Author Topic: Avast found Win32: trojan-gen  (Read 19404 times)

0 Members and 1 Guest are viewing this topic.

yod12

  • Guest
Avast found Win32: trojan-gen
« on: August 04, 2008, 06:48:40 PM »
One of my computers found three instances of  Win32: trojan-gen. I have no idea how it got there. In 15 years of computing, I've never got a hint of a virus except an attempted trojan 3 years ago.

Avast found them and there's not much of a clue as to what to do. Delete, Repair, and Send to Chest are the options with a VERY brief description. Any more input about this?

Offline Justin_22

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 445
  • Free your soul and let it fly
Re: Avast found Win32: trojan-gen
« Reply #1 on: August 04, 2008, 06:51:45 PM »
The -gen indicates a generic detection which can sometimes cause false positives
Where are the files? if they are in the chest you will need to extract them to a temporary folder (not the original location) to do this 
If they are still in the original location please upload the files to www.virustotal.com and post the results here
Avast!  2014 beta - Sandboxie - K9 Web Protection

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast found Win32: trojan-gen
« Reply #2 on: August 04, 2008, 08:29:32 PM »
To know if a file is a false positive, please submit it to VirusTotal and let us know the result. If it is indeed a false positive, send it in a password protected zip to virus@avast.com. VirusTotal has a file size limit of 10Mb. Please, mention in the body of the message why you think it is a false positive and the password used. Thanks.

Maybe you need to disable Hide protected operating system files and enable View hidden files and folders to manage the file(s).

As a workaround, you can add these files to the Standard Shield provider (on-access scanning) exclusion list.
Left click the 'a' blue icon, click on the provider icon at left and then Customize. Go to Advanced tab and click on Add button...
You can use wildcards like * and ?. But be careful, you should 'exclude' that many files that let your system in danger.
The best things in life are free.

yod12

  • Guest
Re: Avast found Win32: trojan-gen
« Reply #3 on: August 04, 2008, 10:52:57 PM »
Thanks,
I REALLY don't have time for this. But I put the files in the Chest. They're on another computer - I'd rather not use it until this is taken care of. Can you tell me how I would do this?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast found Win32: trojan-gen
« Reply #4 on: August 04, 2008, 11:45:28 PM »
I REALLY don't have time for this. But I put the files in the Chest. They're on another computer - I'd rather not use it until this is taken care of. Can you tell me how I would do this?
Can you rephrase? What exactly do you want to do?
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Avast found Win32: trojan-gen
« Reply #5 on: August 05, 2008, 01:11:11 AM »
Thanks,
I REALLY don't have time for this. But I put the files in the Chest. They're on another computer - I'd rather not use it until this is taken care of. Can you tell me how I would do this?

If you don't have time to confirm by analysis at virustotal (assuming this is what you are talking about), and post the results, then we are unlikely to be able to offer any advice on how to take care of the unknown.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder. Right click on the file in the Infected Files section of the chest and select Extract, from the pop-up navigate to the suspect folder, this will make a copy of the file/s you select in the c:\suspect folder.

Upload to VirusTotal - Multi engine on-line virus scanner and report the findings of these files here.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast found Win32: trojan-gen
« Reply #6 on: August 05, 2008, 01:20:46 AM »
Hi yod12,

Well I have to fully agree with DavidR here. We cannot turn magic out of the blue if we have not a clue. If you have no access to that computer and informing on behalf of a third party, we need to have some more data because generic findings are really generic you see. If they are in the chest they cannot harm the user. To give advice, we need the VirusTotal scan results for the affected files, and a hijackthis log attached as a txt file would also be helpful,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

CharleyO

  • Guest
Re: Avast found Win32: trojan-gen
« Reply #7 on: August 05, 2008, 02:42:10 AM »
***

I will echo David amd Polonus in that for us to help you, you must help us with the needed information. Only you have access to the problem and we must rely on you to provide us with the clues in order for us to become the detectives.


***

yod12

  • Guest
Re: Avast found Win32: trojan-gen
« Reply #8 on: August 05, 2008, 07:36:24 AM »
Thank you all very much! Much of this is Greek to me (pardon to any Greeks, it's a colloquial expression). I'm trying to decipher what David's saying... So I can create a folder in the C:\ drive. Sorry, I have no idea what you mean by excluding it in the S Sheild, etc. I think I follow you about exporting them (one by one?) to that folder. I guess I can't just drag it to that folder? I imagine I may be able to figure out how to upload it. Again, I thank you all very much. Sorry I wasn't that clear in my previous post.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder. Right click on the file in the Infected Files section of the chest and select Extract, from the pop-up navigate to the suspect folder, this will make a copy of the file/s you select in the c:\suspect folder.

Upload to VirusTotal - Multi engine on-line virus scanner and report the findings of these files here.

[/quote]

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Avast found Win32: trojan-gen
« Reply #9 on: August 05, 2008, 03:03:42 PM »
You need to customise the standard shield provider to add exclusions.

Left click the avast icon and you should get a pop-up of the avast shields/providers, if you see a button called Details... >> click that and it will give a more detailed view, select the Standard Shield.

Now you are at the start point of my instruction on how to add an exclusion.
You will see a Customize button, click that.
You will see a number of Tabs, click the Advanced one.
Click the Add button, that will allow you to create a new exclusion.
Type or copy and paste the exclusion C:\Suspect\*, click OK.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

yod12

  • Guest
Re: Avast found Win32: trojan-gen
« Reply #10 on: August 05, 2008, 11:17:05 PM »
I'll see if I can figure this out. I really appreciate your help. Someone over at CNET said that I have to restore the virus to its original location if I put it in the Chest. Is that right?

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Avast found Win32: trojan-gen
« Reply #11 on: August 05, 2008, 11:28:55 PM »
I have no idea of what was said at CNet or why, but here is the place to get avast related help. The worst possible place to put it would be the original location, as if it is a piece of malware then it would be active.

By Extracting it to a different location, even if it were malware it isn't active as any commands to run it in the original location wouldn't work in the temporary location.

That is why I told you to create the temporary location, c:\suspect folder and why you should exclude that folder so you can upload it to virustotal without avast alerting. This is the only way you can confirm if the detection is good or false.

I would recommend you don't waste your time at CNet as clearly they don't know what is going on. If you have any questions ask them here, where more people than you can shake a stick at (well 5 of them) are jostling to help you.

The one and only time it will be sent to its original location (restored) is if an when it is confirmed as a false positive detection and this hasn't been done.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

yod12

  • Guest
Re: Avast found Win32: trojan-gen
« Reply #12 on: August 06, 2008, 08:16:49 AM »
So I create a 'suspect' folder and export these puppies in there. From looking quickly at the virustotal site, there's only an option to upload them (one by one?). Does it scan these files right away? Do I get a response? Are the results posted somewhere? What do I do with these things that are sitting in a 'suspect' folder in the meantime? Is it the same as the Avast Chest?
Thank you for you patient guidance. I really appreciate it!

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Avast found Win32: trojan-gen
« Reply #13 on: August 06, 2008, 03:07:26 PM »
Yes you can only upload one at a time and they are scanned then (there may be a queue) and the results are displayed to the screen.

There is an option to email samples for analysis (you will have to check out the site for that I've never used it), I don't know if this would allow for sending multiple samples and the respons would come by email.

Leave them in the suspect folder until the situation is resolved, the same is true of the copy in the chest.

There is no rush to delete anything from the chest, a protected area where it can do no harm. Anything that you send to the chest you should leave there for a few weeks. If after that time you have suffered no adverse effects from moving these to the chest, scan them again (inside the chest) and if they are still detected as viruses, delete them.
« Last Edit: August 06, 2008, 03:09:04 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

yod12

  • Guest
Re: Avast found Win32: trojan-gen
« Reply #14 on: August 08, 2008, 12:45:50 AM »
Thanks David,

So I uploaded one of the files to virustotal. It scanned and displayed the reults as in a record. What do I do/how do I display the results here or anywhere else. I don't know what most of this stuff means.