Author Topic: Win32:Malware-gen  (Read 11008 times)

0 Members and 1 Guest are viewing this topic.

Offline exmachina00

  • Newbie
  • *
  • Posts: 10
Win32:Malware-gen
« on: November 17, 2010, 12:59:55 AM »
Hello, extremely helpful and patient avast! forum staff!

I've been dealing with a persistent infection or attempted infection by Win32:Malware-gen since 10/24/10. While I dismissed it as an irritant for almost a month, I've gotten to the point where I'm both worried about it and tired of dealing with it.

Whenever I boot my computer each morning, I get a notice from avast! about a detected threat, which is usually a gibberish .exe name that has attempted to infect vbc.exe in C:\Windows\winsxs.

I've run avast! and gotten numerous hits, but it didn't seem to solve the problem. I've also run Malwarebytes, which was unable to find any source.

Enclosed are the logs from both Malwarebytes and OTL. Please let me know if I need to provide further information or take further steps to assist with the diagnosis.

Thank you in advance for your help and time.

EDIT: The virus' actual target appears to be vbc.exe in some Microsoft.NET folder, but avast!'s warning closed too quickly for me to write it down properly and there doesn't seem to be any log of it.
« Last Edit: November 17, 2010, 01:10:45 AM by exmachina00 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Win32:Malware-gen
« Reply #1 on: November 17, 2010, 09:58:05 AM »
Quote
but avast!'s warning closed too quickly for me to write it down
if you right click the orange ball down by the clock. There is an option: show last popup message


Essexboy have been notified, and will look at the log`s when he arrives

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Win32:Malware-gen
« Reply #2 on: November 17, 2010, 05:09:32 PM »
i would suggest you try superantispyware as an second opion sometimes it detcets things malwarebytes misses and vice verse

http://www.superantispyware.com/

have you update malwarebytes before scanning? for usually malwarebytes usually is good with dealing with those kind of infections.
good luck
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #3 on: November 17, 2010, 09:08:57 PM »
Hmm this is a mystery as there is no apparent malware showing

But lets dig a bit deeper

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window:
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again


  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the "Advanced System Analysis with Malware removal mode enabled " check box.

  • Click on the “Execute selected scripts”.
  • Automatic scanning, healing and system check will be executed.
  • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
  • It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
  • All applications will work properly after the system restart.
When restarted

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Analysis " check box.

  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.
Attach both virusinfo_syscure.zip and virusinfo_syscheck.zip to your next post

Offline exmachina00

  • Newbie
  • *
  • Posts: 10
Re: Win32:Malware-gen
« Reply #4 on: January 09, 2011, 07:23:40 PM »
My apologies; I went away for the holidays and neglected to check this topic.

I tried clicking the avz4 link and it resulted in a 404 message. Is there somewhere else I can download this utility?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #5 on: January 09, 2011, 08:24:06 PM »
Yep it was pulled and integrated into the standalone AV  a few days ago
New destructions

Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named )

First we will run a virus scan

On the first tab select all elements down to Computer and then select start scan
Once it has finished select report and post that.



Do not close AVPTool or it will self uninstall, if it does uninstall - then just rerun the setup file on your desktop

Now an analysis scan

Select the Manual Disinfection tab
Press the Gather System Information button
Once done Open the last report saved folder  then attach the zip file to your next post zip or upload to Mediafire and post the sharing link.
The file is located at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip



Offline exmachina00

  • Newbie
  • *
  • Posts: 10
Re: Win32:Malware-gen
« Reply #6 on: January 11, 2011, 12:56:05 AM »
The report is attached.

The sysinfo zip is here: http://www.mediafire.com/?99lbmenanb91w97

Thanks for the help!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #7 on: January 11, 2011, 03:53:44 PM »
That killed a couple in the java cahce but that is all

Is Avast still reporting malware ?


Offline exmachina00

  • Newbie
  • *
  • Posts: 10
Re: Win32:Malware-gen
« Reply #8 on: January 12, 2011, 02:52:13 AM »
Hm, not yet. I'll keep a lookout over the next few days to see.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #9 on: January 12, 2011, 03:59:13 PM »
When you are happy let me know and I will remove my tools

Offline exmachina00

  • Newbie
  • *
  • Posts: 10
Re: Win32:Malware-gen
« Reply #10 on: January 13, 2011, 06:03:22 PM »
I'm still getting the popup.

Object: C:\Users\Will\AppData\Local\Temp\l6edsxoj.exe (this changes; it's always some random combination of letters and numbers)
Infection: Win32:Malware-gen
Action: Moved to chest
Process: C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #11 on: January 13, 2011, 08:34:11 PM »
Being in your temporary file would lead me to suspect it is coming from online as opposed to your system

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89679
  • No support PMs thanks
Re: Win32:Malware-gen
« Reply #12 on: January 13, 2011, 08:58:05 PM »
Yes, but the Process responsible for that file in temp appears to be .net related (vbc.exe) unless that file and .net version are bogus.

So something is using .net framework v2...\vbc.exe and that has placed that file in temp, surely that all can't be happening from outside ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Malware-gen
« Reply #13 on: January 13, 2011, 09:27:55 PM »
It is actually trying to use the dotnet framework as opposed to dotnet being infected, well thats my reading anyway  ;D  But using CF will show me any hidden drivers or reg entries to confirm one way or the other

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89679
  • No support PMs thanks
Re: Win32:Malware-gen
« Reply #14 on: January 13, 2011, 09:35:28 PM »
OK, thanks.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security