Win32:Malware-gen Detected by Avast

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by melm, Jun 1, 2010.

  1. melm

    melm Private First Class

    Avast detected Win32:Malware-gen in the following places:

    5/31/2010 5:59:51 PM C:\WINDOWS\SYSTEM32\CSELECT.EXE [L] Win32:Malware-gen (0)
    File was successfully moved to chest...
    5/31/2010 7:39:04 PM C:\Program Files\TOSHIBA\TOSAPINS\COMPS1\Toshiba Software Modem0\MANUAL\B26470A.EXE|>CSELECT.EXE [L] Win32:Malware-gen (0)
    File was successfully moved to chest...
    5/31/2010 7:49:31 PM C:\System Volume Information\_restore{E6281E8D-5BCF-412A-8532-C7FE9ECF653A}\RP30\A0016753.exe [L] Win32:Malware-gen (0)
    File was successfully moved to chest...
    5/31/2010 7:49:36 PM C:\System Volume Information\_restore{E6281E8D-5BCF-412A-8532-C7FE9ECF653A}\RP30\A0016755.EXE|>CSELECT.EXE [L] Win32:Malware-gen (0)
    File was successfully moved to chest...
    *

    I cleaned with CCleaner, TFC, turned off system restore. Also scanned with SpySweeper, Comodo Firewall, aSquared, along with SAS and MBAM. No detection with any of those. Full scans with Avast have found no further detection.


    Followed "READ & RUN ME FIRST".
    Unable to get ComboFix to run on desktop, even after disabling all anti-spyware, malware, and avast.

    Attached the four logs I could obtain.

    Your help is greatly appreciated in determining if the virus remains on the computer.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, melm

    You are not instructed to do this until your system is found to be malware-free.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Please run the below scanner and post the results:

    Using ESET's Online Scanner

    What malware problems are you still experiencing?


    dr.m
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avast is falsely detecting software for your Toshiba modem to be a problem. You need to restore whatever it remove since these are valid files.
     
  4. melm

    melm Private First Class

    Thanks for the replies. I really appreciate the help.
    I would have responded sooner, but the weather cut off my internet connection for some time.

    I automatically turned off system restore after Avast move the files to the virus chest. Sorry, it's a habit. I had also scanned with MBAM and the other programs right away. I did it a second time to save the logs, after I came to the MG Forum.

    I was able to run ComboFix in safe mode, but I don't know how effective it would be? I have attached that log with the ESET log.

    I'm afraid I can't restore those files removed by Avast. I attempted to extract and it only worked for a short time. Avast detected it in the same file a little while later, as well as the new place. Of course if I had left on system restore ... :-o

    Melissa
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Restore the files from Avast and then shutdown Avast's active protection ( or vice versa if necessary). Then uninstall Avast and download and install the current version since you are out of date. Hopefully they corrected the false detection.

    Either way, you are not having malware problems.
     
  6. melm

    melm Private First Class

    Thank you for your help. I appreciate the time you've taken.

    :wave
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Speaking for chaslang, also - "You're Welcome".

    * It is now time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)[/COLOR]
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! [​IMG]
     
  8. melm

    melm Private First Class

    Thanks again to both of you. :drool

    Will follow through.

    melissa
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds