Need Help -- Win32downlowder LWR and several others...

Hello and happy holidays!!

How do I remove these fellows from my system?

http://img.photobucket.com/albums/v469/Lizoid/Avast.jpg

This is a screenshot listing “everything” that is suddenly affecting my system.

Win32DownloaderLWR seems to be the main issue, it seems to have acquired friends overnight.

Here is my OTL Log… and my ASWMBR log. I haven’t done anything other than save the logs.

So! Lets kill 'em. Where do we begin?

so you did a custom scan and selected “scan memory” ?

you are not the first one, if you search the forum…

what you have detected is signatures from other security programs loaded in memory
that is also why you cant take any action, as this is not files…but a process…you cant move a process to chest

do not change the default scan settings if you do not know what the result is
do not use the “scan memory” setting as this will give some strange scan result…you find out if you search

use the default quick/full scan with default settings

Avast is my only security program.

It found all of this after running my standard midnight scan.

I ran a second scan and found all of this, and rather than wait for two hours again I did a mem-scan. Same results.

Wish it was a case of “operator error” but the day before showed NOTHING and today… shows several active troublemakers.

Avast is my only security program.
strange as the OTL log say you have Malwarebytes and SpyBot S&D
PRC - [2011/08/31 17:00:48 | 001,047,208 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe

and one of the detections is from mbamservice.exe and that is Malwarebytes!

Oh and I was just informed by Current Female Companion that she ran a boot-time scan right before I came home.

Apparently it did nothing?

I stand corrected!

Apparently she installed those in an effort to clean the LWR infection.

Apparently she installed those in an effort to clean the LWR infection.
so you got this before installing MBAM and SpyBot ?

and you are sure that you have not changed any of the default avast scan and selected “scan memory” ?

If so…then Essexboy need to have a look…

Ok.

According to my logs, last night it found Win32Downloader.

I left her a note not to use the computer as it had a virus, please run a “boot scan” for me.

She says that ran it, then ran a full scan AGAIN and still had Win32Downloader… so she set up Spybot and Malware per “advice” from someone… and this is the result.

So… I have removed Spybot, and MalwareBytes. I shall reboot then run a quick scan… and report the results.

I am wondering whether this is a false positive as we now have three like this and so far I can see nothing on the logs

Have you run a scan without memory being selected ?

Hi EB!

I just rebooted and am currently running Avast quick scan, default settings. I shall report back shortly.

Thankee, it may be a quirk within the memory scan as other programmes using svchost may have that characteristic

I ran a quick scan with default settings… NO threat found.

According to MEM-scan… I am just SWIMMING in copies of Win32Downloader.

Is there anything else I can run to settle this once and for all? I’m just a wee bit paranoid about this computer I got some “important stuff” on here for work.

With the memory scan any type of security programme will show up as ,malware as it holds the definitions in memory

I believe this to be a false positive - as the only people reporting this at the moment have all conducted memory scans