Win32:malware.gen?

Starting Today, Said Malware/Virus is appearing every time I run a scan for some reason or another, If i remove the file it’s supposedly infecting, it appears elsewhere

I’ve done full scans with Malwarebytes Anti-Malware and SuperAntiSpyware, and they don’t show any threats whatsoever, I’m not entirely sure what to make of the situation, the worst I got out of SuperAnti was two tracking cookies.

Is Avast finding something that isn’t there or are the other two simply not catching it at all? This really has me worried.

What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?

You say it reappears elsewhere (so give a couple of examples), does it retain the same file name or does that change also (if so give a couple of examples) ?

Are you experiencing any adverse/strange occurrences ?

I can’t give a direct location now, All I can currently state is it being in random Folders of my C:Drive, I just ran another full scan and nothing came up this time, It was a different file each time though. I’m running another scan to see if it shows face again.

As for adverse/strange occurrences, Nothing really unusual has happened other than suddenly getting claims of Win32 Malware.

Check the C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\report (winXP) location for the type of scan name Full System Scan, etc. this is where all report files are located. For Vista, win7 the path is C:\ProgramData\Alwil Software\Avast5\report.

This folder may be hidden.

Not sure if this helps but…

  • 0000000A 4418852
  • 00000006 1180250280 JP_BB_FIX.exe C:\Program Files\SEGA\PHANTASY STAR ONLINE Blue Burst Win32:Trojan-gen Vir yes 1277245229 1914135
  • 00000007 1180250280 JP_BB_FIX.exe C:\Program Files\SEGA\PHANTASY STAR ONLINE Blue Burst Win32:Trojan-gen Vir yes 1278087967 1914135
  • 00000008 1256503257 uninst.exe C:\Program Files\Pando Networks\Media Booster Win32:Malware-gen Vir yes 1278956406 295295
  • 00000009 1256503257 A0136100.exe C:\System Volume Information\_restore{75B24976-4861-4D19-A118-8E17509FA1C6}\RP181 Win32:Malware-gen Vir yes 1278968163 295295

Those are the infected files, found them in the Chest.

Also After another scan, nothing has come up.

This one was mentioned in another topic, try a forum search for the file name. Does the program Pando Networks\Media Booster not ring any bells ?
uninst.exe
C:\Program Files\Pando Networks\Media Booster

This one doesn’t appear random to me, presumably you have this game installed ?
JP_BB_FIX.exe
C:\Program Files\SEGA\PHANTASY STAR ONLINE Blue Burst

This one I wouldn’t worry about:
A0136100.exe
C:\System Volume Information_restore{75B24976-4861-4D19-A118-8E17509FA1C6}\RP181

  • Infected Restore Points - There really is little benefit in chasing a detection in the system volume information folder. It is only there because it had previously been deleted or moved from the system folders and this is a back-up created by system restore.

  • Worst case scenario it isn’t infected and you delete it, you can’t use that restore point in the future, not much of a loss and the older the restore point is the less of an issue it is.

  • So if there is any suspicion about a restore point then it is best removed from the system volume information folder or it could bite you in the rear at some point in the future when you use system restore if it included that restore point.

So I can probably delete these all together? Or no.

I THINK those are the only infected files, I’ve run a third full scan now and come up empty for threats.

With exception of the suspect restore point, Deletion is never a good idea without full investigation. That is why I gave you the info about searching the forum on that first file name and why I asked if these programs rang a bell with you.

I have no idea what you have installed on your system, that is why I asked the questions, so I can’t answer that question.