OSCust.exe win32:Trojan-gen (other)

It only took 5 seconds to scan the file which was kinda wierd but it didnt say it was already analyzed. So should I go ahead and delete it from the chest? What would I do about the constant Default Block UPnP Discovery" Stealthed (###.###.#.#, Port ssdp(####)) if they continue to show up?

Why is dema running Norton complaining about avast! discovering a Trojan-gen he askes retorically. ???

UPnP should be disabled anyway:
http://www.grc.com/unpnp/unpnp.htm

Thanks for the Info, was waiting to see if this was a false positive before I did anything.

Ok I tryed both options you listed, first I deleted the infected file in the chest and uninstalled Avast, I then updated NIS09/Malwarebytes/SUPERantispyware and scanned in both safemode and normal mode with nothing showing up. Afterwards I redownloaded Avast Home Edition, turned on my windows firewall and noticed that one of the exceptions in the options for windows firewall was “Discovery” and this was checked, I then proceeded to reset the defaults which set the only exceptions back to local network.
I then completely uninstalled my NIS09 and repaired Avast afterwards, which was successful. After uninstalling norton I did a thorough scan with archived files checked and it came up with 16 Listed Lines - Selected Lines 1, no signs of viruses but for these 16 lines it says the following "Unable to Scan Archive? These lines are all under c:\users and are all random numbers/letters after my name. Are these the remnants of the infected file that was the virus? Is it possible its still on my computer? What other steps can I take to make absolutely sure Its removed. Thankyou guys for your previous replys, all of this is new to me considering Ive never had this issue before.

Welcome to avast!

When you see “Unable to Scan Archive” it is files that are compressed and will be scanned when un-compressed so its nothing to worry about.

Read why Vincent Steckler left Symantec and joined avast!:
http://blog.avast.com/2009/07/20/welcome-and-why-i-joined-avast

I have the following questions;

  1. The 16/41 files that virustotal said were bad from my scan, arent these the compressed files you speak of? (Its very wierd that it would be the exact same number as the corrupted files found in that file), and would it be safe to move these to the chest for now?
  2. What exactly is “Discovery” in the windows firewall exceptions (Info - Rule “Default Block UPnP Discovery” Stealthed (###.###.#.#, Port ssdp (####)). Inbound UDP Packet.), is it where the worm/virus was trying to access my computer, and how did it change the options to make it an exception?
  3. I found a thread regarding OSCust.exe with a post from a AW represenative stating its used during manufacturing process, http://forums.tentonhammer.com/showthread.php?t=34992 , but this still doesnt explain why I had two txt boxes pop up stating I had malicious software and “my computer” started a scan yet all the scanners Ive used show up clean but Avast finds this file that apparently isnt harmful. I have my doubts but Id like to learn more regarding this and how I can make sure my computers really clear of this threat.
  4. Whats the best way to find out I dont have any rootkits installed?

For some reason avast doesnt want to open in safemode, itll start the memory process and give me the instruction box with another tab in the taskbar named avast - simple user interface but it wont open, even after clicking on it repetitively. I tryed repairing it in safemode w/ networking but it still wont open. Its opened before in safemode but wouldnt allow me to access the chest. What could be causing this?

The fact that you have 16 “unable to be scanned” files, and there were 16 returns for the virustotal results is pure coincidence. Read nothing into that.
The 16 file unable to be scanned are not necessarily malicious, in fact they probably are not. In the scan report, the pane can be maximized, and the header tabs moved so the filename and path can be read. By looking at the names and paths, it can give a good idea as to what they are.
They should not be moved to the chest.
Go each file, and context-scan (right click) with MBAM.
I actually think the problem you have with a rogue application probably has nothing to do with the OSCust file; it just happened to be detected at about the same time.

If I remember correctly, some Avast functions - like the chest - are not available in safe mode.
In normal mode, update MBAM, and run a full scan again.
Post the scan report.

I believe your right that this happened to just show up after the rogue application popping up, heres my MBAM Log and a new Hijackthis Log. MBAM shows nothing as usual, can I assume my computers clean, or is there something still residing somewhere.

The Discovery exception that was checked in my windows firewall has the following def; This feature allows this computer to discover other devices and be discovered by other devices on the network. (Uses Function Discovery Host and Publication Services, UPnP, SSDP, NetBIOS and LLMNR) so I guess this is how the program entered my computer in the first place but the firewall that was active at the time was my NIS09 smart firewall and its settings were to block these which it showed in the log. Im not getting any messages so far using windows firewall about it blocking that connection, its not checked in the exceptions anymore. What if this could be the new vulnerability said in the following thread, http://forum.avast.com/index.php?topic=47903.0, Im using adobe flash player 9 currently on my computer.

The log looks clean to my untrained brain.

However, there are a number of “023” (services) entries for which the log states “file missing”, a few too many for that to be normal.
I don’t actually know the import of that…sometimes when software has been incorrectly removed it can leave such an entry behind, but a lot of yours seem to belong to the OS.
Might pay to wait till someone more expert can analyze that.

Would it be safer to just have a complete clean install on my computer, I still have the software cds it came with.

If you are happy to format and reinstall, and you’d feel better as a result, shy not.
I don’t know that it is required, though.
Why not wait and see what a few others say?

If you do decide to reinstall, make sure you save your wanted files,
and maybe save the installers (latest) for security software to a clean flash drive so that you can install the AV etc before connecting to the net.

I do not see the need to do a fresh install but you need to un-install the vulnerable Adobe\Reader 8.0 and install the latest update.

Go to Start then enter windows update then Change settings then select Install updates automatically (recommended) or at least Check for updates but do not download them nor install them

Vista SP2 is available.

Run Secunia Online Software Inspector to see what applications are vulnerable:
http://secunia.com/vulnerability_scanning/online