Avast Free says i am infected with Win32:Malware-gen. The Avast popup only appears once a day (not at the same time each day) and only started last week when i updated to the latest version of Avast.
After reviewing your logs, I am going to refer you to our Certified Malware expert, named Essexboy. He will also review your logs and give you further instructions, however he comes on the forum late UK time (6 - 8 PM). He will respond to you in this thread, so remember to check this thread daily.
Please do not make any further changes to your machine since you have provided the logs.
IMPORTANT: If you are on a home network, disconnect the affected machine from the network. Do not share a USB/flash drive with this affected machine. Do not use this machine unless Essexboy instructs you do to malware removal instructions; use a different machine to check email, do not sync your phone or any other device with this machine.
:OTL
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-527701978-4243745748-3329972647-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-527701978-4243745748-3329972647-1000\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
I took a screenshot of the popup box yesterday just in case you asked. See attached Avast-Notice.jpg.
The popup says “Malware Blocked.” The object listed is: C:Windows.…_A6AB176A953A_4ACA_B22B_DC5BE6B01EE9.exe. The Process listed is: C:\windows\system32\rundll32.exe.
Ran Run Fix. Report attached as 07102012_145206.log
FYI, during the restart after the reboot avast auto-updated my definition file.
Selected “Scan All Users” and ran Quick Scan. Report attached as OTL-2.Txt
I did a search in Windows Explorer and it found the file in: C:\Windows\Installer{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}
In the context menu i told Explorer to open file location. The only other file listed is: misc.exe.D0DF3458_A845_11D3_8D0A_0050046416B9
Both files have the exact modified date and time: 5/26/2010 at 1:50am and are listed as Applications.
The file you asked about is 84IB in size. The misc.exe… file is 34KB in size.
Don’t know if it matters at all, but on Saturday i ran a full disk scan with MBAM Free and it found nothing. I also ran a full disc scan with Windows Defender and it didn’t find anything either.
Selected “Scan All Users” and ran Quick Scan again with the md5 commands. Two reports attached.
I tried to save the report as ANSI and got a dialog that said some unicode information would be lost if i did. Didn’t know if that was important so saved it as unicode and ANSI.
OTL-3.Txt (unicode)
OTL-3B.TXT (ANSI)
I’ll take a false positive. Should i let Avast know that their new version is generating a false positive or just ignore it? And if i ignore it, what if another similar warning pops up but with a different file?
Can’t submit the false positive. I selected the file, selected False Positive as the type, selected “I know what I’m Doing” at the bottom (because YOU do), but it tells me i need to fill in the missing information before i can submit. Actually, the dialog that comes up says “Please make sure that all the fields are filled in with correct data.”