Author Topic: win32:Malware-gen virus. Help needed  (Read 4827 times)

0 Members and 1 Guest are viewing this topic.

matttttttttttt

  • Guest
win32:Malware-gen virus. Help needed
« on: January 09, 2011, 08:16:39 AM »
I decided to reformat my computer today and afterwards ran a boot scan with avast for the heck of it. It found the virus in the subject above. Can't repair, quarentine, or delete it. I read this forum and dowloaded, installed, and ran the free malwarebytes program. But it didn't find said malware. I re-ran the avast boot scan and it still detects the virus. Any suggestions?

The virus is located in C:\Program files\online services\MSN90\Pkgs\en\outlook2003sm.cab|>L2636304.CAB|>FINDER.EXE

SafeSurf

  • Guest
Re: win32:Malware-gen virus. Help needed
« Reply #1 on: January 09, 2011, 08:32:07 AM »
Hello matttttttttttt and welcome to the forum.

Do you have anything in your Avast Virus Chest?  If so, please give a screen shot (preferably) or type exactly what is in the Chest.

Next, check the information on the first post of this thread under Virus/Worms for you to check your machine for malware: http://forum.avast.com/index.php?topic=53253.0

Follow the directions for obtaining the OTL logs (save them as ANSI and not Unicode).  When the OTL scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.  Post the two (2) OTL log as an attachment (Additional Options > Attach > Browse (the logs will be on your desktop > Post). 

I am going to refer you to our Certified Malware expert, named Essexboy.  He will also review your logs and give you further instructions, however he comes on the forum late UK time.  He will respond to you in this thread, so remember to check this thread daily. 

Please do not make any further changes to your machine once you have provided the logs.  Thank you.


matttttttttttt

  • Guest
Re: win32:Malware-gen virus. Help needed
« Reply #2 on: January 09, 2011, 09:10:49 AM »
There is nothing in the chest. Once the virus was found in the boot scan I tried to repair it but it was unable to. Error 42060. I tried to quarentine it but it wouldn't let me. I even tried deleting it(which I know you shouldn't) and it wouldn't do that either.

I then read this forum about trying the malwarebytes so I downloaded it and ran it. Nothing found. So now what? There is no "If nothing found go to step 3" listed on the thread.

Then I remembered I get Norton for free through my provider. I hadn't used it up til now but decided to download and try it. It also found nothing. Yet when I run the avast boot scan it finds the virus.

SafeSurf

  • Guest
Re: win32:Malware-gen virus. Help needed
« Reply #3 on: January 09, 2011, 09:16:30 AM »
Once the virus was found in the boot scan I tried to repair it but it was unable to. Error 42060. I tried to quarantine it but it wouldn't let me. I even tried deleting it(which I know you shouldn't) and it wouldn't do that either.
You should quarantine it...not repair (as some malware cannot be repaired, and not delete it).  Quarantine is the safest option.

Then I remembered I get Norton for free through my provider. I hadn't used it up til now but decided to download and try it. It also found nothing.
So you now have Norton and Avast on your machine?  Two AV's on the same machine create all kinds of problems!  If you have Norton on your machine, you need to uninstall it:

Download and run the Norton removal tool from here to clear them  http://us.norton.com/support/kb/web_view.jsp?wv_type=public_web&docurl=20080710133834EN
then reboot.

Now try running the Avast boot-time scan and quarantine the infection.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:Malware-gen virus. Help needed
« Reply #4 on: January 09, 2011, 01:51:37 PM »
I believe finder.exe is a false positive, update Avast and then rescan

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: win32:Malware-gen virus. Help needed
« Reply #5 on: January 09, 2011, 02:02:24 PM »
I believe finder.exe is a false positive, update Avast and then rescan

Yes, it's a FP...!
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0