system
November 3, 2011, 2:10pm
1
For the last 2 days, I’ve been encountering this virus/worm named as Win32:Malware-gen (refer to SS below).
http://i272.photobucket.com/albums/jj193/louise478/1-2.png
Whenever I try to open folders I’ve created before this virus came up, this, with the pop-up by Avast! (above), comes up.
http://i272.photobucket.com/albums/jj193/louise478/2-2.png
The folders are automatically sent to the Virus Chest as it has not given me any other option. I found out that disabling Avast! whenever accessing folders work but I want to remove the malware completely.
Anyone knows how to fix this? I think this is a common problem but I have not found a definite fix yet while searching the net. Thank you.
By the way, my Avast! version is 6.0.1289.
Pondus
November 3, 2011, 3:05pm
2
have you run a quick scan with MalwareBytes ?
Malwarebytes Anti-Malware 1.51. http://filehippo.com/download_malwarebytes_anti_malware/
always update before you start scan
click on the remove selected button to quarantine anything found
post the scan log here
system
November 3, 2011, 4:54pm
3
Here it is.
Malwarebytes’ Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8076
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
11/4/2011 12:54:01 AM
mbam-log-2011-11-04 (00-54-01).txt
Scan type: Quick scan
Objects scanned: 182935
Time elapsed: 8 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CLASSES_ROOT\exefile\NeverShowExt (Risk.HiddenExt) → Value: NeverShowExt → Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Pondus
November 3, 2011, 4:56pm
4
did that solve your problem ?
If not, follow this guide and attach the logs from OTL and aswMBR
http://forum.avast.com/index.php?topic=53253.0
lower left corner > additional options > Attach > ( OTL.txt / Extras.txt / aswMBR.txt )
then Essexboy will have a look when he arrive here in a couple of hours
system
November 4, 2011, 8:03am
5
Sadly, no. And for some reason, OTL won’t work properly. The program is not responding properly so the scan was never finished. However, aswMBR.exe work fine.
Attached are the scan logs for Malwarebytes and aswMBR.exe
DavidR
November 4, 2011, 10:46am
6
Did the avast autosandbox have you run it in the sandbox ?
If so run it again and have the avast autosandbox open it normally.
Also: Run an avast scan and allow it to move those two detections it found to the virus chest.
15:52:11.453 File: C:\WINDOWS\086722514.exe **INFECTED** Win32:Malware-gen
15:52:23.281 File: C:\WINDOWS\Sfawsjmlhzzb.exe **INFECTED** Win32:Malware-gen
system
November 4, 2011, 11:40am
7
No, it automatically was sent to the Virus chest.
Should I do a full or a quick scan will do?
DavidR
November 4, 2011, 11:51am
8
Where did you get OTL from as I haven’t seen that happen in a very long time ?
Check this topic for download locations and instructions, http://forum.avast.com/index.php?topic=53253.0 .
Ensure that you have the latest avast virus definitions update.
system
November 4, 2011, 1:45pm
9
I downloaded OTL from the link in the topic you gave.
I’ve done a quick scan using Avast!. Found 20 + infections and I moved everything to the virus chest. What should I do next?
DavidR
November 4, 2011, 1:50pm
10
Try downloading OTL again, I have just downloaded it and no alert from avast, ensure avast is up to date.