Author Topic: Win32:Maleware-gen Help?  (Read 13727 times)

0 Members and 1 Guest are viewing this topic.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Win32:Maleware-gen Help?
« Reply #15 on: July 09, 2010, 07:31:01 PM »
deleted

« Last Edit: July 10, 2010, 02:34:52 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Bandaids

  • Guest
Re: Win32:Maleware-gen Help?
« Reply #16 on: July 09, 2010, 07:32:31 PM »
I believe the file has regenerated.
I have attached the report OTM produced in this post.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Win32:Maleware-gen Help?
« Reply #17 on: July 09, 2010, 07:45:07 PM »
okay

is it still regenerating?
does everything seem to be running okay?

use ccleaner to clear the temporary internet cache  http://www.piriform.com/ccleaner

also make sure that Windows is always kept up to date  - you may have a necessary security update missing

Microsoft report
- http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanDownloader:Win32/Renos.KF
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Bandaids

  • Guest
Re: Win32:Maleware-gen Help?
« Reply #18 on: July 09, 2010, 07:56:51 PM »
I believe the file is still regenerating as the value is still appearing in HijackThis.
I have fix checked it again, just to make sure.
But after i immediately redo the scan, the file shows up again.

Also it seems that 'gpr.exe' cannot be found in my Temp Folder.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Win32:Maleware-gen Help?
« Reply #19 on: July 09, 2010, 08:04:26 PM »
make sure that you are disconnected from the internet

boot into Safe Mode
- turn computer off
- lightly tap F8 key as computer is turned on
- this should take you to page with Safe Mode option (you may first be asked what to boot - choose yr hard drive)

run HijackThis in Safe Mode and you should be able to remove the entry

then see how doing
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: Win32:Maleware-gen Help?
« Reply #20 on: July 09, 2010, 08:19:27 PM »
Use hijack free to kill the processhttp://www.hijackfree.de/en/hijackfree/
Then boot into safe mode
run ->cmd
Quote
taskkill /f /im gpr.exe
attrib -h -s -r c:\windows\temp\gpr.exe
del c:\windows\temp\gpr.exe
then disable the malware entry in registry by regedit or by msconfig.exe ->startups
Dreams don't die, they just fall asleep.

Bandaids

  • Guest
Re: Win32:Maleware-gen Help?
« Reply #21 on: July 09, 2010, 08:25:45 PM »
as Mkis suggested.

I booted into safe mode and fix checked the gpr.exe processes using HijackThis.
Seems like they did not respawn after this.

Right now i'm doing a scan with MalwareBytes.

and is it better if i also did what superhacker said just to make sure?

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: Win32:Maleware-gen Help?
« Reply #22 on: July 09, 2010, 08:36:49 PM »
Yes it is better to ensure the malware removed completely
Dreams don't die, they just fall asleep.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Win32:Maleware-gen Help?
« Reply #23 on: July 09, 2010, 09:09:25 PM »
it is okay in this case seems a good procedure to run - especially if the malware did re-appear

I am not familiar with the procedure but I cant see anything untoward
another forum member may provide second opinion
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Bandaids

  • Guest
Re: Win32:Maleware-gen Help?
« Reply #24 on: July 09, 2010, 09:31:55 PM »
@superhacker

sorry im kind of new to all of this.
so can you please elaborate how i can disable the malware entry via regedit?

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Win32:Maleware-gen Help?
« Reply #25 on: July 10, 2010, 12:26:25 AM »
are you still having problems Bandaids?

I meant I was unfamiliar with the Superhacker procedure but it all read good

This is how you disable the malware entry via regedit
- you go to the registry via regedit by click Start, go to Run, type in regedit and click OK
- you search in registry by open Edit on toolbar and choose Find from the dropdown menu - and type gpr.exe in the box, and press Enter

If you find an entry which is obviously the malware, then delete it - and press F3 to search for the next instance of the malware

And CAREFUL with editing in the Registry - reply post here before you do it, if you want
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Bandaids

  • Guest
Re: Win32:Maleware-gen Help?
« Reply #26 on: July 10, 2010, 07:46:03 AM »
Thank you mkis.

When i was searching the registry for gpr.exe, nothing was found.
Does that mean it does not exist in the registry?

and since i have removed the virus.
is there a way to make sure its gone and should i remove it from avast virus chest?

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Win32:Maleware-gen Help?
« Reply #27 on: July 10, 2010, 08:09:07 AM »
well, normal running is the test - how are you doing?

you seemed adequately computer competent to carry out tasks to deal with any common problems
keep an eye in things - and this page directs towards how to ensure  yr system is kept clean of this malware

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanDownloader:Win32/Renos.KF#prevention_link

if files are in the chest you are protected from them
if you can provide a screen shot of what is in the chest, I can give you a further reply on that.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Bandaids

  • Guest
Re: Win32:Maleware-gen Help?
« Reply #28 on: July 10, 2010, 08:23:06 AM »
i have attached the screenshot in this post.

These files were all found before i posted on this forum for help.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Win32:Maleware-gen Help?
« Reply #29 on: July 10, 2010, 10:05:14 AM »
they look genuine enough to delete

but you can leave off for a couple of weeks in case there is more malware work to do.
and concentrate now in making sure you tune yr system back to good running and keep an eye out for any problem areas, and if running satisfactorily cpme back in a few weeks and clear out yr chest.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.