Hello, I’ve spent the past couple of days upgrading someone’s laptop to Windows 10.
After installing Avast I realized that the program detected a “FileRepMetagen” infectionat msaudioeng.exe located in App\Data\Local\Temp, the program blocked the thread, sent the file to quarantine and prompted me to restart the system and do a boot scan to make sure there’s no infections left, I left the scan run but the cycle repeats, as soon as the system restarts the infection gets blocked and Avast asks me to perform a boot scan.
Additionally, I noticed that the warning doesn’t trigger if my internet is down when I restart the system.
Feedback would be appreciated! I’ll attach the proper logs.
I’m very confused by this, the file keeps showing up after every restart.
Thanks for the reply! I just submitted the file, the scan says that the file was detected by the taskeng.exe process too so I’m utterly confused about this being a false positive or not.
Maybe my registry isn’t clean?
This situation is oddly similar t this https://forum.avast.com/index.php?topic=169463.0 I’m tempted to run the script but as stated, that only applies to that user.
After countless restarts, scans and running the file, the detection still persists.
Apparently, on top of the FileRepMetagen detection, Avast also detects and blocks a Win32:Malware-gen infection every time the system starts up and there’s internet connection.
Here’s the log.
Here’s the log, the infection remains after restarting.
According to Avast’s log the full path is [Chest] C:\Users\Francisco Cardoso\AppData\Local\Temp\msaudioeng.exe, naturally the file is gone after the detection since it gets sent to quarantine, so t gets created every time I restart Windows.
Search.txt was generated instead of report.txt, here’s the file.
Edit:
I see some important information in the log, is this a keylogger? As I’ve mentioned before, this isn’t my computer it’s a family member’s and I was just upgrading it and scaning for maware. I had to access my email account here to register here so hopefully I’m not at risk.
[*]Accept the Terms of Use and click Start
[*]Allow the running of add-on.
If using Mozilla Firefox or Google Chrome:
[*]A link to esetsmartinstaller_enu.exe will be provided. Make sure to download it to the desktop
[*]Double click esetsmartinstaller_enu.exe
[*]Allow the Terms of Use and click Start
To perform the scan:
[*]Make sure that Enable detection of potentially unwanted applications is checked.
[*]In the Advanced Settings dropdown menu:
[*]Make sure that Remove found threats is unchecked
[*]Scan archives is checked
[*]Scan for potentially unsafe applications and Enable Anti-Stealth technology are checked
[*]Use custom proxy settings is unchecked
[*]Now click on Start
[*]The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
[*]When completed the Online Scan will begin automatically. The scan may take several hours.
[*]Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
[*]Now click on Finish
[*]Use notepad to open the logfile located at C:\Program Files(x86)\ESET\EsetOnlineScanner\log.txt
[*]Copy and paste that log as a reply to this topic]
Here’s the log, it seems like the infection is gone after this restart since I haven’t seen the usual detection so far.
Any additional steps or precautions to make sure this system is clean?
Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe
Thank you!
I did install Malwarebytes to check for infections, I’ll run the rest of the programs, automatic updates is enabled so the rest shouldn’t be an issue