win32 malware gen

i have read the instructions on this link http://forum.avast.com/index.php?topic=53253.0
all up to the last page and they kept on telling the others to create a new topic( i hope i got it right)

so here i had this win32 malware gen via message from facebook.
a message from 5 friends sent via facebook mobile containing a link. i opened it and “poof” my computer was infected.
i run avast boot scan and i commanded to delete all threats. ( it was past 2am already and i’m already wasted so i stupidly chose to delete instead of moving to chest).
7am that day, i run windows defender and avast custom scan to check if there are any threats that was not deleted, so no threats were found.
that same they i opened my computer again and annoyingly received a threat message from avast about this malware gen. annoyed i always delete whenever avast pops out with that malware thing.
it has been weeks already and avast stopped popping out with malware gen but yesterday, i went out to print a document(i run out of black ink) and the internet cafe’s antivirus detected a worm from my flash drive, i was alarmed so i run boot scan again today, and viola! win 32 malware is still alive. this time i moved everything to chest
after that i researched about this malware gen and i came up to this forum i followed the steps for the link above and here are the logs
MBAM log after removing all selected files

Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org

Database version: 5688

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

2/6/2011 4:43:33 PM
mbam-log-2011-02-06 (16-43-33).txt

Scan type: Quick scan
Objects scanned: 142375
Time elapsed: 4 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

the OTL logs

http://www.mediafire.com/?gsrvofg7ygiv7fh
http://www.mediafire.com/?wiaoim5stsutkvg
i really do hope that i did everything right

i posted here because i don’t know what to do next. hehe. :slight_smile:
by the way i’m using avast! 4.8 professional edition.

hey and welcome to the forum. I hope someone else can check your log there I’m no expert on them. but i suggest a boot scan might be a good first step sens it sounds that avast is detection something that is reaper if i understand your post.

http://www.schmahl.net/avastbootscan.php

during the boot scan send anything it finds to the chest.

good luck

It is OK…you could have just posted the logs here as attachments :wink:

Essexboy is notified

by the way i'm using avast! 4.8 professional edition.
why not upgrade to avast 5 pro, it is free if you have a valid icense

^ ow about the log files, i’ve read the other post and i’ve read to upload the logs on mediafire so that is what i did.
^ and by the way, that was fast! i wasn’t expecting an “OK” reply that fast.

. about upgrading, i am planning, just don’t have enough time to manage my pc.

also. gonna start boot scan. ^^ as suggested.

Hi there lets get the show on the road ;D

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.1 FF - prefs.js..extensions.enabledItems: m3ffxtbr@mywebsearch.com:1.1 FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\2.bin [2011/01/18 19:35:11 | 000,010,055 | ---- | M] () -- C:\Users\Llorry Manto\AppData\Roaming\Mozilla\Firefox\Profiles\5jg3qqux.default\searchplugins\SmileyCentral_1v.xml [2011/01/08 10:03:51 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM File not found (No name found) -- C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN O4 - HKU\S-1-5-21-1131567986-3692601068-143179124-1000..\Run: [SME] C:\ProgramData\9e6caa\SM9e6_2204.exe () [2011/01/10 21:25:25 | 000,000,000 | ---D | C] -- C:\ProgramData\lOgIo04300

:Files
ipconfig /flushdns /c
C:\ProgramData\9e6caa
C:\PROGRAM FILES\MYWEBSEARCH

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

here is the log.

by the way, after rebooting the pc, an OTL window opened and i run it, then a notepad pops out
i included the file on the attachments.

Ok methinks I need a slightly stronger tool as one element did not want to play. Once this run is complete can you let me know what problems remain

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[
]Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

^ ow, i could not disable avast. i don’t know why, i’ve denied full control of the system already just like what i did in MBAM but combofix keeps on detecting it.

Could you run combofix from safe mode please

I have Avast 5,Free edition. I have not been infected by a single virus, in ten years, until four days ago. I do daily scans, on startup, every day, except Saturdays. So, the infection must have occurred late on last Wednesday. To my recollection, three things happened on that evening. My wife spent a lot of time on Facebook, and before shutting down, I installed the latest security updates of Open Office(3.3), and Opera 10.01.
Several files were found to be infected. Among them some system volume restore info., a few system files, and on boot scan the Avast 5 cleaner file. The latter is interesting since I had intended to remove Avast, which had recently replaced AVG, as a test, and because a Search listed many complaints with Win32.Malware.gen, all reported by Avast users.
To me, it meant that, either, Avast was seeing things, or it was the only good AV.
The day after the boot scan, Avast found a couple other infections. At that point, I did scans, with Malwarebytes AntiSpyware, which found several malware items, all but one in the Registry. I did a virus scan with Housecall Trendmicro on line, and another antispyware scan with SuperAntispyware, which removed more junk. I did a manual scan Saturday, and the usual automatic scan, with Avast. Both clean, but today, though clean, but computer tried to shut down by itself, at scan’s completion. On restarting both antispyware programs found a couple of Registry issues, which I cleaned up.
I am not sure if I am done with this Malware, or if Avast is reliable. Interesting to note is the fact that the Avast cleaner file was infected. I did a redownload, and it went straight into the Vault, with 0 Kb in the download location. After the complex clean up, a redownload succeeded. I think that I eliminated the issues with Open Office and Opera. Facebook is, still, suspect.

There was a minor glitch where the removal tool was detected as malware - this was rectified with the next update

okay. i’ll try it, but maybe tomorrow. (busy schedule. :))

avast was already disabled yet still, combofix keeps on detecting it.

a big mistake that many do is, they think they’re infected just because they download something but that’s wrong; in order to have an infected computer the malware has to run active in memory (if it’s a rootkit it’s an other story).

this may be offtopic but it’s important knowledge.

Regards,
Tenko

hi .:slight_smile: so i’ve encountered yet another problem so i repeated the steps that i did. here is the MBAM log and the ots log
and also i haven’t run combo fix ever since due to a tight schedule.

i promise to do everything that you want me to do right away this time .
i will also run avast boot scan today

>> avast was already disabled yet still, combofix keeps on detecting it.

Disable Avast image 1 and 2

recommendation > Replace USB Disk Security with MCShield http://amf.mycity.rs/programs/mc/mcshield/

Why disabling the avast self defense help in anything with virus manipulation? ???

I understand that Avast prevent Combofix run

if i happen to run combo fix in safe mode, do i have to disable my security softwares?

if you run ComboFix in safe mode ,CF will work in reduse mode

and some of function of CF will not work. CF is maint to run in normal mode

if you do not know how to run CF, first uninstall your antivirus and then re-start CF tool