Windows 7 Forums Search
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7 - AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!

 
01-08-2012   #1


Windows 7 Home 64 bit OEM
 
 

AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!

Okay, so while I was watching TV (on the TV), my AVG Resident Shield thing popped up with multiple thread detection. Apparently I have five infections of "Trojan horse SHeur4.MTZ." Googling it did not come up with the specific trojan.

These were all found in the Samsung Support Center and BatteryLife extenders.

The results:

c:\Program Files (x86)\Samsung\BatteryLifeExtender\Drv\SABI2x86\KStartMem.exe
c:\Program Files (x86)\Samsung\Samsung Support Center\Drv\drv2x86\KStartMem.exe

My options are to "Remove selected," "Remove all unhealed," and "Close." If I right click on one, it says "Move to vault" and "Go to file." I clicked "Remove selected" and they were moved to the vault.

What does the virus do? What is KStartMem.exe? Should I take any further action?

Edit: Did a virus scan and the virus came up in some more places. Lovely.

D:\SystemSoftware\BASW-01314A\BLE_Setup.msi\_D1916ABB420E953A1F6ECB8cFDACD69C:\_BA8F88163136405BA3AF746835FC96DF
D:\SystemSoftware\BASW-01314A\BLE_Setup.msi\_D1916ABB420E953A1F6ECB8cFDACD69C
D:\SystemSoftware\BASW-01314A\BLE_Setup.msi
C\Windows\Installer\1191e.msi:\_D1916ABB420E953A1F6ECB8cFDACD69C:\_BA8F88163136405BA3AF746835FC96DF
C\Windows\Installer\1191e.msi:\_D1916ABB420E953A1F6ECB8cFDACD69C
C\Windows\Installer\1191e.msi:

I'm trying to remove these objects, but I'm getting the message:
Moved object is bigger than the archive size limit
Object mentioned below is bigger than maximum size permitted
D:\SystemSoftware\BASW-01314A\BLE_Setup.msi
C\Windows\Installer\1191e.msi:

So . . . what do I do?


Last edited by suzannec; 01-08-2012 at 02:20 AM..
My System SpecsSystem Spec
01-08-2012   #2


Windows 7
 
 


I AM HAVING THE SAME PROBLEM!!!! I was watching TV and all of a sudden my AVG popped up with the same Trojan! I can't find any information on the Internet on how to remove it, because when I try to remove it with my AVG, it says that removing it may cause my system to become unstable. I also can't remove it to the Virus Vault, due to the same issue of the files being bigger than my archive size.
Attached Thumbnails
AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!-trojan-sheur4.mtz-.jpg   AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!-trojan-sheur4.mtz-part-2.jpg  
My System SpecsSystem Spec
01-08-2012   #3


Win 7 premium 64bit/Win Pro XP 32bit /Ubuntu 12.04
 
 


well i found this article that explains what it does
http://www.eset.eu/encyclopaedia/msi...kit-gen?lng=en
about it not removeing im not sure i say wait for someone with more knowledge about this then me ,sorry i cant really help but don't worry i'm certain somebody here can help you
EDIT:anyways best advice i could give is download malwarebytes and scan your system and try to remove it with that http://www.malwarebytes.org/

also try to scan it with SAS,i took off a couple nasties with this when malwarebytes failed me before http://www.superantispyware.com/
My System SpecsSystem Spec
.


01-08-2012   #4


windows 7 32 bit
 
 

Trojan SHeur4.MTZ

Hi there,

I also have the virus in 5 locations and 2 of them I have in the virus vault. The other three say that it they are too large to move. I am also trying to find out how to get rid of these. Can someone help?

These are the 3 files that I can not move

C:\Windows\Installer\777c4.msi
\_BA8F8816136405BA3AF7468
\_1A1C8CC4CAF00E54302118F

These are the 2 files I have in the virus vault

C:\Program Files (x86) Samsung\Samsung Support Centre\Drv\drv2x86\KStartMem.exe

C:\Program Files (x86) Samsung\BatteryLifeExtender\Drv\SAB12x86KStartMem.exe


Any help would be greatly appricated.

Thanks
My System SpecsSystem Spec
01-08-2012   #5


windows 7
 
 


im having the same issue. hopefully figure out how to resolve this....please post if you figure it out first!
My System SpecsSystem Spec
01-08-2012   #6


 
 


it seems like a false postive switch the Microsoft sercurity Essentials instead. it's free and better than AVG.
My System SpecsSystem Spec
01-08-2012   #7


Windows 7 Home Premium x64 SP1
 
 


Welcome to Seven Forums solaris326, powereyeguy and kancerr. Submit the files to Virus Total, and see what 43 AV have to say about them. A Guy
My System SpecsSystem Spec
01-08-2012   #8
JMH


Win 7 Ultimate 64-bit. SP1.
 
 


Quote   Quote: Originally Posted by AussieGuy92 View Post
it seems like a false postive switch the Microsoft sercurity Essentials instead. it's free and better than AVG.
Not a very helpful post to people seeking advice /support with a problem.
My System SpecsSystem Spec
01-08-2012   #9


windows 7
 
 


virus total came up with no results ;/
My System SpecsSystem Spec
01-08-2012   #10


windows 7
 
 


i think it is a false positive. everybody who has it has a samsung... only avg is picking it up.
My System SpecsSystem Spec
Reply

 AVG found trojan SHeur4.MTZ in BatteryLifeExtender?! problems?



Thread Tools



Similar Threads for: AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!
Thread Forum
Network drive found but not found? Network & Sharing
Solved Need some help got a trojan System Security
Trojan:Win32/FakeSpypro & Trojan:JS/FakeSpypro System Security
Trojan Found in Setup.exe on Build 16385 x86 ISO Image! System Security


All times are GMT -5. The time now is 01:15 AM.



Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30