Author Topic: Win32:adware-gen  (Read 6834 times)

0 Members and 1 Guest are viewing this topic.

aarons3

  • Guest
Win32:adware-gen
« on: May 03, 2007, 09:23:40 PM »
Need some help.
I thought I had Gromozon on my Pc. I scanned for it using the site FreewheelinFrank gave but it did not find anything. Ive ran avast and came up with Win32:adware-gen. I locked in the chest, now what. What ever I have it  is changing,moving and deleting my icons my wallpaper slowing my computer way down and yelling DANGER DANGER DANGER in the voice of the robot from the old Lost in Space. Please help.   Unfortunately I just know enough about computer to get myself in real trouble.   ???

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Win32:adware-gen
« Reply #1 on: May 03, 2007, 09:35:50 PM »
Hi aarons3

Have you tried a boot time scan with avast!? Right click the scanner screen, select 'schedule a boot time scan' and reboot when requested.

Have you tried some rootkit scanners:

http://www.f-secure.com/blacklight/
http://www.grisoft.com/doc/download-free-anti-rootkit/us/crp/0

Have you tried the usual free anti-Trojan scanners?-

AVG Anti-spyware (requires Win2k/XP):

http://www.ewido.net/en/product/

a-Squared Free:

http://www.emsisoft.com/en/software/free/

Ad-Aware:

http://www.download.com/3000-2144-10045910.html

Spybot Search & Destroy:

http://www.safer-networking.org/en/download/index.html

If you have or none of this helps, please post a HijackThis! log:

http://www.bleepingcomputer.com/tutorials/tutorial42.html
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Churchmouse

  • Guest
Re: Win32:adware-gen
« Reply #2 on: May 07, 2007, 10:30:00 AM »
Having similar problems here.  :-[  Two nights ago, I noticed my desktop icons suddenly started doing weird things (most all changed to either a blank shortcut arrow and/or outstretched hand)... Before rebooting I ran an Avast system scan and it came up with the following (copied and pasted from Warning log):

5/5/2007   10:25:12 PM   1178418312   HP_Administrator   3744   Sign of "Win32:Adware-gen. [Adw]" has been found in "D:\I386\APPS\APP24364\src\CompaqPresario_Spring06.exe\%MAINDIR%\w6Setp.EXE\[Embedded#5a868]" file. 
5/5/2007   10:28:50 PM   1178418530   HP_Administrator   3744   Sign of "Win32:Adware-gen. [Adw]" has been found in "D:\I386\APPS\APP24364\src\HPPavillion_Spring06.exe\%MAINDIR%\w6Setp.EXE\[Embedded#5a868]" file. 
5/5/2007   10:34:29 PM   1178418869   HP_Administrator   3744   Sign of "Win32:Adware-gen. [Adw]" has been found in "D:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP51\A0009162.exe\%MAINDIR%\w6Setp.EXE\[Embedded#5a868]" file. 
5/5/2007   10:34:50 PM   1178418890   HP_Administrator   3744   Sign of "Win32:Adware-gen. [Adw]" has been found in "D:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP51\A0009163.exe\%MAINDIR%\w6Setp.EXE\[Embedded#5a868]" file. 

i.e., 5 infected files.  I took the advised action and moved them all to the virus chest, then scheduled and ran a boot-time scan just to make sure there was nothing else.  The boot scan was clean, as was the follow-up scan done a few hrs. ago.

Most of the icons have returned to the desktop (except for My Documents shortcut and one for saved games); but many of the folder icons and system shortcut links to folders within the C:\ drive itself are still missing.   ???  They've been replaced by the "unknown file"-looking thingy when Windows doesn't know what a file is associated with; although the ones I've tried still seem to work.

This is all *Very* get-out annoying, since this is barely a two-month old new Windows XP Media Center pc and here it's been messed with by some low-life idiot with nothing better to do than cause unknown people grief!  >:( ... How can I restore the missing icons?  I had made a DVD backup of the restore partition (good thing, as some files on the D:\ drive seem to have been altered); but I'd prefer to avoid reinstalling the OS if at all possible  I was still in the process of transferring old files from previous PC to new, adding programs and otherwise and customizing settings, etc., and so don't have any backups of the files and changes I've made to it so far.

Regarding the earlier suggestions, a) I've heard that rootkit detectors should only be used by those very technically-savvy who know exactly what they're doing (I'm not there yet -- far from that!). :).  b) I had a copy of the AVG Anti-Spyware, but it's on my other desktop PC and the trial has expired... Are you permitted to have more than one free scanner installation; and if so can it be used non-resident after the trial expires?  c) I'm stuck with a *verrrrrry slow* dialup connection and for some odd reason, Ad-Aware has been returning error messages after 5% update file is downloaded.  After several weeks and no change/improvement on that situation, I gave up.  I remember reading somewhere that Lavasoft had run into some type of legal trouble; and that coupled with increasing reports of unreliability and security professionals who no longer recommend it, I'm hesitant to download/install it again.


P.S. I do have Spybot S&D and have run two or three scans subsequent to this annoying incident.  they have found nothing.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Win32:adware-gen
« Reply #3 on: May 07, 2007, 11:01:23 AM »
Hi Churchmouse,

Some rootkit scanners are more user friendly than others. Those from AVG, F-Secure, Panda are fine for the less "technically-savvy", although some legitimate applications do hide processes, so always check any detections on Google.

You can have more than one copy of AVG Anti-Spyware and it will run as an on-demand scanner (non-residential) after the trial period has finished- I'd definitely recommend a scan with this product.

Try removing Ad-Aware and reinstalling it. I've had no problems with reliability and it always finds things on infected computers. Whether or not it has the best detection rate I don't know- my approach is to run multiple free scans because they all pick up different scans.

Try scanning in Safe Mode with Spybot, Ad-Aware and AVG Anti-Spyware, as this can help with detection and removal.

http://www.pchell.com/support/safemode.shtml

To fix your icon problem, try downloading TweakUI and running the option to rebuild icons:

http://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx

« Last Edit: May 07, 2007, 12:34:07 PM by FreewheelinFrank »
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Churchmouse

  • Guest
Re: Win32:adware-gen
« Reply #4 on: May 08, 2007, 05:46:04 AM »
Thanks, Frank, for the links and all the helpful advice. :)  When I checked on the Tweak UI page, there's two download links for this program, including one version  for "Itaniumâ„¢-based systems"...What's the difference, and which one should I choose?

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Win32:adware-gen
« Reply #5 on: May 08, 2007, 09:02:28 AM »
Itanium is a type of chip. Choose that download if you know you have that chip in your computer. I'd hazard a guess that the other link will be the one you need, as I don't believe this chip is particularly common in PC's, but check what chip you have anyway- there's usually a sticker on the computer.

http://en.wikipedia.org/wiki/Itanium
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog