Author Topic: Win32:Malware-gen  (Read 31178 times)

0 Members and 1 Guest are viewing this topic.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89640
  • No support PMs thanks
Re: Win32:Malware-gen
« Reply #15 on: April 05, 2010, 04:52:50 PM »
No, what I would like you to do is a check that the TDSSKiller detection was good.

Check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.

The reason I suggest this is that the TDSSKiller that was suggested is looking for a specific type of rootkit and I don't know much about it or its effectiveness or its accuracy. As I implied if this were truly a rootkit, in theory the windows explorer interface shouldn't find it. Since it did we have the opportunity to confirm the detection or otherwise.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.870) UI 1.0.818/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89640
  • No support PMs thanks
Re: Win32:Malware-gen
« Reply #16 on: April 05, 2010, 04:56:20 PM »
Also found this, if it is of any interest.

Yes that is of interest, I'm no hardware specialist either ;D
However, I would Imagine that any Raid driver would have to be operating at a very low level indeed; so I don't know if that might well have confused TDSSKiller or not, which is why the confirmation scan at virustotal would be worthwhile.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.870) UI 1.0.818/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

elle_97

  • Guest
Re: Win32:Malware-gen
« Reply #17 on: April 05, 2010, 04:57:49 PM »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #18 on: April 05, 2010, 05:12:21 PM »
Hi I have just had a look at the TDSSkiller logs and it appears you had multiple files infected

Also looking at the OTL there are a lot of miscreants there as well

Unfortunately you saved the TDSS logs as Unicode instead of ANSI so they were difficult to read

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.

elle_97

  • Guest
Re: Win32:Malware-gen
« Reply #19 on: April 05, 2010, 05:57:04 PM »
Is there a chance the log is named something other than ComboFix? My computer searched but with zero result.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89640
  • No support PMs thanks
Re: Win32:Malware-gen
« Reply #20 on: April 05, 2010, 06:22:08 PM »
Eh, I hope this is what you were asking for:  :-[

http://www.virustotal.com/reanalisis.html?ca40f7d5669d86f03152c84591e9d7b50f4de0dd77ed3818aa340e439d8d7bdb-1270479335

Almost, this is the one, http://www.virustotal.com/analisis/ca40f7d5669d86f03152c84591e9d7b50f4de0dd77ed3818aa340e439d8d7bdb-1270479335. This shows that no 'conventional' anti-virus scanner detects anything, which is what I suspected.

Now that essexboy is on the case hopefully he has the tools to analyse the problem and bring it to a successful conclusion.

Is there a chance the log is named something other than ComboFix? My computer searched but with zero result.

The file should be as named in the C:\ root directory.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free  24.8.6127 (build 24.8.9372.870) UI 1.0.818/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

elle_97

  • Guest
Re: Win32:Malware-gen
« Reply #21 on: April 05, 2010, 06:38:54 PM »
Sorry about that, have attached the log.


Edit:
Quote
Unfortunately you saved the TDSS logs as Unicode instead of ANSI so they were difficult to read

How do I change that? Thought it was done automatically.
« Last Edit: April 05, 2010, 06:43:47 PM by elle_97 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #22 on: April 05, 2010, 07:32:31 PM »
No problem on that David gave me a link to a nifty little programme - I can read it now  ;D

OK TDSS was successful and replaced one file with a good copy, then deleted the rootkit.  Combofix took out all the other malware.

What problems are you experiencing at the moment ?

elle_97

  • Guest
Re: Win32:Malware-gen
« Reply #23 on: April 05, 2010, 08:08:59 PM »
Just got a warning from Avast!

Malware was found in:
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BA9F4A2F-E990-4D4A-9024-E38A6921616B}\RP233\A0129976.SYS

Name: Win32:Agent-PSI (Rtk)
Rootkit


Thank you guys so much for all your help! It's really appreciated!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #24 on: April 05, 2010, 08:11:32 PM »
That is in system restore - so lets kill it

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done
Any further problems ?

elle_97

  • Guest
Re: Win32:Malware-gen
« Reply #25 on: April 05, 2010, 08:13:18 PM »
Well I never did anything with the last warning, should I send the malware to the chest?
Sorry to be such a dumb newbie, but I don't feel like messing up the work so far

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #26 on: April 05, 2010, 08:14:19 PM »
No need just clear the restore point as above

elle_97

  • Guest
Re: Win32:Malware-gen
« Reply #27 on: April 05, 2010, 08:18:30 PM »
I guess I don't have any other problems (yet)  :-\
Although, I find it strange that I had a problem with old restore points, when I didn't have any.

Thank you so much!  :)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #28 on: April 05, 2010, 08:23:59 PM »
Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself.

elle_97

  • Guest
Re: Win32:Malware-gen
« Reply #29 on: April 05, 2010, 08:26:21 PM »
Great!
Thank you :)