Author Topic: Virus alerts since today : Win32:Trojan-gen  (Read 8258 times)

0 Members and 1 Guest are viewing this topic.

X2020X

  • Guest
Virus alerts since today : Win32:Trojan-gen
« on: February 05, 2012, 01:41:32 PM »
Hi everyone,

First of all i'm on Windows 7 64bit edition. Avast warns me that  "Steamservice.exe" was infectefed by "Win32:Trojan-gen". Avast prompt me to restart my computer for a complete scan.

Scan is currently in progression and at this moment i can read this output :
Fichier C:\ProgramData\Adobe\ARM\Reader_10.1.1\AdobeARM.bin | >ReaderUpdater.exe est infecté par Win32:Trojan-gen
Fichier C:\ProgramData\Adobe\ARM\Reader_10.1.1\ARM.msi | >Binary.AdobeARM.bin | >AcrobatUpdater.exe est infecté par Win32:Trojan-gen
Fichier C:\ProgramData\Adobe\ARM\Reader_10.1.1\ARM.msi | >Binary.AdobeARM.bin | >AdobeARMHelper.exe est infecté par Win32:Trojan-gen
Fichier C:\ProgramData\Adobe\ARM\Reader_10.1.1\ARM.msi | >Binary.AdobeARM.bin | >ReaderUpdater.exe.exe est infecté par Win32:Trojan-gen
Fichier D:\Steam\bin\SteamService.exe est infecté par Win32:Trojan-gen
Fichier D:\Steam\steamapps\common\assassin's creed 2\redist\Directx\t3740t170.tmp>infinst.exe Erreur 42127 {Archive CAB corrompue.}

I'm a little bit surprised of those alerts and i read that "SteamService.exe" is a false positive. Do you think that all alerts are false positives ?

Excuse my frenchy Egnlish and have a good day !

Offline Soure73

  • Full Member
  • ***
  • Posts: 137
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #1 on: February 05, 2012, 01:43:16 PM »
Hi, do a manual update, the issue seems to be resolved now
HP Compaq with Amd AthlonII x2 2.7Ghz,4 Gig ram 1066 Mhz DDR3,ATI Radeon HD 3000(onboard),Windows 10 Home 64bit

X2020X

  • Guest
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #2 on: February 05, 2012, 01:46:40 PM »
Thanks for the info !
But Avast seems to have chewed my client steam :/
« Last Edit: February 05, 2012, 01:50:04 PM by X2020X »

aaron24wood

  • Guest
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #3 on: February 05, 2012, 02:19:55 PM »
I don't know if this applies to this thread, but my scanner took a fit today finding a thing and then suggesting a boot time scan, wherte it found a whole bunch of stuff.  I'm not entirely au fait with lingo and jargon in these situation, but it seems to picking on stuff I wouldn't have thought.

As well as the attached screenshot, it claimed some Adobe ARM fies (I noted particularly the updater executible), although it wouldn't allow me to move any of that stuff to the virus chest or repair it, and I didn't want to delete something I shouldn't.  Indeed, much like the OP.

Any advice would be appreciated.


tonisb

  • Guest
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #4 on: February 05, 2012, 04:18:59 PM »
I has exactly the same problem today.When I allowed Avast to do a boot scan it brought many threats including Adobe\ARM and even in my Malwarebytes program itself. During the process it would only allow me to delete, tried everything else first. Could not find a report after it completed but luckily had manually written down most of it.
Uninstalled Malwarebytes and did a fresh download - same problem so uninstalled again.
Malwarebytes could not find any threats at all.
Did a full scan with avast and it found the following that I can not move to chest, repair or delete. I keep getting an error message.
If I delete these Adobe files will the trojan.gen go way with it?

C:\...|>AcrobatUpdater.exe     SEVERITY High   STATUS  Threat: Win32:Trojan-gen  ACTION     ( Options) RESULT X Error: The operation is not supported for this type of Archive (42111)
C:\...|>AdobeARMHelper.exe - SAME INFO AS ABOVE
C:\...|>ReaderUpdate.exe - SAME INFO AS ABOVE

Can anybody help - I have the free program.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #5 on: February 05, 2012, 04:24:34 PM »
Quote
Can anybody help - I have the free program.
have you done a manual update of avast......do you still get detection after that ?

tonisb

  • Guest
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #6 on: February 05, 2012, 06:05:30 PM »
Hi Pondus,
Thanks for response. Yes I did an update just before I posted and was up to date. What I have done since is manually deleted those files then uninstalled Adobe Reader X, Adobe AIR and Adobe ARM.Ran CCleaner then I restarted the computer then did a complete full scan and it shows no threats. This sounds like good news and I hope has solved the issue. I am now going to re-download Malwarebytes and see what happens there. Hold thumbs.
Thank you.
Toni.

SoLoPa

  • Guest
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #7 on: February 07, 2012, 02:33:09 PM »
Hi everyone, I am posting here as it seems a few of you are experiencing the same problem I am. A couple of days ago Avast advised me to do a boot scan which I did. It threw up a virus and asked me the 5/6 options. I attempted to move said virus to "the chest" but it wouldn't let me, giving me an Error message. I attempted to delete it and the same Error message again. Basically, it would only let me take no action. Once I had rebooted my computer Avast scan log gave me the following details of the virus... C:\ProgramData\Adobe\ARM\Reader_10.1.0\AdobeARM.bin|>AcrobatUpdater.exe, High risk, Win32:Trojan-gen
When I attempted again to delete/ move this virus Avast told me it could no longer find the file.
I proceeded to do a full scan of my computer but it came back telling me no viruses were found. Obviously I am concerned that this virus is still lurking in the depths of my computer but as I can no longer find it I don't know whether this was an Avast glitch or whether something serious is going on. I do get a lot of popups but to be honest who doesn't?!
It is a Windows 7 64bit system that I use, its quite new and came with McAffe which is now out of date, although it still gives a warning message on some pop ups. Other than that I only have Avast.
If anyone has any info about this problem or a way to resolve it I would be really grateful!
Apologies for the extensive message!  :)
Thanks!

B. Watcher

  • Guest
Re: Virus alerts since today : Win32:Trojan-gen
« Reply #8 on: February 11, 2012, 05:43:42 PM »
Just to confirm that this virus indeed is back, and infects the Avast (!) system: though the full thorough scan found nothing, the start-up boot scan however reported that sf.bin in .../defs/12020300/sf.bin was infected with Win32:Trojan-gen. Action was postponed till next restart. After restart I made the system undergo a new boot scan, and then the virus was not found anymore. So who got an infected machine too (or who thinks that his machine has not been infected but did not realised a boot scan yet): make for your system safety your machine undergo a boot scan! Success!