Author Topic: Win32:Malware-gen  (Read 100733 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: Win32:Malware-gen
« Reply #15 on: January 24, 2015, 07:56:27 PM »
Had tried for days at a forum and I got that command, when used in ComboFix began those mistakes and returned with a backup.

Examination with VirusTotal:

SHA256:   6a20b9a886eb106fd1126d29743dcc68b480957f038bc59082973703adbde332
Nombre:   FirewallAPI.dll
Detecciones:   17 / 57
Fecha de análisis:   2015-01-24 18:55:34 UTC ( hace 0 minutos )

Link: https://www.virustotal.com/es/file/6a20b9a886eb106fd1126d29743dcc68b480957f038bc59082973703adbde332/analysis/1422125734/

They helped me but it did not help because Windows gave me those errors
No internet access or programs = perform backup
« Last Edit: January 24, 2015, 08:00:26 PM by Agustín3 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #16 on: January 24, 2015, 08:33:35 PM »
OK I am now unsure as to what they have done,  Do you have a link to your thread on the forum so that I can have a look

REDACTED

  • Guest
Re: Win32:Malware-gen
« Reply #17 on: January 24, 2015, 10:24:25 PM »
Remember this in Spanish
Link: http://www.forospyware.com/t500883.html

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #18 on: January 24, 2015, 11:31:11 PM »
Are you still getting alerts on the firewall api ? 

Why did he switch the user32 dll

REDACTED

  • Guest
Re: Win32:Malware-gen
« Reply #19 on: January 25, 2015, 12:55:52 AM »
Yes. When they helped me, could not run programs or connect to the internet, so I did a system restore, ie the help they gave me worked, but because of those mistakes, I made the restoration and is like nothing that happened.

REDACTED

  • Guest
Re: Win32:Malware-gen
« Reply #20 on: January 25, 2015, 06:18:21 AM »
@essexboy

Let's see how I resume Agustin's issue.

He was having problems with freeze videos and everytime he opened files .AVI o .WAV Avast FSS was giving him this alert: http://imgur.com/8vw0PTR

He could not open Windows Accion Center to get to Windows Firewall. He said he installed Spy Hunter trying to solve the problem so the specialist said that SpyHunter needed to be uninstalled and find out why Avast was detecting FirewallAPI.dll.

After ComboFix was run the specialist told him to uninstalled Panda because he was running 2 AV. He also told him to uninstalled SpyBot and MBAM for the moment, and to run the ComboFix script he left for him. http://www.forospyware.com/t500883-2.html#post2402392

Then Agustin explained that Spybot and MBAM were uninstalled but not properly so he decided to installed them again to run their respective removal tools.

Here comes the problem that even I am not sure how to tell. Agustin installed the programs and then uninstalled them with Appremover. Then ran the ComboFix script but left him without Internet connection so he decided to restore the system to before all repairs were done. So he is back to where he started with the Avast alerts, Panda in his system and Spybot and MBAM badly uninstalled.

BTW nowhere it says why Leosolari gave the script to switch the user32 dll. Also it seems Leosolari got a bit upset because Agustin did not follow the instructions.

I think you have to start from scratch, essexboy.

REDACTED

  • Guest
Re: Win32:Malware-gen
« Reply #21 on: January 25, 2015, 07:36:52 AM »
My question is, where I did not follow the instructions? :S
« Last Edit: January 25, 2015, 08:36:53 AM by Agustín3 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #22 on: January 25, 2015, 01:16:21 PM »
OK lets see what AswMBR finds

Download aswMBR.exe ( 4.5mb ) to your desktop.
Double click the aswMBR.exe to run it.
You may be offered the option of using virtualisation, accept that
When it offers to download the virus database allow that as well
Click the "Scan" button to start scan




On completion of the scan click save log, save it to your desktop and post in your next reply