Author Topic: win32:malware gen assistance please  (Read 6892 times)

0 Members and 1 Guest are viewing this topic.

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
win32:malware gen assistance please
« on: March 10, 2013, 03:02:14 PM »
My avast shows me as having this virus, any help in removing it would be truly appreciated.  attached is the adwcleaner log.

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #1 on: March 10, 2013, 03:03:14 PM »
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Database version: v2013.03.10.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Compaq_Owner :: ORION [administrator]

3/10/2013 9:41:44 AM
mbam-log-2013-03-10 (09-41-44).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 205030
Time elapsed: 15 minute(s), 55 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer\control panel|Homepage (PUM.Hijack.HomePageControl) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: win32:malware gen assistance please
« Reply #2 on: March 10, 2013, 03:06:38 PM »
we also need OTL and aswMBR logs

http://forum.avast.com/index.php?topic=53253.0

« Last Edit: March 10, 2013, 03:10:17 PM by Pondus »

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #3 on: March 10, 2013, 03:08:57 PM »
sorry working on those as we speak.  I didnt know if you wanted them all at once or not...so i posted them as i do them.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: win32:malware gen assistance please
« Reply #4 on: March 10, 2013, 03:11:22 PM »
sorry working on those as we speak.  I didnt know if you wanted them all at once or not...so i posted them as i do them.
that is fine   ;)


and any info on the file avast detected
file name?
location....full file path?

malware removers are notified, it may take hours before thay arrive so be patient


Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #5 on: March 10, 2013, 03:28:09 PM »
heres a few screen shots of scan logs from avast.  as well as the otl log. 

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #6 on: March 10, 2013, 03:33:42 PM »
with the aswmbr program Should i click fix after.....or just post the log and wait?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:malware gen assistance please
« Reply #7 on: March 10, 2013, 04:10:04 PM »
Do not press fix on aswMBR unless we need to change the MBR so the log will do for the moment

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #8 on: March 10, 2013, 04:24:22 PM »
heres the aswmbr scan log

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:malware gen assistance please
« Reply #9 on: March 10, 2013, 04:28:14 PM »
If I could have the OTL log we will then start

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #10 on: March 10, 2013, 04:32:01 PM »
the otl log is posted about 4 posts up with the 2 jpeg screen caps.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:malware gen assistance please
« Reply #11 on: March 10, 2013, 04:40:19 PM »
It appears that Avast is reporting the recovery portions of your computer for some reason. To me they appear legitimate 

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:OTL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Accelerator Plugin) - {656EC4B7-072B-4698-B504-2A414C1F0037} - Reg Error: Value error. File not found
O3 - HKU\S-1-5-21-2628011366-3451951904-1772102454-1009\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-2628011366-3451951904-1772102454-1009\..\Toolbar\WebBrowser: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - No CLSID value found.
[2013/02/24 14:53:21 | 000,373,248 | ---- | M] () -- C:\WINDOWS\EyeCand3.INI

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #12 on: March 10, 2013, 04:58:50 PM »
this log popped up when I ran the otl fix and reboot. 

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:malware gen assistance please
« Reply #13 on: March 10, 2013, 05:12:30 PM »
Is Avast still reporting those files ? Also how is the computer behaving

Offline omegaluke

  • Jr. Member
  • **
  • Posts: 35
Re: win32:malware gen assistance please
« Reply #14 on: March 10, 2013, 05:15:28 PM »
this is the quick scan log for otl (after the fix and reboot).  Computer seems to be running ok, ill have to run avast again to see if it shows any infections.