Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!

08 Jan 2012   #1
suzannec

Windows 7 Home 64 bit OEM
 
 
AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!

Okay, so while I was watching TV (on the TV), my AVG Resident Shield thing popped up with multiple thread detection. Apparently I have five infections of "Trojan horse SHeur4.MTZ." Googling it did not come up with the specific trojan.

These were all found in the Samsung Support Center and BatteryLife extenders.

The results:

c:\Program Files (x86)\Samsung\BatteryLifeExtender\Drv\SABI2x86\KStartMem.exe
c:\Program Files (x86)\Samsung\Samsung Support Center\Drv\drv2x86\KStartMem.exe

My options are to "Remove selected," "Remove all unhealed," and "Close." If I right click on one, it says "Move to vault" and "Go to file." I clicked "Remove selected" and they were moved to the vault.

What does the virus do? What is KStartMem.exe? Should I take any further action?

Edit: Did a virus scan and the virus came up in some more places. Lovely.

D:\SystemSoftware\BASW-01314A\BLE_Setup.msi\_D1916ABB420E953A1F6ECB8cFDACD69C:\_BA8F88163136405BA3AF746835FC96DF
D:\SystemSoftware\BASW-01314A\BLE_Setup.msi\_D1916ABB420E953A1F6ECB8cFDACD69C
D:\SystemSoftware\BASW-01314A\BLE_Setup.msi
C\Windows\Installer\1191e.msi:\_D1916ABB420E953A1F6ECB8cFDACD69C:\_BA8F88163136405BA3AF746835FC96DF
C\Windows\Installer\1191e.msi:\_D1916ABB420E953A1F6ECB8cFDACD69C
C\Windows\Installer\1191e.msi:

I'm trying to remove these objects, but I'm getting the message:
Moved object is bigger than the archive size limit
Object mentioned below is bigger than maximum size permitted
D:\SystemSoftware\BASW-01314A\BLE_Setup.msi
C\Windows\Installer\1191e.msi:

So . . . what do I do?


My System SpecsSystem Spec
.
08 Jan 2012   #2
solaris326

Windows 7
 
 

I AM HAVING THE SAME PROBLEM!!!! I was watching TV and all of a sudden my AVG popped up with the same Trojan! I can't find any information on the Internet on how to remove it, because when I try to remove it with my AVG, it says that removing it may cause my system to become unstable. I also can't remove it to the Virus Vault, due to the same issue of the files being bigger than my archive size.


Attached Thumbnails
AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!-trojan-sheur4.mtz-.jpg   AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!-trojan-sheur4.mtz-part-2.jpg  
My System SpecsSystem Spec
08 Jan 2012   #3
M1GU31

Windows 10 64bit
 
 

well i found this article that explains what it does
http://www.eset.eu/encyclopaedia/msi...kit-gen?lng=en
about it not removeing im not sure i say wait for someone with more knowledge about this then me ,sorry i cant really help but don't worry i'm certain somebody here can help you
EDIT:anyways best advice i could give is download malwarebytes and scan your system and try to remove it with that http://www.malwarebytes.org/

also try to scan it with SAS,i took off a couple nasties with this when malwarebytes failed me before http://www.superantispyware.com/
My System SpecsSystem Spec
.

08 Jan 2012   #4
powereyeguy

windows 7 32 bit
 
 
Trojan SHeur4.MTZ

Hi there,

I also have the virus in 5 locations and 2 of them I have in the virus vault. The other three say that it they are too large to move. I am also trying to find out how to get rid of these. Can someone help?

These are the 3 files that I can not move

C:\Windows\Installer\777c4.msi
\_BA8F8816136405BA3AF7468
\_1A1C8CC4CAF00E54302118F

These are the 2 files I have in the virus vault

C:\Program Files (x86) Samsung\Samsung Support Centre\Drv\drv2x86\KStartMem.exe

C:\Program Files (x86) Samsung\BatteryLifeExtender\Drv\SAB12x86KStartMem.exe


Any help would be greatly appricated.

Thanks
My System SpecsSystem Spec
08 Jan 2012   #5
kancerr

windows 7
 
 

im having the same issue. hopefully figure out how to resolve this....please post if you figure it out first!
My System SpecsSystem Spec
08 Jan 2012   #6
AussieGuy92

 
 

it seems like a false postive switch the Microsoft sercurity Essentials instead. it's free and better than AVG.
My System SpecsSystem Spec
08 Jan 2012   #7
A Guy

Microsoft Community Contributor Award Recipient

Windows 7 Home Premium x64 SP1
 
 

Welcome to Seven Forums solaris326, powereyeguy and kancerr. Submit the files to Virus Total, and see what 43 AV have to say about them. A Guy
My System SpecsSystem Spec
08 Jan 2012   #8
JMH

Win 7 Ultimate 64-bit. SP1.
 
 

Quote   Quote: Originally Posted by AussieGuy92 View Post
it seems like a false postive switch the Microsoft sercurity Essentials instead. it's free and better than AVG.
Not a very helpful post to people seeking advice /support with a problem.
My System SpecsSystem Spec
08 Jan 2012   #9
kancerr

windows 7
 
 

virus total came up with no results ;/
My System SpecsSystem Spec
08 Jan 2012   #10
kancerr

windows 7
 
 

i think it is a false positive. everybody who has it has a samsung... only avg is picking it up.
My System SpecsSystem Spec
Reply

 AVG found trojan SHeur4.MTZ in BatteryLifeExtender?!




Thread Tools Search this Thread
Search this Thread:

Advanced Search




Similar help and support threads
Thread Forum
how to remove the .exe Trojan horse SHeur4.zp virus?
I got infected with the trojan horse sheur4.zp and it infected most of my computer files, music and picture and some registry files. How do I get rid of this infection.
System Security
Trojan called 'Trojan.Generic.2582177' on my system
Hi, I have Window7 Ultimate 64 bit on my system. I use Bitfender as my antivirus software. This morning it informed me that it has found a file infected with a virus called 'Trojan.Generic.2582177' which it cannot clean. I've contacted Bitfender to see if they know what I should do but haven't...
System Security
operating system not found and no drivers were found eror
as usual I turned off my laptop and after a while a turned on again to use my laptop but it couldn't reach operating system and showed error : " OPERATING SYSTEM NOT FOUND" ! I tried all instructions to solve the problem and finally run by windows start up CD to re-install new windows. this...
Installation & Setup
Trojan Found in Setup.exe on Build 16385 x86 ISO Image!
Well, maybe that LeBlanc fellow had a point about bogus ISO images. I just fired up setup.exe from an image of the x86 Build 7600.16385 leak under my current build 7264 installation and look what Microsoft Security Essentials found (see attached image). Note: The ISO in question has the...
System Security


Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 13:06.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App