hule C:\WINDOWS\system32\ITLPFW32.DLL
4/26/2011 5:37:46 PM Untreated: Trojan.Win32.Agent.hule C:\WINDOWS\system32\ITLPFW32.DLL Skipped by user
4/26/2011 5:39:54 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
4/26/2011 5:40:15 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe Skipped by user
4/26/2011 5:41:06 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\ALG.EXE
4/26/2011 5:41:16 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\ALG.EXE Skipped by user
4/26/2011 5:45:42 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\CISVC.EXE
4/26/2011 5:45:53 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\CISVC.EXE Skipped by user
4/26/2011 5:46:10 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\CLIPSRV.EXE
4/26/2011 5:47:06 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\CLIPSRV.EXE Skipped by user
4/26/2011 5:47:36 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\DLLHOST.EXE
4/26/2011 5:47:52 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\DLLHOST.EXE Skipped by user
4/26/2011 5:48:01 PM Detected: Virus.Win32.Expiro.w C:\Program Files\NavNT\DEFWATCH.EXE
4/26/2011 5:48:16 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\NavNT\DEFWATCH.EXE Skipped by user
4/26/2011 5:48:45 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\DMADMIN.EXE
4/26/2011 5:48:50 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\DMADMIN.EXE Skipped by user
4/26/2011 5:50:12 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\IMAPI.EXE
4/26/2011 5:50:17 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\IMAPI.EXE Skipped by user
4/26/2011 5:51:27 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\MNMSRVC.EXE
4/26/2011 5:51:32 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\MNMSRVC.EXE Skipped by user
4/26/2011 5:52:35 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSDTC.EXE
4/26/2011 5:52:41 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSDTC.EXE Skipped by user
4/26/2011 5:52:58 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSIEXEC.EXE
4/26/2011 5:54:05 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSIEXEC.EXE Skipped by user
4/26/2011 5:55:09 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\NETDDE.EXE
4/26/2011 5:55:14 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\NETDDE.EXE Skipped by user
4/26/2011 5:55:31 PM Detected: Virus.Win32.Expiro.w C:\Program Files\NavNT\RTVSCAN.EXE
4/26/2011 5:55:47 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\NavNT\RTVSCAN.EXE Skipped by user
4/26/2011 5:56:50 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\HPZipm12.exe
4/26/2011 5:56:57 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\HPZipm12.exe Skipped by user
4/26/2011 5:58:01 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\SESSMGR.EXE
4/26/2011 5:58:15 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\SESSMGR.EXE Skipped by user
4/26/2011 5:58:19 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\LOCATOR.EXE
4/26/2011 5:58:43 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\LOCATOR.EXE Skipped by user
4/26/2011 5:58:53 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\RSVP.EXE
4/26/2011 5:59:37 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\RSVP.EXE Skipped by user
4/26/2011 6:00:10 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\SCARDSVR.EXE
4/26/2011 6:00:29 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\SCARDSVR.EXE Skipped by user
4/26/2011 6:03:04 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\SPOOLSV.EXE
4/26/2011 6:03:18 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\SPOOLSV.EXE Skipped by user
4/26/2011 6:03:36 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Spyware Terminator\SP_RSSER.EXE
4/26/2011 6:04:06 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Spyware Terminator\SP_RSSER.EXE Skipped by user
4/26/2011 6:05:11 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\SMLOGSVC.EXE
4/26/2011 6:05:26 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\SMLOGSVC.EXE Skipped by user
4/26/2011 6:06:32 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\UPS.EXE
4/26/2011 6:06:38 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\UPS.EXE Skipped by user
4/26/2011 6:07:44 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Viewpoint\Common\ViewpointService.exe
4/26/2011 6:08:13 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Viewpoint\Common\ViewpointService.exe Skipped by user
4/26/2011 6:08:19 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\VSSVC.EXE
4/26/2011 6:08:48 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\VSSVC.EXE Skipped by user
4/26/2011 6:09:51 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\WBEM\WMIAPSRV.EXE
4/26/2011 6:09:54 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\WBEM\WMIAPSRV.EXE Skipped by user
4/26/2011 6:09:59 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Windows Media Player\WMPNETWK.EXE
4/26/2011 6:10:04 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Windows Media Player\WMPNETWK.EXE Skipped by user
4/26/2011 6:11:14 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\IEUDINIT.EXE
4/26/2011 6:11:30 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\IEUDINIT.EXE Skipped by user
4/26/2011 6:11:49 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\INF\UNREGMP2.EXE
4/26/2011 6:12:06 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\INF\UNREGMP2.EXE Skipped by user
4/26/2011 6:12:21 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\SHMGRATE.EXE
4/26/2011 6:12:45 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\SHMGRATE.EXE Skipped by user
4/26/2011 6:12:59 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\RUNDLL32.EXE
4/26/2011 6:13:13 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\RUNDLL32.EXE Skipped by user
4/26/2011 6:13:54 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\REGSVR32.EXE
4/26/2011 6:14:12 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\REGSVR32.EXE Skipped by user
4/26/2011 6:14:44 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Outlook Express\SETUP50.EXE
4/26/2011 6:15:41 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Outlook Express\SETUP50.EXE Skipped by user
4/26/2011 6:16:47 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\IE4UINIT.EXE
4/26/2011 6:17:01 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\IE4UINIT.EXE Skipped by user
4/26/2011 6:18:09 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\PROGMAN.EXE
4/26/2011 6:18:17 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\PROGMAN.EXE Skipped by user
4/26/2011 6:20:23 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\HELP.EXE
4/26/2011 6:20:34 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\HELP.EXE Skipped by user
4/26/2011 6:21:36 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Microsoft Office\Office\BINDER.EXE
4/26/2011 6:21:41 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Microsoft Office\Office\BINDER.EXE Skipped by user
4/26/2011 6:22:46 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\Easy CD Creator\CDCopier.exe
4/26/2011 6:22:49 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\Easy CD Creator\CDCopier.exe Skipped by user
4/26/2011 6:24:46 PM Detected: Virus.Win32.Expiro.w C:\Program Files\NetMeeting\CONF.EXE
4/26/2011 6:24:49 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\NetMeeting\CONF.EXE Skipped by user
4/26/2011 6:24:51 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
4/26/2011 6:25:10 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe Skipped by user
4/26/2011 6:25:17 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\Easy CD Creator\Creatr50.exe
4/26/2011 6:25:29 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\Easy CD Creator\Creatr50.exe Skipped by user
4/26/2011 6:25:35 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Windows NT\DIALER.EXE
4/26/2011 6:26:01 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Windows NT\DIALER.EXE Skipped by user
4/26/2011 6:26:07 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
4/26/2011 6:28:17 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe Skipped by user
4/26/2011 6:28:19 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\TWAIN_32\ESCNDV\ESCFG.EXE
4/26/2011 6:28:29 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\TWAIN_32\ESCNDV\ESCFG.EXE Skipped by user
4/26/2011 6:28:33 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\TWAIN_32\ESCNDV\ESCNDV.EXE
4/26/2011 6:28:51 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\TWAIN_32\ESCNDV\ESCNDV.EXE Skipped by user
4/26/2011 6:28:57 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\TWAIN_32\ESCNDV\ESTCFG.EXE
4/26/2011 6:29:26 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\TWAIN_32\ESCNDV\ESTCFG.EXE Skipped by user
4/26/2011 6:30:16 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HelpCtr.exe
4/26/2011 6:30:22 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\HelpCtr.exe Skipped by user
4/26/2011 6:31:23 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQISC01.EXE
4/26/2011 6:31:34 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQISC01.EXE Skipped by user
4/26/2011 6:32:04 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQISE01.EXE
4/26/2011 6:32:15 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQISE01.EXE Skipped by user
4/26/2011 6:32:28 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQPANOS.EXE
4/26/2011 6:32:38 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQPANOS.EXE Skipped by user
4/26/2011 6:33:40 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQPSXP.EXE
4/26/2011 6:33:50 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQPSXP.EXE Skipped by user
4/26/2011 6:34:04 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQQPAWP.EXE
4/26/2011 6:34:14 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQQPAWP.EXE Skipped by user
4/26/2011 6:35:41 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Windows NT\HYPERTRM.EXE
4/26/2011 6:35:48 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Windows NT\HYPERTRM.EXE Skipped by user
4/26/2011 6:36:02 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE
4/26/2011 6:36:10 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE Skipped by user
4/26/2011 6:36:28 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE
4/26/2011 6:36:41 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE Skipped by user
4/26/2011 6:39:11 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Adobe\Adobe Photoshop CS2\ImageReady.exe
4/26/2011 6:40:54 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Adobe\Adobe Photoshop CS2\ImageReady.exe Skipped by user
4/26/2011 6:42:11 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE
4/26/2011 6:42:33 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE Skipped by user
4/26/2011 6:42:50 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE
4/26/2011 6:42:59 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE Skipped by user
4/26/2011 6:53:58 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Symantec\LiveUpdate\LUALL.EXE
4/26/2011 6:54:42 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Symantec\LiveUpdate\LUALL.EXE Skipped by user
4/26/2011 7:07:03 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\USMT\MIGWIZ.EXE
4/26/2011 7:07:27 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\USMT\MIGWIZ.EXE Skipped by user
4/26/2011 7:30:52 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Movie Maker\MOVIEMK.EXE
4/26/2011 7:31:46 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Movie Maker\MOVIEMK.EXE Skipped by user
4/26/2011 7:40:53 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE
4/26/2011 7:41:19 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE Skipped by user
4/26/2011 7:41:33 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Outlook Express\MSIMN.EXE
4/26/2011 7:41:41 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Outlook Express\MSIMN.EXE Skipped by user
4/26/2011 7:42:04 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSINFO32.EXE
4/26/2011 7:42:15 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSINFO32.EXE Skipped by user
4/26/2011 8:07:13 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Messenger\MSMSGS.EXE
4/26/2011 8:27:41 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Messenger\MSMSGS.EXE Skipped by user
4/26/2011 8:28:55 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSPAINT.EXE
4/26/2011 8:28:56 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSPAINT.EXE Skipped by user
4/26/2011 8:29:14 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Adobe\Adobe Photoshop CS2\Photoshop.exe
4/26/2011 8:29:15 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Adobe\Adobe Photoshop CS2\Photoshop.exe Skipped by user
4/26/2011 8:29:18 PM Detected: Virus.Win32.Expiro.w C:\Program Files\QuickTime\PictureViewer.exe
4/26/2011 8:29:18 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\QuickTime\PictureViewer.exe Skipped by user
4/26/2011 8:29:20 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Windows NT\Pinball\PINBALL.EXE
4/26/2011 8:29:21 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Windows NT\Pinball\PINBALL.EXE Skipped by user
4/26/2011 8:29:31 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Scandisc.exe
4/26/2011 8:29:33 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Scandisc.exe Skipped by user
4/26/2011 8:29:35 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Microsoft Office\Office\1033\SCHDPL32.EXE
4/26/2011 8:29:37 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Microsoft Office\Office\1033\SCHDPL32.EXE Skipped by user
4/26/2011 8:29:39 PM Detected: Virus.Win32.Expiro.w C:\Program Files\NavNT\VPC32.EXE
4/26/2011 8:29:39 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\NavNT\VPC32.EXE Skipped by user
4/26/2011 8:29:42 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Outlook Express\WABMIG.EXE
4/26/2011 8:29:43 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Outlook Express\WABMIG.EXE Skipped by user
4/26/2011 8:29:52 PM Detected: Virus.Win32.Expiro.w C:\Program Files\WinRAR\WinRAR.exe
4/26/2011 8:29:52 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\WinRAR\WinRAR.exe Skipped by user
4/26/2011 8:29:54 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Windows Media Player\WMPLAYER.EXE
4/26/2011 8:29:54 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Windows Media Player\WMPLAYER.EXE Skipped by user
4/26/2011 8:29:56 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
4/26/2011 8:29:57 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Windows NT\Accessories\WORDPAD.EXE Skipped by user
4/26/2011 8:30:01 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\NTSD.EXE
4/26/2011 8:30:02 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\NTSD.EXE Skipped by user
4/26/2011 8:30:30 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\RDPCLIP.EXE
4/26/2011 8:30:31 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\RDPCLIP.EXE Skipped by user
4/26/2011 8:30:42 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\LOGONUI.EXE
4/26/2011 8:30:45 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\LOGONUI.EXE Skipped by user
4/26/2011 8:30:49 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\NTVDM.EXE
4/26/2011 8:30:51 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\NTVDM.EXE Skipped by user
4/26/2011 8:30:57 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\CMD.EXE
4/26/2011 8:31:00 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\CMD.EXE Skipped by user
4/26/2011 8:31:08 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\network diagnostic\xpnetdiag.exe
4/26/2011 8:31:08 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\network diagnostic\xpnetdiag.exe Skipped by user
4/26/2011 8:31:12 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPOSFX08.EXE
4/26/2011 8:31:12 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPOSFX08.EXE Skipped by user
4/26/2011 8:31:16 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQSCNVW.EXE
4/26/2011 8:31:16 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQSCNVW.EXE Skipped by user
4/26/2011 8:31:19 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPZWIZ01.EXE
4/26/2011 8:31:20 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPZWIZ01.EXE Skipped by user
4/26/2011 8:31:22 PM Detected: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQNRS08.EXE
4/26/2011 8:31:22 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\HP\Digital Imaging\BIN\HPQNRS08.EXE Skipped by user
4/26/2011 8:31:33 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSHTA.EXE
4/26/2011 8:31:34 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\MSHTA.EXE Skipped by user
4/26/2011 8:31:37 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\NOTEPAD.EXE
4/26/2011 8:31:38 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\NOTEPAD.EXE Skipped by user
4/26/2011 8:31:41 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\REGEDIT.EXE
4/26/2011 8:31:43 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\REGEDIT.EXE Skipped by user
4/26/2011 8:32:05 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Microsoft Office\Office\OSA9.EXE
4/26/2011 8:32:05 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Microsoft Office\Office\OSA9.EXE Skipped by user
4/26/2011 8:32:08 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
4/26/2011 8:32:08 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe Skipped by user
4/26/2011 8:32:48 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\OSK.EXE
4/26/2011 8:32:49 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\OSK.EXE Skipped by user
4/26/2011 8:33:31 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Fanfiction Downloader\ff_downloader.exe
4/26/2011 8:33:32 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Fanfiction Downloader\ff_downloader.exe Skipped by user
4/26/2011 8:33:38 PM Detected: Virus.Win32.Expiro.w C:\Documents and Settings\EREN\Desktop\RKUnhookerLE.EXE
4/26/2011 8:33:38 PM Untreated: Virus.Win32.Expiro.w C:\Documents and Settings\EREN\Desktop\RKUnhookerLE.EXE Skipped by user
4/26/2011 8:37:53 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Adobe\Adobe Photoshop CS2\Required\Droplet Template.exe
4/26/2011 8:37:53 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Adobe\Adobe Photoshop CS2\Required\Droplet Template.exe Skipped by user
4/26/2011 8:39:38 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\DWWIN.EXE
4/26/2011 8:39:40 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\DWWIN.EXE Skipped by user
4/26/2011 8:39:52 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\GRPCONV.EXE
4/26/2011 8:39:54 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\GRPCONV.EXE Skipped by user
4/26/2011 8:40:27 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\NET.EXE
4/26/2011 8:40:27 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\NET.EXE Skipped by user
4/26/2011 8:40:28 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\NET1.EXE
4/26/2011 8:40:28 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\NET1.EXE Skipped by user
4/26/2011 8:40:51 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\RUNONCE.EXE
4/26/2011 8:40:53 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\RUNONCE.EXE Skipped by user
4/26/2011 8:40:57 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\SAVEDUMP.EXE
4/26/2011 8:40:59 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\SAVEDUMP.EXE Skipped by user
4/26/2011 8:41:16 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\TASKMGR.EXE
4/26/2011 8:41:16 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\TASKMGR.EXE Skipped by user
4/26/2011 8:41:31 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\VERCLSID.EXE
4/26/2011 8:41:33 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\VERCLSID.EXE Skipped by user
4/26/2011 8:41:41 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\WBEM\WMIPRVSE.EXE
4/26/2011 8:41:41 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\WBEM\WMIPRVSE.EXE Skipped by user
4/26/2011 8:42:18 PM Detected: Trojan.Win32.Sasfis.bhrv C:\WINDOWS\system32\ITLNFW32.DLL
4/26/2011 9:01:32 PM Untreated: Trojan.Win32.Sasfis.bhrv C:\WINDOWS\system32\ITLNFW32.DLL Skipped by user
4/26/2011 9:02:53 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\SPOOLSV.EXE
4/26/2011 9:02:53 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\SPOOLSV.EXE Skipped by user
4/26/2011 9:02:59 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\RUNDLL32.EXE
4/26/2011 9:02:59 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\RUNDLL32.EXE Skipped by user
4/26/2011 9:03:08 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
4/26/2011 9:03:08 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe Skipped by user
4/26/2011 9:03:16 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\EXPLORER.EXE
4/26/2011 9:03:16 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\EXPLORER.EXE Skipped by user
4/26/2011 9:03:31 PM Detected: Virus.Win32.Expiro.w C:\Program Files\NavNT\DEFWATCH.EXE
4/26/2011 9:03:31 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\NavNT\DEFWATCH.EXE Skipped by user
4/26/2011 9:03:49 PM Detected: Trojan.Win32.Agent.hule C:\WINDOWS\system32\itlpfw32.dll
4/26/2011 9:03:49 PM Untreated: Trojan.Win32.Agent.hule C:\WINDOWS\system32\itlpfw32.dll Skipped by user
4/26/2011 9:03:55 PM Detected: Virus.Win32.Expiro.w C:\Program Files\NavNT\rtvscan.exe
4/26/2011 9:03:55 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\NavNT\rtvscan.exe Skipped by user
4/26/2011 9:04:16 PM Detected: Virus.Win32.Expiro.w C:\Documents and Settings\eren\Application Data\Microsoft\Windows Media\12.0\wmpacm.exe
4/26/2011 9:04:16 PM Untreated: Virus.Win32.Expiro.w C:\Documents and Settings\eren\Application Data\Microsoft\Windows Media\12.0\wmpacm.exe Skipped by user
4/26/2011 9:04:19 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Spyware Terminator\sp_rsser.exe
4/26/2011 9:04:19 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Spyware Terminator\sp_rsser.exe Skipped by user
4/26/2011 9:04:30 PM Detected: Virus.Win32.Expiro.w C:\Program Files\Viewpoint\Common\ViewpointService.exe
4/26/2011 9:04:30 PM Untreated: Virus.Win32.Expiro.w C:\Program Files\Viewpoint\Common\ViewpointService.exe Skipped by user
4/26/2011 9:04:32 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\wbem\wmiapsrv.exe
4/26/2011 9:04:32 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\wbem\wmiapsrv.exe Skipped by user
4/26/2011 9:04:35 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\dmadmin.exe
4/26/2011 9:04:35 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\dmadmin.exe Skipped by user
4/26/2011 9:04:48 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\alg.exe
4/26/2011 9:04:48 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\alg.exe Skipped by user
4/26/2011 9:04:49 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\net.exe
4/26/2011 9:04:49 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\net.exe Skipped by user
4/26/2011 9:04:51 PM Detected: Virus.Win32.Expiro.w C:\WINDOWS\system32\net1.exe
4/26/2011 9:04:51 PM Untreated: Virus.Win32.Expiro.w C:\WINDOWS\system32\net1.exe Skipped by user
4/26/2011 9:06:08 PM Task completed

#21 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 27 April 2011 - 02:55 PM

hello

Sorry for the delay but have been doing research on your virus as it is a very bad one - W32/Expiro and W32/Expiro

It will infect all exe files on the computer and some places indicate it can steal credit card info - so you should inform your bank and credit cards in case something happens


Now you need to back up anything that you cannot replace like family photos and things like that so you don't lose them, if this was my computer I would format it and reinstall windows as that is the best way to be sure to remove all of this virus.

I have seen one tool that claims it can clean this but I have never used it before so I don't know how it works - http://free.avg.com/us-en/win32-expiro

so tonight you should backup what you don't want to lose because even if you try to clean it it could damage the operating system to the point you can't boot the computer and have to format anyway.

after you have backed everything up let me know what you want to do


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#22 User is offline   ookami 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 14
  • Joined: 19-April 11
  • Gender:Female
  • Location:United States, New York

Posted 29 April 2011 - 06:38 PM

I'm trying that tool in the link, and running it now. I backed up all my files and if all fails, could you tell me how to format my computer? Or where I can go to format in case nothing else can be done?

#23 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 30 April 2011 - 02:09 PM

What computer do you have?


Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#24 User is offline   ookami 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 14
  • Joined: 19-April 11
  • Gender:Female
  • Location:United States, New York

Posted 30 April 2011 - 03:38 PM

I have a Windows XP Home Edition (Compaq)

By the way, I did try out that tool in the link and it has been scanning for two days now. It keeps telling me 'The virus is active in memory and may re-infect files that have been already cleaned. It is necessary to run the remover during next system boot. Do you wish to schedule remover run for the next restart?'

The Luna theme that comes with this computer is turned off and goes straight to Classic theme. I have to turn it on myself but it goes back to the other theme. The computer is very slow today but it was doing fine the other day. I'm not even sure if the tool is even helping this computer at all.

This post has been edited by ookami: 30 April 2011 - 04:00 PM


#25 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 30 April 2011 - 04:02 PM

Hello

Here is how to format the computer for compaq - has to be destructive

http://oem.windowsreinstall.com/Compaq/Compaq_XPfull.htm



How did things go with the tool?



Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#26 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,462
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 03 May 2011 - 07:19 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users