Is the computer still infected?

Hello guys,

I have attached the OTL, malware bytes and Avira Logs.

Problem description:

Yesterday, avast started to detect malware-gen (6 files) files in the following path:

C:\Users\Bruno\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\cd57425dc33e2325\120712-0049\Att\ RANDOM NAME\ RANDOM File name.

All random file name have weird extensions like .zi, .exe1, .rar1, etc.

I couldnt attach the avast log with the detection, because I uninstalled it to try other avs and check if something was found. Maybe the downloader responsible to download the files detected by avast.

Malware bytes, panda cleaner, adwcleaner and hitman pro didnt found anything. However Hitman pro asked to fix the winsock. I let it fix, even not having any connection problem that I was aware.

I attached the avira log, because it detected other files with the same path logic described above. Also avira said that I should run the avira rescue cd because it found something hidden in the system. I am going to do it now with avast rescude disk and avira rescue cd.

Avast has detected in real time, last thursday, a site with the blacole exploit. I am not sure if it could be related. Also, the only thing diferent I have done was install a free program that convert videos do DVD format, so the DVD player could play the video I have made to the wedding of a friend.

Today, I re installed avast and no detection was alerted so far. But I am not sure if its ok.

Thanks for your time!

Yesterday, avast started to detect [b]malware-gen[/b] (6 files) files in the following path:
what was the malware name given by avast?

it seems like you have Fortinet endpoint installed…is that not a AV program?

EDIT: was it Win32:Malware.gen?

Hello Pondus.
Thanks for the reply.

Yes, it was win32:malware-gen.

The fortinet that I am using is not the antivirus. It’s just the vpn so I can access the computer of my job if needed.

Thanks!

OK …malware experts are notified and will check Your logs.
Most of them are located in europe and we are almost at midnight here now, so if you dont recive a reply here in a couple of hours then i Guess you must wait untill tomorrow :wink:

No problem. :smiley:

I think the situation is controlled by now. But it’s always better to get a second opinion. :smiley:

Looks clean nothing apparent showing :slight_smile:

Great news! Thanks, I was not sure this time if it was really clean :slight_smile: