Adware.Gen virus removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by Faith007, Oct 31, 2009.

  1. Faith007

    Faith007 Private E-2

    Hello:

    I recently clicked on the wrong button when my Firewall gave me a warning about a potential problem (i.e., I clicked Permit) and I immediately got an Avira Antivir warning regarding a virus. So I ran AntiVir and got 4 virus detections. I chose the option to repair all and the problem files were renamed. Here is the pertinent section of my log file:

    Beginning disinfection:
    C:\dj960\win2k_xp\hpzglu04.exe
    [DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen
    [NOTE] The file was moved to '4b666c63.qua'!
    C:\dj960\win2k_xp\util\common\hpfpdi04.exe
    [DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen
    [NOTE] The file was moved to '4b526c63.qua'!
    C:\Program Files\Hewlett-Packard\HPZ\Glue\hpzglu04.exe
    [DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen
    [NOTE] The file was moved to '4af08054.qua'!
    C:\System Volume Information\_restore{359A55C2-FA23-4F19-9F1D-95A478A8B65D}\RP373\A0014949.exe
    [DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen
    [NOTE] The file was moved to '4b1c6c23.qua'!

    Do I need to do anything else? Should I delete those renamed files?
    And what exactly is this virus?
    Thanks for your help.
     
  2. Faith007

    Faith007 Private E-2

    I just saw the advisory about posting log files directly in the post. I'm not sure that it matters at this point, but here is the snippet from my Antivir log file as an attachment.
    BTW, my O/S is Win XP Home
    Thanks.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like Avira is just detecting files for your HP DeskJet 960 printer. So if you have this printer and installed the drivers, this is a false detection. Make sure you have the current version of Avira installed an that it is fully updated. If these are still being shown, you should report the false detections to Avira.
     
  4. Faith007

    Faith007 Private E-2

    I do indeed have this printer as well as an updated version of Antivir.
    I thought I'd go ahead and perform the entire Malware Removal process anyway.
    I followed the cleaning instructions carefully.
    One of the MGlogs files (newfiles.txt) says "Some malware is saving things here."
    So I thought I'd post all of my scan results, for your perusal. Wouild you mind taking a look at them? Thank You.
     

    Attached Files:

  5. Faith007

    Faith007 Private E-2

    Here are the last two attachments. Thanks again for your expert attention to this.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean, but you do need to uninstall the below and install the current versions.

    Java(TM) 6 Update 16
    Mozilla Firefox (3.0.6)
    SpywareBlaster 4.1



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  7. Faith007

    Faith007 Private E-2

    Problem: When I was doing the ComboFix uninstall, I received a number of Firewall messages asking for permission to perform an action. Since I thought the action was OK to Permit, I clicked "Permit" for each one.
    But then I got this message:

    Location of startup: FILE
    C:\32788R22FWJFW\HIDEC.EXE
    This trojan horse program was found on your machine.
    It has been shut down, but the fILE from which it started still remains and can be started up again.
    Do you want the file removed also?

    I clicked Yes and then clicked "Deny" to every other Firewall message asking for permission to perform an action.
    Please let me know what's going on here.
    Thank You.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These were all valid system changes that were occurring while uninstalling ComboFix. If you block changes from things that you are knowingly running (ie. you know you were uninstalling ComboFix) then you block the uninstall from working properly.

    C:\32788R22FWJFW is a temporary folder name used by ComboFix.

    And HIDEC.EXE is just one of a great many files/programs used by ComboFix.

    This is why instructions for using ComboFix state to shutdown protection before running it. This really includes even uninstalling it even though the instructions do not specifically state this.

    Even MGclean.bat makes changes to files, folders and registry keys to put things back to the defaults. If you get messages when you run it and stop them from running, you would also stop MGclean.bat from working properly.
     
  9. Faith007

    Faith007 Private E-2

    Yes, I really wish the uninstall instructions had mentioned to disable the Firewall. So what do I do now? Try the uninstall again?

    Thanks for the post.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In ComboFix.exe is still on your Desktop then start at step 2 again with protection disabled. If it is not on your Desktop, just continue at step 3 since MGclean.bat may remove the rest. Again it is best to disable protection while doing this so that you avoid unnecessary interference from your protection software.
     
  11. Faith007

    Faith007 Private E-2

    But isn't it dangerous to disable the firewall, even for a short period of time?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Potentially yes! Likely no! You could also just physically unplug your cable to the internet while doing this. The trouble with disconnecting while doing various uninstalls is that some programs require a connection to complete uninstalls. I don't believe ComboFix does as long as you are not at out date. However, you now are out of date. So before you could properly uninstall you would need to download the current version ( combofix.exe ) and save it to your Desktop. And you will need to use NEW instructions for uninstalling which are below:

    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    "%userprofile%\Desktop\combofix" /uninstall
    • Notes: The space between the combofix" and the /uninstall, it must be there.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds