Author Topic: Pop:: Win32:Evo-gen [Susp], Win32:Malware-gen, URL:Mal and raspppoe  (Read 8266 times)

0 Members and 1 Guest are viewing this topic.

jlrq

  • Guest
Re: Pop:: Win32:Evo-gen [Susp], Win32:Malware-gen, URL:Mal and raspppoe
« Reply #15 on: April 29, 2014, 08:38:57 PM »
Sorry, missed it! Here you are.

BTW, it's been a few hours since the last Avast notification.... fingers crossed!

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Pop:: Win32:Evo-gen [Susp], Win32:Malware-gen, URL:Mal and raspppoe
« Reply #16 on: April 30, 2014, 08:17:10 PM »
Hi jlrq,

Quote
Maybe it's not relevant, but a lot of PPPoE and Outlook lines have been popping up in the Gmer window while analising...

GMER does not use virus database like AV/AM programs, nor it preform generics scans like OTL or FRST does. It is a powerfull antirootkit tool which has the task to detect any possible rootkit or malicious behavior using his own routines.
translated: . . GMER seeks hidden malware components/pieces/files, mal-behavior, malware designed to hide other active malware component from AV/AM or from our diagnostic tools, they are known as rootkit.

This in other words means that the GMER shall likely detect known or unknown malware (behavior) or some other type of rootkit. This also means that GMER will probably detect some legitimate program as a possible malicious behavior.

From posted GMER logs I can tell/gess how PPPoE and Outlook are related, as both application does calling kernel32.dll. My guesses are that for this reason avast! using his own "Eve-Gen" routine to flags raspppoe.exe when Outlook has attempt to send e-mail.


---- User code sections - GMER 2.1 ----
.text   C:\Program Files (x86)\WAN Miniport PPPOE\raspppoe.exe[916] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112           
.text   C:\Program Files\AVAST Software\Avast\AvastUI.exe[3796] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter       
.text   C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE[4796] C:\Windows\system32\kernel32.dll!SetUnhandledExceptionFilter + 1 






=> I can confirm now, on your system there is no malware. To remove FRST and GMER, please download DelFix again and check box for Remove disinfection tools.

raspppoe.exe is a software for dial up connections (old way for internet connection) and is not digitally signed. You can uninstall this services driver, or I can use FRST to delete if you wish, but in any case this isn't legit nor malicious service by itself. If I where you, I would remove (uninstall) this if I do not use it.

« Last Edit: April 30, 2014, 08:23:03 PM by magna86 »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Pop:: Win32:Evo-gen [Susp], Win32:Malware-gen, URL:Mal and raspppoe
« Reply #17 on: April 30, 2014, 08:25:32 PM »
The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.

VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

jlrq

  • Guest
Re: Pop:: Win32:Evo-gen [Susp], Win32:Malware-gen, URL:Mal and raspppoe
« Reply #18 on: May 02, 2014, 12:22:41 PM »
Hi again,

I apologize for my late reply, I have been away for a couple of days. Only think I can tell you is that since my last message, no more windows have appeared and that I am very happy that you say that my system is clean. I just hope no more windows pop up. DelFix applied.

I do really appreciate the time you have put into helping me solve this issue. If only we were in the same continent, I would happily buy you a couple of beers!!! You guys do an amazing job!

Many thanks!  8)