Tuesday, December 02, 2008   
  Search   
 
Register  Login  
Forums  
     Minimize  

Welcome to MeraWindows forums.

Thank you for being at the Microsoft Windows Community Site. You may have to register before posting in forums. It's absolutely free. After registering, you can get all the benefits available to our registered members, you can access our Downloads section, you can participate in contests, etc. You can post in forums in English as well as in Hindi, in fact we encourage you to use Hindi in your posts. If you have any problem with registration or login, please contact us.

     
  


 
  Microsoft Windows Forums  Windows Vista  General  In XP virus infected named newheur_pe virus how to remove it unable to clean using eset nod32 antivi
Previous Previous
 
Next Next
New Post 8/2/2008 12:25 PM
User is offline lami
10 posts
Member


In XP virus infected named newheur_pe virus how to remove it unable to clean using eset nod32 antivi 

my machine is of XP os which is now showin a virus named newheur_pe virus in eset but its not cleaning ..when i scanned using trend micro office scan it doesn t shows it as virus at all..these antivirus are all full version.. this virus occupies the whole memory processes and unable to process any other things in the machine..i traced the folder which creates a exe in the startup location..even i deletes the entries in the windows, regedit wherever it is in the machine ..it reproduces again n again ..i was fedup also i have lot of data so could not format the machine ..give me solution to ged rid of the virus ..thanks in advance...

 
New Post 8/2/2008 1:45 PM
User is offline Manan
889 posts
beingmanan.com
Experienced Member




Re: In XP virus infected named newheur_pe virus how to remove it unable to clean using eset nod32 antivi 
Modified By Manan  on 8/2/2008 1:46:12 PM)

Found this on another forum:

 

Thanks for the replies everyone, I believe I finally managed to eliminate this particular nasty.

Thanks pandlouk for reminding me about a-squared, I'd forgotten about that program. It was with this I made some progress. After downloading the command line version and running a scan, a variant of the Trojan-Downloader.win32.Agent was detected in sxs2.exe. A-squared also allowed me to quarantine the file. Interestingly, it wasn't able to remove a number of associated files and registry entries.

From what I have discovered, in addition to the sxs2.exe there are a number of 'autorun.*' files located in the root and %winroot%\system32. These files perform a number os tasks including, creating an autorun enrty in userinit.exe,  changing the attributes on all the related files to hidden, system, and read only and also changing the value in:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden" so that it's impossible to choose the show hidden and system files in explorer.

The 'autorun.*' files, by the way, are:

autorun.inf
autorun.bat
autorun.reg
autorun.bin
autorun.exe
autorun.vbs
autorun.wsh
autorun.fcb
autorun.srm
autorun.txt
autorun.ini
autorun.ico

download a-squared Free 3.0.


It's a Microsoft world kid, I am just living in it.

Read the latest info from all the top Microsoft related blogs at one place: Everything Microsoft

Being Manan.comEverythingMS News Mesh

BeingManan.com | Twitter: manan | Last.FM: manan
 
New Post 8/2/2008 4:53 PM
User is offline Vasu Jain
2968 posts
www.cyberDimensions.blogspot.com
Forum Guru




Re: In XP virus infected named newheur_pe virus how to remove it unable to clean using eset nod32 antivi 

 lami wrote 

virus named newheur_pe virus in eset but its not cleaning ..when i scanned using trend micro office scan it doesn t shows it as virus at all..these antivirus are all full version.. this virus occupies the whole memory processes and unable to process any other things in the machine..i traced the folder which creates a exe in the startup location..even i deletes the entries in the windows, regedit wherever it is in the machine ..it reproduces again n again ..

NOD32 antivirus system uses a unique implementation of heuristic analysis, which can successfully detect many new viruses and worms as soon as they first appear. The heuristic analysis protects the users of NOD32 in the most critical time of infection spread - from the appearance of the infiltration until the release of antivirus updates. In such case, NOD32 will mark the new found infiltration as "Probably unknown ... virus" followed by detailed description of the infiltration.

Most common types of infiltration are:

  • NewHeur_PE virus
    File marked as "NewHeur_PE v�rus" was detected using broad heuristics because it contains parts of code typical of worm infiltrations spread over the internet. Using this method NOD32 was able to identify worms Win32/Zafi.B, Win32/Mydoom.R, Win32/Bagle.X and many others.

What to do when NOD32 detects a "Probably unknown..." virus ?

Please email the file to sample@nod32.com. If you are sure that this is a "fasle alarm", include also a description of the program the file belongs to (product name, its purpose, creator, and the URL for the product's website).

 

 

 

they may help as well:

http://forums.spybot.info/archive/index.php/t-12192.html

http://translate.google.com/translate?hl=en&sl=zh-CN&u=http://www.wangyx.com/%3Fp%3D14&sa=X&oi=translate&resnum=9&ct=result&prev=/search%3Fq%3Dsxs2.exe%26hl%3Den%26sa%3DG


"There are only '10' types of ppl in dis world. Those who understand BINARY and those who dont."

 
Previous Previous
 
Next Next
  Microsoft Windows Forums  Windows Vista  General  In XP virus infected named newheur_pe virus how to remove it unable to clean using eset nod32 antivi


   Get Your Own E-Mail Account @MeraWindows.com Minimize  
New Page 1 New Page 1
Show your cool quotient with @merawindows.com email account