Author Topic: WIN32:malware-gen my biggest problem at computer world ..  (Read 1600 times)

0 Members and 1 Guest are viewing this topic.

rsaylrsayl

  • Guest
WIN32:malware-gen my biggest problem at computer world ..
« on: November 01, 2010, 02:18:26 AM »
hello Tech Team
iam using avast v4.8 updated
and i have virus or malware ..
WIN32:malware-gen
i can't delete it even when i make schudle boot scan
some times it get the virus and i choose delete all !
but when i open the windows again i recive the same alret from avast that i still have the same virus !

while i was trying to solve it or finding any tool to remove this virus or malware ..
i found this link by google
http://forum.avast.com/index.php?topic=51642.0
and i found essexboy asking for using malwarebytes ..
and i got it .. and made scan .. then i got that i have 6 virus or malware
and this is the report which i got it

Quote
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5008

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/30/2010 11:06:32 PM
mbam-log-2010-10-30 (23-06-32).txt

Scan type: Flash scan
Objects scanned: 104381
Time elapsed: 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AMSINT32 (Virus.Sality) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

but the programme ask me to restart when i choose remove for them ..
and when iam done from the restart .. i face the same virus .. by avast ..
and the same 6 virus by the malwarebytes ..
and no one of them is deleted ..

i whsh to solve this problem so much ..
cause i have so many data which i can't accept lossing it by making formate ..

and thanks at all
w8ing for the answer

SafeSurf

  • Guest
Re: WIN32:malware-gen my biggest problem at computer world ..
« Reply #1 on: November 01, 2010, 09:54:55 AM »
Hello rsaylrsayl and welcome to the forum.  :)

Please update MBAM and run a FULL scan and this time instead of taking "no action" put all infected items into quarantine.  If asked to reboot after running MBAM, then do so.

After running MBAM and posting you log again, check the information on the first post of this thread under Virus/Worms for you to check your machine for malware: http://forum.avast.com/index.php?topic=53253.0

Follow the directions for obtaining the OTL logs.  Post the two (2) OTL log as an attachment (Additional Options > Attach > Browse (the logs will be on your desktop > Post). 

I am going to refer you to our Certified Malware expert, named Essexboy.  He will also review your logs and give you further instructions, however he comes on the forum late UK time.  He will respond to you in this thread, so remember to check this thread daily.  I will continue to provide assistance in the meantime, then remain in the background while he works with you.

Also in your next post, please describe what problems you are having with your machine.

Please do not make any further changes to your machine after you provide the logs.

Let me know if you have any questions.  Thank you.