 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
Windows 7 - Antivirus found infection in srrstr.dll |
01-26-2012
|
#1 | | Windows 7 Home Premium 64 Bit |
Antivirus found infection in srrstr.dll Okay so I have been without a antivirus for quite a while and really needed one so I was able to get Kaspersky, after installing and updating I did a full system scan. In the scan it found 38 virus's thought it wasn't able to finish the scan due to a blue screen error. Of those 38 I was able to remove all except 1 which it said was the file srrstr.dll in my SysWOW64 folder. After finding that, I did some research and found out that the file srrstr.dll should actually be in System32 so I took a look in there and actualy found a second srrstr.dll file. So my question is, would it be wise to delete the srrstr.lll from my SysWOW64? Or would doing so actualy harm my computer even further.
If nessesary I can kill it with my File Assassin from MalwareBytes.
| My System Specs | | System Manufacturer/Model Number ASUSTeK Computer Inc. OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Duo CPU P7450 @ 2.13GHz 2.13 GHz Memory 4.00 GB |
01-26-2012
|
#2 | | Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 |
Hi,
Which virus were you infected with?
Regards,
Golden | My System Specs | | System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
2*Samsung F1 SpinPoint 1TB in RAID1;
1*Western Digital WD10EARS 1TB
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! |
01-26-2012
|
#3 | | Windows 7 Home Premium 64 Bit |
Umm a Trojan I believe. Basicly all it told me was Trojan.Win32.Searches.abv, then where it was. | My System Specs | | System Manufacturer/Model Number ASUSTeK Computer Inc. OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Duo CPU P7450 @ 2.13GHz 2.13 GHz Memory 4.00 GB |
01-26-2012
|
#4 | | Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 |
Hi,
It seems to be a variant of the Win32.Searches trojan which is known to be quite damaging. Here is a similar infection where the OP also reported srrstr.dll being flagged by Kaspersky: Kaspersky Lab Forum > Kaspersky unable to remove Trojan.Win32.Searches.abt
Its unclear from the thread how they fixed the problem, or if they even did, so I would recommend the following:
- On a different clean PC, change all your passwords for any online forum/bank accounts etc.
- Do a format and clean install of your entire system to guarantee that the infection as been removed Clean Install Windows 7
If you have an OEM Windows installation, you might be able to do a factory reset/recovery from the recovery partition/disks.
Regards,
Golden | My System Specs | | System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
2*Samsung F1 SpinPoint 1TB in RAID1;
1*Western Digital WD10EARS 1TB
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! |
01-26-2012
|
#5 | | Windows 7 Home Premium 64 Bit |
Hmmm, alright thanks. I'm not sure if I have a partition for that in my computer but I do have a recovery disk. Just was hoping to not have to lose everything but sometimes seems its just out of our control.
Just 1 more thing, would it not be wise then to possibly just delete it with my File Assassin from MalwareBytes?
Last edited by Zrpizzaguy; 01-26-2012 at 11:55 AM..
| My System Specs | | System Manufacturer/Model Number ASUSTeK Computer Inc. OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Duo CPU P7450 @ 2.13GHz 2.13 GHz Memory 4.00 GB |
01-26-2012
|
#6 | | |
I don't see why this needs to be a reload  . I would try downloading and running tdsskiller from: Virus Removal Tools which does a great job at finding rootkits. If it finds anything, remove it and reboot. Repeat as necessary(You may have to turn off system restore to be successful). From there, Download and install Malwarebytes Antimalware and run that. Once that is completed, I would run Spybot S&D (I recommend unchecking the box for Teatimer during install) Finally, I would download and run the appropriate version of hitman pro for your os from: Downloads - SurfRight. If you are still having problems, I would try combofix which can be downloaded from bleepingcomputer.com, and eset's online virus scanner. Hope it helps!
-Mantis | My System Specs | | System Manufacturer/Model Number Custom OS Windows 7 All Versions CPU i5 2500k Motherboard P8Z68-V PRO Graphics Card Asus GTX560TI Sound Card Integrated Monitor(s) Displays Hanns-G 28" Screen Resolution 1920x1200 Mouse Logitch G7 PSU Silverstone Strider Series 1000w Modular Hard Drives OCZ Agility2 120GB SSD
2x Seagate 7200.11 1TB HDD |
01-26-2012
|
#7 | | Windows 7 Home Premium 64 Bit |
Thing is, iv used MalewareBytes, but the file is in both System32 where it should be, and SysWOW64. So i'm not entirely sure if its safe for deleting or not. If it was I would have used File Assassin a while ago. | My System Specs | | System Manufacturer/Model Number ASUSTeK Computer Inc. OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Duo CPU P7450 @ 2.13GHz 2.13 GHz Memory 4.00 GB |
01-26-2012
|
#8 | | |
If it is being detected as a virus in your syswow64 folder but not system32, then they are probably not really the same file. See if the file sizes match up, if they don't then delete the syswow64 one, if they do match and have the same modified date then delete them both and replace them with one from a windows disk. (If you need me to I can upload the file. I just need to know your windows version, service pack, and if it is 32 or 64 bit.
-Mantis | My System Specs | | System Manufacturer/Model Number Custom OS Windows 7 All Versions CPU i5 2500k Motherboard P8Z68-V PRO Graphics Card Asus GTX560TI Sound Card Integrated Monitor(s) Displays Hanns-G 28" Screen Resolution 1920x1200 Mouse Logitch G7 PSU Silverstone Strider Series 1000w Modular Hard Drives OCZ Agility2 120GB SSD
2x Seagate 7200.11 1TB HDD |
01-26-2012
|
#9 | | Windows 7 Home Premium 64 Bit |
Well I already know they aren't the same size, the one in System32 is somewhere in 200kb's, where as this one is 96kb's. | My System Specs | | System Manufacturer/Model Number ASUSTeK Computer Inc. OS Windows 7 Home Premium 64 Bit CPU Intel(R) Core(TM)2 Duo CPU P7450 @ 2.13GHz 2.13 GHz Memory 4.00 GB |
01-26-2012
|
#10 | | |
Then I would recommend that you file assassin the one in syswow64 and run the programs I specified in my original post. That should get you going fine.
-Mantis | My System Specs | | System Manufacturer/Model Number Custom OS Windows 7 All Versions CPU i5 2500k Motherboard P8Z68-V PRO Graphics Card Asus GTX560TI Sound Card Integrated Monitor(s) Displays Hanns-G 28" Screen Resolution 1920x1200 Mouse Logitch G7 PSU Silverstone Strider Series 1000w Modular Hard Drives OCZ Agility2 120GB SSD
2x Seagate 7200.11 1TB HDD Antivirus found infection in srrstr.dll problems? All times are GMT -5. The time now is 01:20 AM. |  |