system
March 26, 2009, 7:15pm
21
Scythe If you are talking about my issue I exported(copied) the virus info from the log viewer into a text document that I then uploaded to the virus total site. I unfortunately dont understand what you mean about changing my original post from http to hxxp?
You have to go back to your post that I have shown below, and hit the “Modify” button. Then change where I have highlighted in red in my previous post.
You need to change the “http” to “hxxp” or something else to break the link, so that it’s not active anymore.
Scott(Charleston) post:5:
Sorry here it is hope this is right. Thanks again for your time and feedback Scott
7/24/2008 2:51:37 PM 1216925497 SYSTEM 1652 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
8/9/2008 7:23:57 AM 1218281037 SYSTEM 1636 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\Brackett\Local Settings\Temporary Internet Files\Content.IE5\95BVO2MD\topnav[1].swf (C:\Documents and Settings\Brackett\Local Settings\Temporary Internet Files\Content.IE5\95BVO2MD\topnav[1].swf) returning error, 0000A413.
8/13/2008 11:25:51 AM 1218641151 SYSTEM 1576 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
8/26/2008 12:11:40 AM 1219723900 SYSTEM 1692 Function setifaceUpdatePackages() has failed. Return code is 0x00000001, dwRes is 00000001.
10/9/2008 7:00:43 AM 1223550043 SYSTEM 1528 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
10/10/2008 8:45:54 AM 1223642754 SYSTEM 1528 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
10/18/2008 9:24:13 AM 1224336253 SYSTEM 1512 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
11/28/2008 8:55:14 AM 1227880514 SYSTEM 1584 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
12/6/2008 8:55:07 PM 1228614907 SYSTEM 1708 Sign of “JS:Packed-L [trj]” has been found in “hxxp://j1j2j34.com/seas/spl/pdf.pdf” file.
12/6/2008 10:12:00 PM 1228619520 SYSTEM 1708 Sign of “JS:Packed-L [trj]” has been found in “hxxp://j1j2j34.com/seas/spl/pdf.pdf” file.
12/9/2008 7:29:06 PM 1228868946 SYSTEM 1520 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\WINDOWS\SoftwareDistribution\Download\60e28f2fefe55b8867c36eb78f0d8fdc\BIT8B.tmp (C:\WINDOWS\SoftwareDistribution\Download\60e28f2fefe55b8867c36eb78f0d8fdc\BIT8B.tmp) returning error, 00000026.
12/16/2008 12:34:17 AM 1229405657 SYSTEM 1524 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
12/16/2008 4:34:23 AM 1229420063 SYSTEM 1524 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
12/16/2008 8:34:28 AM 1229434468 SYSTEM 1524 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
1/5/2009 8:25:45 PM 1231205145 SYSTEM 1712 AAVM - scanning warning: x_AavmCheckFileDirectEx: http://www.tvguide.com/ScriptResource.axd?d=S_87Xd2HAdUfH6HxRyXa8rVdd9AxnC7cBO2sAjDBOF_QVmv6IV26ZeRI6Q38YYzPzOiE34LU6Yz3f39FqYHU94MpKTAX7BToaJcbyGZeK1o1&t=633564874556067955 (C:\WINDOWS\TEMP_avast4_\unp21235768.tmp) returning error, 0000A413.
2/23/2009 11:34:10 AM 1235406850 SYSTEM 1532 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
2/23/2009 3:37:21 PM 1235421441 SYSTEM 1532 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
3/25/2009 6:57:07 AM 1237978627 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\Program Files\EnglishOtto\uninstallotto.exe” file.
3/25/2009 7:16:37 AM 1237979797 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\Program Files\GemMaster\uninstallgemmaster.exe” file.
3/25/2009 7:23:05 AM 1237980185 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\System Volume Information_restore{163AE8C9-33BA-4185-877E-271E48F5CC80}\RP520\A0070728.exe” file.
3/25/2009 7:23:05 AM 1237980185 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\System Volume Information_restore{163AE8C9-33BA-4185-877E-271E48F5CC80}\RP520\A0070729.exe” file.
3/25/2009 7:47:34 AM 1237981654 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\Program Files\EnglishOtto\uninstallotto.exe” file.
3/25/2009 11:11:43 AM 1237993903 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\Program Files\GemMaster\uninstallgemmaster.exe” file.
3/25/2009 11:18:25 AM 1237994305 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\System Volume Information_restore{163AE8C9-33BA-4185-877E-271E48F5CC80}\RP520\A0070728.exe” file.
3/25/2009 11:19:59 AM 1237994399 Brackett 4976 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\System Volume Information_restore{163AE8C9-33BA-4185-877E-271E48F5CC80}\RP520\A0070729.exe” file.
system
March 26, 2009, 7:30pm
23
Ok I think I found out what you were talking about and I just modified to read hxxp for those two spots-sorry for the brain damage 0let me know if that did the trick
DavidR
March 26, 2009, 7:48pm
24
You have to go back to your post that I have shown below, and hit the “Modify” button. Then change where I have highlighted in red in my previous post.
You need to change the “http” to “hxxp” or something else to break the link, so that it’s not active anymore.
@ scythe944
By quoting the original text you have replicated the problem you are seeking to resolve. So you should modify the quoted text ;D ;D
system
March 26, 2009, 7:49pm
25
The Windows firewall is also on-I didn’t know that. Do I need to turn off the Windows firewall since I have the avast firewall on?
I know, I was just trying to help him understand. I fixed mine, sorry bout that.
system
March 26, 2009, 8:03pm
27
Did I make the right corrections about the hxxp from http? I thought I did that in the post from yesterday where it was a link and now it is unlinked after I modified it?
Yes Scott, you did fine. Thanks!
system
March 26, 2009, 8:29pm
29
No, leave Windows firewall on after all is done. Avast does not yet have a firewall.
system
March 26, 2009, 8:39pm
30
OK Are we making progress now. Have I given you everything you need or is there anything else-Thanks again for your help and quick response time.
system
March 26, 2009, 8:42pm
31
Judging by your comment. CharleyO, Is Avast! going to have its own firewall soon or something? I thought the network shield acts like a miniature firewall, shouldn’t that be enough?
system
March 26, 2009, 10:02pm
32
While Network shield & Web shield do have some characteristics of a firewall, neither is exactly a firewall.
Avast has announced that their own in-house built firewall will be released with avast! 5 sometime in June or July.
system
March 30, 2009, 4:12pm
33
Can you let me know what I do with thses items in my virus vault since you feel that they are not malicious. Do I delete them, leave them or what?
Files that are in the virus chest can do no harm, so you can safely leave them in there. Normal procedure around here (to the best of my knowledge) is that you should keep the files in the chest for about 2 weeks to make sure that you don’t need the file, and that you have a copy in case you want to send it to avast for analysis.
If you find that your system works fine after the 2 weeks, and that you don’t need to send the files, then you can safely delete them if you’d like.
Again, it doesn’t hurt anything by keeping them in the chest.
system
March 30, 2009, 5:15pm
35
Thanks scythe for all your help as well as CharleyO.
system
April 1, 2009, 3:26am
37
You are welcome, Scott.
Thanks for helping, scythe944, while I was away for a couple of days.
Anytime CharleyO! Others (including you probably) do the same for me…
system
April 1, 2009, 10:55pm
39
I just got Avast Home and It said I have the Win 32 trojan gen as well, can you please tell me what to do step by step. All downloads I need or anything
Hey John, I don’t know if you have done this or not yet, but it’s best to start your own thread when you have a problem, even though it may have something to do with the original post (it keeps things cleaner).
So, if you may, please start a new thread, and we’ll help you out the best that we can.
Thanks!