Author Topic: Win32:Malware-gen created everytime i launch a program  (Read 6024 times)

0 Members and 1 Guest are viewing this topic.

erick2687

  • Guest
Win32:Malware-gen created everytime i launch a program
« on: December 01, 2009, 06:57:25 PM »
Hello,

This has been a pretty recent event. Every time I launch this certain program, Avast detects something in the temporary folder of the program. It is a known program and I have uninstalled it and reinstalled it and received the same response.

1. How was it detected? What was scanning, you yourself or the back-ground scanner? When did the message occur on a download, unzipping, opening a file, mail or mail-attachment, etc.?
opening Livid's Union-resident protection picked it up

2. What was the source of the file, where did the file come from?.: e.g. address, URL, source.

C:\Documents and Settings\CeeKay\Local Settings\Temp

3. When was it downloaded or received?
It is created on program launch
4. What is the exact file name with extension.
name changes.the last two were
mxe31D.tmp
mxe26F.tmp

5. What was the exact wording of the message that the AV program  came up with? This is important for later.
"file name.tmp" contains a sample of Win32:Malware-gen

here is the jotti link
http://virusscan.jotti.org/en/scanresult/d8f4c92750093652900d464f89729b610a60e98e

also i scanned my computer with avast,superantispyware and malewarebytes and they find nothing

i dunno where to go from here.


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: Win32:Malware-gen created everytime i launch a program
« Reply #1 on: December 01, 2009, 07:33:49 PM »
With 8 detections on Jotti I would tend to side on the avast detection being good.

However I would suggest uploading to virustotal that has 41 scanners: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.

So what is this certain program that you are launching which generates the detected files ?

I don't really understand this "opening Livid's Union-resident protection picked it up." So is this the certain program I'm asking about ?
More importantly by 'resident protection' are you talking another antivirus/security application ?

If so then, a) having two resident scanners installed is not recommended as rather than provide twice the protection it can cause conflicts that could leave you more vulnerable or, b) avast could be detecting its unencrypted signatures or, c) files that it opens for scanning.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

erick2687

  • Guest
Re: Win32:Malware-gen created everytime i launch a program
« Reply #2 on: December 01, 2009, 07:59:27 PM »
With 8 detections on Jotti I would tend to side on the avast detection being good.

However I would suggest uploading to virustotal that has 41 scanners: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.

So what is this certain program that you are launching which generates the detected files ?

I don't really understand this "opening Livid's Union-resident protection picked it up." So is this the certain program I'm asking about ?
More importantly by 'resident protection' are you talking another antivirus/security application ?

If so then, a) having two resident scanners installed is not recommended as rather than provide twice the protection it can cause conflicts that could leave you more vulnerable or, b) avast could be detecting its unencrypted signatures or, c) files that it opens for scanning.

here are the results from virustotal
https://www.virustotal.com/analisis/c61175d548fb3284eb90e19b3336d67b1f15a7e5d44838b48d15ac671cac5671-1256963289

The program that i try to launch is called Union http://www.lividinstruments.com/software_union.php
i only have one resident scanner and it is avast

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: Win32:Malware-gen created everytime i launch a program
« Reply #3 on: December 01, 2009, 09:35:30 PM »
This is a different file to the one you uploaded to Jotti and insn't in the same file name format that you have reported before, e.g. mxe26F.tmp.
So it would have been better for comparison if that file were uploaded to VT.

Interesting that not even avast reports that file as infected on virustotal (so did your installed avast alert) ?

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

erick2687

  • Guest
Re: Win32:Malware-gen created everytime i launch a program
« Reply #4 on: December 01, 2009, 10:03:22 PM »
This is a different file to the one you uploaded to Jotti and insn't in the same file name format that you have reported before, e.g. mxe26F.tmp.
So it would have been better for comparison if that file were uploaded to VT.

Interesting that not even avast reports that file as infected on virustotal (so did your installed avast alert) ?



sorry about that! The thing is the file created is different in name each time.

here is the virustotal
https://www.virustotal.com/analisis/c61175d548fb3284eb90e19b3336d67b1f15a7e5d44838b48d15ac671cac5671-1256963289

here is the jotti
http://virusscan.jotti.org/en/scanresult/d8f4c92750093652900d464f89729b610a60e98e/b01be881bbd09cfdf8a1eb0c48581990364a3fc7

all using the same file mxe26F.tmp

micky77

  • Guest
Re: Win32:Malware-gen created everytime i launch a program
« Reply #5 on: December 01, 2009, 10:05:39 PM »
I think it is the same file, same shah ,same md5, same size, definitely same file. The date on VT is 31/10/09 send again, you will probably get ' already analyzed ' choose re-analyze

erick2687

  • Guest
Re: Win32:Malware-gen created everytime i launch a program
« Reply #6 on: December 01, 2009, 10:17:10 PM »
I think it is the same file, same shah ,same md5, same size, definitely same file. The date on VT is 31/10/09 send again, you will probably get ' already analyzed ' choose re-analyze

rescanned

virus total
https://www.virustotal.com/analisis/c61175d548fb3284eb90e19b3336d67b1f15a7e5d44838b48d15ac671cac5671-1259701885

jotti
http://virusscan.jotti.org/en/scanresult/b01be881bbd09cfdf8a1eb0c48581990364a3fc7

micky77

  • Guest
Re: Win32:Malware-gen created everytime i launch a program
« Reply #7 on: December 01, 2009, 10:29:49 PM »
 I take it you did not pay $299 for the product   ;D

Was it some crack/keygen that was used

erick2687

  • Guest
Re: Win32:Malware-gen created everytime i launch a program
« Reply #8 on: December 01, 2009, 10:49:58 PM »
I take it you did not pay $299 for the product   ;D

Was it some crack/keygen that was used

it comes free with their hardware which i did buy. =)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Win32:Malware-gen created everytime i launch a program
« Reply #9 on: December 01, 2009, 11:04:15 PM »
Hi erick2687,

Trojan.Win32.Monder.gen is generic detection of trojans that are involved in the installation of "Virtumonde" adware/spyware,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: Win32:Malware-gen created everytime i launch a program
« Reply #10 on: December 01, 2009, 11:31:21 PM »
Many of the detections are generic (including avast) this make an FP a possibility, certainly more doubt.

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and possible false positive in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already in the chest) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.

Once submitted, periodically scan the sample in the chest (every few days) and if it is no longer detected then it looks like it was an FP and has been corrected. That should hopefully resolve the detections on the temp .tmp files, normally I would suggest excluding the file/s from scans, but this is going to be difficult given the random naming issue.

Is there any settings in the program that can change the location for temp files, if so you could exclude that folder and .tmp files from being scanned, e.g. 'c:\Union_Temp\*.tmp' without the quotes, assuming you can change the default temp location for the program to Union_Temp, etc. The *.tmp bit would exclude all .tmp files using the * wildcard, care has to be taken to ensure you don't leave a big gap in security; hence the creation of a unique folder for union temp files and only excluding the .tmp file type..
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security