Author Topic: What do I do? Malware  (Read 11586 times)

0 Members and 1 Guest are viewing this topic.

Tiggie

  • Guest
What do I do? Malware
« on: December 08, 2012, 06:09:54 PM »
My system is XP Windows home edition sp2.Compact presario AMD Processor.
I have done a full scan with Avast and sent a high threat to the Chest.
The threat is as follows; Win32Malware-gen  File name is D:\...\A00093532.sys .Please how do I deal with this?
Your help would be dearly appreciated, I am not really computer savvy.
Thankyou
Tiggie.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: What do I do? Malware
« Reply #1 on: December 08, 2012, 06:17:31 PM »
you already have.....you sendt it to chest

Offline DJBone

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6366
Re: What do I do? Malware
« Reply #2 on: December 08, 2012, 06:30:58 PM »
And you should also update your WinXP to SP3 to receive security updates!

DJBone
Win10 x64, APS (always latest version)
Avast Mobile Security (always latest version)

Offline chris..

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2931
Re: What do I do? Malware
« Reply #3 on: December 08, 2012, 06:47:45 PM »
File name is D:\...\A00093532.sys
Is this file in d:\system volume information ?
To my mind it's tcpip.sys from restauration point.

Tiggie

  • Guest
Re: What do I do? Malware
« Reply #4 on: December 08, 2012, 07:07:58 PM »
Thankyou, Pondus and DJ Bone, yes its safe in the chest but should I delete it or is it a file which is needed , if so how can one clean it?
I wanted SP3 but when I tried to install it I was told I had not got the resources .
I must mention I recently downloaded Opera and Safari, but took Safari off today after reading it was known to not be secure as other browsers. I wonder if that is how I got the malware.
I also have on my pc Superanti spyware. I use windows firewall.
Chris05
Thankyou too . I don,t know if this file is d\system volume information.I just copied out what Avast showed me.Is there a way I can find out?
Tiggie

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: What do I do? Malware
« Reply #5 on: December 08, 2012, 07:14:02 PM »
I wanted SP3 but when I tried to install it I was told I had not got the resources .

That's not possible, if your current XP install is legit.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Tiggie

  • Guest
Re: What do I do? Malware
« Reply #6 on: December 08, 2012, 07:49:47 PM »
Asyn, Thankyou.
Yes my version of xp windows will be legit as I bought it from Currys.
Tiggie
 

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: What do I do? Malware
« Reply #7 on: December 08, 2012, 07:53:45 PM »
Yes my version of xp windows will be legit as I bought it from Currys.

No idea who 'Currys' is..!!?? But if your XP is legit you should update to SP3 ASAP..!!!
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Tiggie

  • Guest
Re: What do I do? Malware
« Reply #8 on: December 08, 2012, 08:45:17 PM »
Chris 05
Chris you are right, I have just seen inside the avast virus chest and see A0093532.sys that the original location is  D:\System Volume information\_restore\D Last changed 25.07.2001.
I see three more infected files in the chest   Killit.exe  original location  C:\hp\bin  last changed 16.9.1999.
ProcessLogger.exe original location C:\hp\bin last changed 24.01.2003
tcpip.sys  original location  D:\MiniNT\system32\drivers.
This p.c is a hewlett packard.
Can I be helped please.?
Tiggie

TheHulk

  • Guest
Re: What do I do? Malware
« Reply #9 on: December 08, 2012, 08:48:25 PM »
just clean windows restore points from disk cleanup that will remove it off

Offline chris..

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2931
Re: What do I do? Malware
« Reply #10 on: December 08, 2012, 09:00:04 PM »
I don,t know if this file is d\system volume information.I just copied out what Avast showed me.Is there a way I can find out?

You can see more about "\...\" avast showed you in your "virus chest" information.

As I had issue yesterday with "tcpip.sys" avast showed me 3 "A000xxxx.sys" Win32Malware-gen corresponding "tcpip.sys" from my 3 restored points.

So be careful before to let avast to delete this file.

Of course it's strange you can't update SP3 even if I don't think it's the cause of the malware (if it's really a malware)
Maybe you'll have to test with malwarebytes to be sure...

Edit sorry for this post a little late  :-[
yes you can clean old windows restore point
« Last Edit: December 08, 2012, 09:04:43 PM by chris05 »

Offline DJBone

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6366
Re: What do I do? Malware
« Reply #11 on: December 08, 2012, 09:04:02 PM »
To be sure you haven't any further malware on your system follow this guide and attach the logs: http://forum.avast.com/index.php?topic=53253.0
A malware specialist will help you if you're infected.

DJBone
« Last Edit: December 08, 2012, 09:12:30 PM by DJBone »
Win10 x64, APS (always latest version)
Avast Mobile Security (always latest version)

Tiggie

  • Guest
Re: What do I do? Malware
« Reply #12 on: December 08, 2012, 09:56:32 PM »
The Hulk thankyou,
I have looked at disk cleanup and presume its under"Remove Restore Points " would I be right? and I would need to click on restore from the avast chest  before doing the disk cleanup.
Please have you any advice on the other things in the virus chest?
Tiggie

Tiggie

  • Guest
Re: What do I do? Malware
« Reply #13 on: December 08, 2012, 10:05:50 PM »
Chris05 what did you do with this same problem.
I will download Malwarebytes. and have another go at downloading sp3 especially after doing disk cleanup.

Tiggie

Tiggie

  • Guest
Re: What do I do? Malware
« Reply #14 on: December 08, 2012, 10:22:17 PM »
DJ Bone, I will do as you suggest. I  have been lucky over the last 10 years, happily sailing along, but now sp2 is not supported along with an older system I suppose anything can happen.
I am told that I need to take off IE8 ,delete ? if I am to try to get sp3 on once again.
Tiggie