Win32:Malware-gen & Win32:Downloader-PKU [Trj] warnings

Hi there,

In following your intructions (http://forum.avast.com/index.php?topic=53253.0), I have included my logs with this post.

in following the advice given here: http://forum.avast.com/index.php?topic=101759.msg814117#msg814117

I was also not able to run AVZ Antiviral Toolkit… but followed the OTL steps and ComboFix steps…

Here are my logs… It seems to have worked (knock on wood!)… just wanted to say thanks! :slight_smile:

Hello, :slight_smile:
!!!Slowly with this script if you want to keep your system bootable!!!

Why did you started Combofix without supervision?

Read what the author of Combofix “sUBs” think about it:
http://www.techsupportforum.com/1829551-post6.html

Also, read an official article about runing ComboFix
http://www.bleepingcomputer.com/forums/topic273628.html


And you used an OTL scripts on your own
C:[b]_OTL[/b]

Each script fix is only relevant for the system where it working on malware removal and no other.
Using script on another computer may cause problems :wink:


AVZ…?


Your AntiVirus softwere wase active wile Combofix running: Wrong!

AV: avast! Internet Security Enabled/Updated {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security Enabled {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security Enabled/Updated {904CF271-6431-DA47-5FCE-A87D98DFB681}


Step1
I will be helping you out with your particular problem on your computer.

  1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
  2. The fixes are specific to your problem and should only be used for this issue on this machine.
  3. If you don’t know or understand something, please don’t hesitate to ask.
  4. Please DO NOT run any other tools or scans while I am helping you.
  5. It is important that you reply to this thread. Do not start a new topic.
  6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  7. Absence of symptoms does not mean that everything is clear.

Step2

how ComboFix works?
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this Instruction.

Re-run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.

When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
Attach log reports ( ComboFix.txt) back to topic.

edit: Add link “how ComboFix works?”

Hey magna86,

Sorry about that, I am not super familiar with any of these programs or fixing malware etc. I just made an assumption that it was okay because that cubsfan described the same problem as me. No more assumptions - trust the pros!

As for the Combofix saying that antivirus and firewall was active… I ‘temporarily disabled it for 10 minutes’ when I probably should have done it permanently (like I did this time)… then when I ran Combofix, a window popped up saying that it was still active and suggests it being closed, if you go further that they dont take responsibility, etc. and there was only an OK button… So at that point I had selected CNTRL-ALT-DEL > Services and went and stopped the avast programs… THEN I went back to Combofix and hit OK (since I thought it was disabled)… :s not really sure why that happened.

Anyways, I re-ran Combofix like you suggested and attached the new log file that was created.

Sorry for waiting…

No malware activity in logs…

It is necessary to uninstall Combofix

Start (
http://fotkica.com/thumbs2/117539_tmb_191855275_Windows_Logo_key.gif
) >> Run

Combofix /Uninstall

Enter

Your older logs showed traces of possible infected USB devices. If you want to check by yourself, here’s how you can do that:

Checking USB storage devices / removable drives

Download MCShield.
Official site

[*] Double click MCShield-Setup to install the application.
[*] Wait a few seconds to MCShield finish initial scan.
Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
[*] Connect your USB storage devices to the computer one at a time. Scanning will be done automatically.

When all scanning is done, you need to attach a logreport that has made MCShield.

Start → All Programs → MCShield → Logs

Attach here → AllScans.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.

I recommended to you to keep MCShield.
It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but will immediately clean Memory card or external HDD

How’s your computer behaving now ?