Win32:Hoaxalarm-M

What is this!!! I have some malware on my PC(pop ups,false 404 errors,false system errors) & Avast finds it & identifies as Win32:Hoaxalarm-M but I can’t get rid of it. If I delete the file it just keeps coming back. Please help as it’s driving me nuts.

Are you using Windows XP?
Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning
Select for scanning archives.
Boot.

Other option is scanning in SafeMode (repeatedly press F8 while booting): http://support.microsoft.com/default.aspx?scid=kb;en-us;315222

Other good thing is disable System Restore, boot, enable it again. If you find a virus keeps coming back after you delete it, it’s most probably infected the System Restore folder, the best way to solve this is to disable System Restore, reboot your machine and then enable it again. After all, run a full avast! scanning. System Restore cannot be disabled on Windows 9x and it’s not available in Windows 2k.

Enable/Disable System restore on Windows ME: http://support.microsoft.com/default.aspx?scid=kb;en-us;Q264887
Enable/Disable System restore on Windows XP: http://support.microsoft.com/default.aspx?scid=kb;[LN];310405

OK,I will try this. Many thanks for your help & time.

This is not work in my problem?

http://forum.avast.com/index.php?topic=15721.0

Best regards from Slovenia

You need to find out what is running and bringing it back.

I would also suggest a change of browser to one leee suscetpable to this form of attack, firefox or opera. If you visit the same sites it could be that you are being reinfected in that way.

Program & Tutorial - Also useful as a diagnostic tool - Download HiJackThis.zip - HJT Information HiJackThis Tutorial 1 or HiJackThis Tutorial 2
For an on-line analysis - HiJackThis Log file - On-line Analysis
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
OR HiJackThis Log file - On-line Analysis 2

Hello for all!

Today I go on Pandasoftware and there strart online Activescan but Activescan did not delete or repere this in report they write:

[tr][td]Incident[/td][td]Status[/td][td]Location[/td][/tr]
[tr][td]Adware:adware/securityerror[/td][td]Not desinfected[/td][td]C:\WINDOWS\system32\mssearchnet.exe[/td][/tr]
[tr][td]Adware:adware/spyaxe[/td][td]Not desinfected[/td][td]C:\WINDOWS\SYSTEM32\hpBD25.tmp[/td][/tr]
[tr][td]Adware:adware/securityerror[/td][td]Not desinfected[/td][td]C:\WINDOWS\SYSTEM32\mssearchnet.exe[/td][/tr]
[tr][td]Adware:adware/miamore[/td][td]Not desinfected[/td][td]C:\WINDOWS\SYSTEM32\st3.dll[/td][/tr]

I delete all this files in safe mode and I set recovery system to disable.

To this time all is OK, Avast is ron Ok, all is Ok, no more popups, and security alarms.

Best regards from Bostjan - Slovenia

Now watch out for false positive warnings from avast, as Panda’s on-line scanner doesn’t encrypt its virus signature files, s watch for any indications for files in the ‘Activescan’ folder.

Hello!

Sistem work very wel, like befor I have this adware.
Avast work Ok…

Best regards Bostjan