Author Topic: Another Win32 Trojan-gen help needed  (Read 5057 times)

0 Members and 1 Guest are viewing this topic.

jaykers

  • Guest
Another Win32 Trojan-gen help needed
« on: February 01, 2009, 09:12:32 PM »
This seems to be located in c:\systemvolumeinformation  Binary.toolbarinstaller.exe
I've tried to move to chest but an "error occured moving file to chest" and I cannot delete for the same reason.  I know this isn't enough information but if someone could direct me to read the entire line I would appreciate it & then can post more info.  Why can I not move these two files to chest?  Thanks for any assistance!

micky77

  • Guest
Re: Another Win32 Trojan-gen help needed
« Reply #1 on: February 01, 2009, 09:18:41 PM »
Turn off your system restore,reboot,turn it back on again,set a fresh restore point

http://support.microsoft.com/kb/310405

http://www.howtogeek.com/howto/windows-vista/disable-system-restore-in-windows-vista/
« Last Edit: February 01, 2009, 09:20:43 PM by micky77 »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: Another Win32 Trojan-gen help needed
« Reply #2 on: February 01, 2009, 09:25:43 PM »
Hi micky77,

You have beaten me to it, I would like to give the same advice.
System Volume Information is your system restore points folder.
To get rid of it, Flush your system restore points:
To do this, you have to disable system restore and enable it afterwards again.
(note: this will delete all your system restore points and malware (adware in this case) that were present in it).

How to disable system restore see previous posting=====
After you disabled System Restore.... Reboot.. and after rebooting, enable it again, so a new system restore point will be made. A clean one now!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89060
  • No support PMs thanks
Re: Another Win32 Trojan-gen help needed
« Reply #3 on: February 01, 2009, 09:38:47 PM »
Personally I wouldn't disable system restore to resolve a detection in one restore point as that removes ALL restore points infected or otherwise.

If you have XP, vista32bit or Win2k, you could enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, a memory scan will take place followed by the opening of the Simple User Interface, Menu, 'Schedule boot-time scan...' Or see http://www.digitalred.com/avast-boot-time.php.

You say two files I only see one ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

jaykers

  • Guest
Re: Another Win32 Trojan-gen help needed
« Reply #4 on: February 01, 2009, 10:05:17 PM »
THANK YOU!!!!!

DavidR, I had already been working on the solution that micky77 and polonus had suggested and didn't see your reply till now.  Both files, yes I had two were located in the same section.  I just completed what micky77 and polonus had posted and I'm clean!!!!  More wonderful, helpful information to record in my computer notes, I thank you all for your help!!!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89060
  • No support PMs thanks
Re: Another Win32 Trojan-gen help needed
« Reply #5 on: February 01, 2009, 11:38:32 PM »
No problem, glad I could help.

Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

baberainbow

  • Guest
Re: Another Win32 Trojan-gen help needed
« Reply #6 on: February 02, 2009, 03:06:30 PM »
This seems to be located in c:\systemvolumeinformation  Binary.toolbarinstaller.exe
I've tried to move to chest but an "error occured moving file to chest" and I cannot delete for the same reason.  I know this isn't enough information but if someone could direct me to read the entire line I would appreciate it & then can post more info.  Why can I not move these two files to chest?  Thanks for any assistance!

I have just found exactly the same two trojan.gen(other) viruses seemingly in the same restore file c:\system volumeinformation\_restore{then the numbers}\RP78A0010689.msi\Binary.Toolbarinstaller.exeand as above these could not be moved to the virus chest with the Avast error "Error occurred during moving fule to chest.  What is the reason that Avast cannot move a file to the virus chest?  The only "toolbar" I have downloaded in the last two days is McAfee Siteadvisor - I wonder if Jaykers has downloaded the same?  Not sure where else this could have come from?

baberainbow

  • Guest
Re: Another Win32 Trojan-gen help needed
« Reply #7 on: February 02, 2009, 03:24:23 PM »
Personally I wouldn't disable system restore to resolve a detection in one restore point as that removes ALL restore points infected or otherwise.

If you have XP, vista32bit or Win2k, you could enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, a memory scan will take place followed by the opening of the Simple User Interface, Menu, 'Schedule boot-time scan...' Or see http://www.digitalred.com/avast-boot-time.php.

You say two files I only see one ?


I don't quite understand how, by doing a boot-time scan, it would clear the two viruses from the system?  If Avast could not put the viruses into its virus chest during the first scan when the viruses were found.  How would it help by doing this with a boot-scan? 

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89060
  • No support PMs thanks
Re: Another Win32 Trojan-gen help needed
« Reply #8 on: February 02, 2009, 03:51:10 PM »
Because of your comment:
Quote from: baberainbow
I've tried to move to chest but an "error occured moving file to chest" and I cannot delete for the same reason.

This is commonly protection by system restore or the OS, this protection won't be present if windows isn't running, e.g. when the boot-time scan runs before windows us fully up and running.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

AMA

  • Guest
Win32 Trojan-gen. I also need help!
« Reply #9 on: February 02, 2009, 06:59:34 PM »
Gentleman  Help!

After running a scan. Avast! detected the following files with an “Infection win32: Trojan-gen (other)” Result.
C:\system volume information\...\binary toolbarinstaller.exe
C:\program files\google\...binary\toolbar installerinstaller.exe
C:\Windows\installer\...\binary.toolbarinstaller.exe

 I could not delete, move or repair them.  I got the following error msg:
“error occurred during deleting/move/renaming: this operation not supported for this type of archive”.

I’m running XP. Should I follow the same suggestion given by micky7 and DavidR?  I’m a novice at this so your help would really be appreciated.

Thank you

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89060
  • No support PMs thanks
Re: Another Win32 Trojan-gen help needed
« Reply #10 on: February 02, 2009, 07:40:45 PM »
I would suggest you start with the lessor of the two, e.g. a boot-time scan so that good restore points aren't lost. The other option is a fall-back if the boot-time scan can't take care of it.

The ones outside the system volume information folder may still experience the same problem as what your path doesn't show is the \...\ bit which is likely to show it is in an archive that avast can't extract from. I believe I have seen this in another topic and you may have to manually remove then.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

AMA

  • Guest
Re: Another Win32 Trojan-gen help needed
« Reply #11 on: February 03, 2009, 04:29:18 AM »
DavidR,

Option one worked great. Thank you so much for your  expert help.  I really really appreciated it.
Happy to be part of the forum.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89060
  • No support PMs thanks
Re: Another Win32 Trojan-gen help needed
« Reply #12 on: February 03, 2009, 03:14:44 PM »
No problem, glad I could help.

Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security