Author Topic: (FP) Win32:spyware-gen (TRJ)  (Read 10475 times)

0 Members and 1 Guest are viewing this topic.

Bob Anderson

  • Guest
(FP) Win32:spyware-gen (TRJ)
« on: July 14, 2008, 05:54:14 PM »
Yesterday July 13 Avast home detected Reg Organizer (a registry cleaner I have been using for years) as a virus. There us no doubt this is a FP. I have sent the detected file to Avast and am awaiting a fix. I cannot run reg organizer until there is a fix. This is my first FP and I have been using Avast for about two years. Reg Organizer is not well known but if anyone here runs it with Avast, please let me know.

-Bob

sanctuaryforever

  • Guest
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #1 on: July 14, 2008, 06:34:16 PM »
I'm sure they will fix it as soon as they get around to investigating it

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89187
  • No support PMs thanks
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #2 on: July 14, 2008, 07:54:27 PM »
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Bob Anderson

  • Guest
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #3 on: July 14, 2008, 08:48:09 PM »
Thanks DavidR. I followed your exclusion instructions and Avast no longer detects it. I also scanned it at Virus Total and it was detected by 10 out of 33 AVs.

http://www.virustotal.com/analisis/f9ba649b41de1e835df26942588f0ac3

I don't see how organizer.exe could be malware. I have run it hundreds of times since I first installed the cleaner, Reg Organizer. I have not changed the file in any way.

I use True Image and what I will do is wait for Avast updates, then I will restore an older image dated before July 13. Avast will update automatically and then I'll try to run Reg Organizer. If it runs, problem solved and then I would restore the latest image. If no solution can be found then I will just leave organizer.exe excluded forever.

-Bob

Spiritsongs

  • Guest
"Registry Cleaner(s)"
« Reply #4 on: July 14, 2008, 09:37:42 PM »
 :)  Hi Bob :

 There are many "Microsoft Most Valuable Professionals" who advise AGAINST
  using a "registry cleaner" on the newer Operating Systems; the Ones who
  help people fight malware problems on the Aumha Support Forums are
  definitely against using them . You might be interested in WHAT they have to
  say at http://aumha.net/viewtopic.php?t=28099  !?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89187
  • No support PMs thanks
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #5 on: July 14, 2008, 10:23:59 PM »
Thanks DavidR. I followed your exclusion instructions and Avast no longer detects it. I also scanned it at Virus Total and it was detected by 10 out of 33 AVs.

http://www.virustotal.com/analisis/f9ba649b41de1e835df26942588f0ac3

I don't see how organizer.exe could be malware. I have run it hundreds of times since I first installed the cleaner, Reg Organizer. I have not changed the file in any way.

You should still send it to avast as outlined in the link also, that is truly the only way to resolve an FP (if this is truly what it is), which will help other avast users if they happen to use reg organiser (contrary to the Microsoft MVPs ;D opinions, which personally I don't hold with, not that I'm an MVP ;D).

I use True Image and what I will do is wait for Avast updates, then I will restore an older image dated before July 13. Avast will update automatically and then I'll try to run Reg Organizer. If it runs, problem solved and then I would restore the latest image. If no solution can be found then I will just leave organizer.exe excluded forever.

The simplest and safest solution whilst the jury is out (10/32 detections) would have been to stick the reg organiser file in the chest (you should be able to survive without it for a short time), where it can do no harm. Periodically scan the copy in the chest (after VPS updates) and when it is no longer detected, restore it. Much less hassle than having to use True Image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Bob Anderson

  • Guest
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #6 on: July 15, 2008, 01:14:23 AM »
DavidR:

I have sent organizer.exe directly from the chest to Avast to their virus address yesterday July 13th.

Good point about scanning the copy in the chest. That would be simpler than doing a restore from TI.

-Bob

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89187
  • No support PMs thanks
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #7 on: July 15, 2008, 01:19:44 AM »
No problem, I have Drive Image and even though that is quick, we often forget the easier solution, even though you probably didn't realise you could scan within the chest.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

tb39

  • Guest
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #8 on: July 17, 2008, 09:00:31 PM »
DavidR:

I have sent organizer.exe directly from the chest to Avast to their virus address yesterday July 13th.

Good point about scanning the copy in the chest. That would be simpler than doing a restore from TI.

Hi Guys.......... this is my firt question on the forum.   I have this trojan ? Win32:spyware-gen (TRJ) when I scanned with Avast, but I am wondering if it is a false positive also.   Have you had any reply/news from Avast yet ? - I have mine confined in the chest and all the rest of the workings of the PC seem to be OK.

Tig   :-\

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #9 on: July 17, 2008, 09:18:03 PM »
tb39, follow David's advices on reply #2.
The best things in life are free.

tb39

  • Guest
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #10 on: July 17, 2008, 10:51:51 PM »
Thanks Tech - will do.

tb39

Bob Anderson

  • Guest
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #11 on: July 18, 2008, 07:52:07 PM »
tb39:

What file triggered Win32:spyware-gen (TRJ) ? The latest update today 080718-1 does not solve the problem for my file 'organizer.exe', but I have it excluded from scanning.

-Bob

tb39

  • Guest
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #12 on: July 18, 2008, 09:26:12 PM »
Bob...........
This problem was on a friends PC but today I was over there and he had deleted the file from the chest  !!! ???
However, I think it was from a temp file in the cookies section on his I.E.
I scanned with Avast and all was clear of 'nasties' - I also scanned with Malwarebytes and SuperAntiSpyware and again all is clear and clean.
Sorry  :'( I cannot help with anymore information as I have not been able to send the offending file for verification of being an FP (due to my friends rather hasty action of deleting it !!)
Hope you get yours sorted soon - I will keep an eye on it.

tb39

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89187
  • No support PMs thanks
Re: (FP) Win32:spyware-gen (TRJ)
« Reply #13 on: July 18, 2008, 10:47:29 PM »
Check the avast! Log Viewer (right click the avast 'a' icon), Warning section, this contains information on all avast detections.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security