Page 1 of 3 123 LastLast
Results 1 to 10 of 26
  1. #1
    Newbie
    Overall activity: 0%

    Join Date
    Mar 2008
    Posts
    14
    Liked
    0 times
    Points
    3,552

    AVAST 5 FREE SHOWING INFECTION OF WIN 32:malware-gen

    I have been using Avast Free for the last four years(with mixed kind of emotions)and recently switched to AVAST 5 FREE.While downloading and installing some app Avast went crazy and gave alarms about WIN 32:malware gen(quite sad because while downloading and prior to install that app ,I had repeatedly scanned it with Avast but nothing was flagged as malware at that time.The trouble started after installation of that downloaded app )As Avast Was unable to delete the infection(file being offline or read only,as informed by Avast)I did reinstall of C drive but the trouble prevails.Dependable utilities (i have been using for years like CCLEANER uTORRENT,Malwre bytes etc) are being flagged troublesome and it is just annoying to say the least.Repeated uninstall and reinstall of AVAST 5 have not resolved the issue and as a last resort,I wanted to scan the PC in safe mode but sadly again,AVAST CANNOT SCAN IN SAFE MODE:ERROR MESSAGE BEING-UNABLE TO START SCAN THERE ARE NO MORE END POINTS AVAILABLE FROM THE END POINT MAPPER

    while right click scanning of c drive ,Avast shows signs of WIN32:malware genbut not able to delete these or move to chest.Same is the case with boottime scan also

    So You Can imagine ,I am feeling helpless and irritated-doubting whether these are false alarms(PC is working Reasonably Ok,no issues of slow or crashes)because at start of any app,AVAST starts flagging these as malware but unable to do anything about these infection-MILLION DOLLAR QUESTION-WHAT IS THE POINT IN KEEPON USING AVAST IF IT CANNOT PROTECT FROM MALWARE OR DELETE IT IF DETECTED


    Meanwhile I have done couple of scans with AVAST 5 FREE and the report is as follows:

    avast! Real-time Shield Scan Report
    * This file is generated automatically
    *
    * Started on: Friday, March 05, 2010 5:33:53 AM
    *

    3/5/2010 5:40:45 AM C:\WINDOWS\SYSTEM32\OLE32.DLL [L] Win32:Malware-gen (0)
    While moving file to chest, error occurred: The specified file is read only
    During the file delete, error occurred: The specified file is read only
    3/5/2010 5:40:48 AM C:\WINDOWS\system32\core.dll [L] Win32:Malware-gen (0)
    File was successfully moved to chest...
    *
    * avast! Real-time Shield Scan Report
    * This file is generated automatically
    *
    * Started on: Friday, March 05, 2010 5:52:23 AM
    *

    3/5/2010 5:56:35 AM C:\WINDOWS\SYSTEM32\OLE32.DLL [L] Win32:Malware-gen (0)
    While moving file to chest, error occurred: The specified file is read only
    During the file delete, error occurred: The specified file is read only
    *
    * avast! Real-time Shield Scan Report
    * This file is generated automatically
    *
    * Started on: Friday, March 05, 2010 6:25:55 AM
    *

    As you can see Avast is detecting the infection but is not able to remove it

    C:\WINDOWS\winstart.bat
    Error:File is offline-it is currently not available(ERROR 42006)

    C:\WINDOWS\SYS32\ole32.dll
    threat high Win32:Malware-gen
    The Specified file is read only(Error 6009)

    I hope this new info helps you to help me in this lousy situation

    Funny thing is I canot do the scan in SAFE MODE-The error message from AVAST is

    UNABLE TO START SCAN.THERE ARE NO MORE END POINTS AVAILABLE FROM THE END POINT MAPPER

    Any idea what it implies?


    Any suggestions as to how to resolve this issue are most welcome and appreciated

    q2na

  2. #2
    Experienced User
    Overall activity: 0%

    Join Date
    Oct 2009
    Location
    Chennai
    Posts
    474
    Liked
    2 times
    Points
    6,676
    Scan using MBAM and see what happens.

  3. #3
    Banned
    Overall activity: 0%

    Join Date
    Jul 2009
    Location
    safeguy is homosexual
    Posts
    297
    Liked
    0 times
    Points
    2,973
    http://forum.avast.com/index.php#2

  4. #4
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Hi
    C:\WINDOWS\SYS32\ole32.dll

    SYS32 is not a Windows system folder.

    more: are you using Windows 3.0?
    C:\WINDOWS\winstart.bat

    http://support.microsoft.com/kb/69186/

  5. #5
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Windows 3.0 isn't a 32 bit OS... it's a 16 bit one.

    Mind posting a HijackThis log? for us, because it sounds like it's badly infected with something. And on top of that, Avast sounds like it's been corrupted...
    pacman -Syyu life not found in sync db

  6. #6
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Quote Originally Posted by hellnoire View Post
    Windows 3.0 isn't a 32 bit OS... it's a 16 bit one.
    That's the strange thing


    You can create a batch file called WINSTART.BAT to load memory-resident utilities in Windows applications. This gives you more conventional memory to run DOS applications under Microsoft Windows version 3.00. Microsoft LAN Manager and some other network drivers will not load properly using WINSTART.BAT. If the network driver does load, an error message is displayed on exit because there is no way to unload the driver.

    apart of hellnoire's legit request of a HJT log.
    I suspect a TDS3 rootkit infection and an incompatibility with MS critical update MS10-15 (february).

    You may also check if your OS is compatible with MS10-15

    http://support.microsoft.com/kb/980966

    Then try to remove TDS3 Rootkit and other malware with HitMan Pro 3.5 (30 days free trial)

  7. #7
    Verified Member
    Overall activity: 0%

    Join Date
    Dec 2009
    Posts
    300
    Liked
    0 times
    Points
    3,229
    This is surely some sort of serious malware infection which is infecting all other EXE's and also have corrupted Avast. As suggested by members above, dload a fresh copy of MBAM and HijackThis. Update MBAM, do a full scan and post the log back here.

    Also post a HJT log.

    PS- Before dloading above tools, rename them to any random name.

    Alternatively, u can also use rescue discs.
    There is no best that cannot be bettered.

  8. #8
    Banned
    Overall activity: 0%

    Join Date
    Oct 2009
    Location
    Earth
    Posts
    790
    Liked
    113 times
    Points
    16,820
    Quote Originally Posted by Ranjan View Post
    Alternatively, u can also use rescue discs.
    Try this one.(avira resque cd)
    Last edited by LizardMan; 03-06-2010 at 12:31 AM. Reason: Automerged Doublepost

  9. #9
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    TDS3 rootkit infection
    If your box is rootkited then it requires high level work of disinfection. Time to back-up your files and start the war...

    Avast or any AV solution can kill this threat if its detected before execution, but once executed inside the system then it is a very different story.
    Last edited by Ceyfer √; 03-06-2010 at 12:48 AM. Reason: added link | Norman TDSS Cleaner.
    "Stars and the Sun"


  10. #10
    Modern-day Romeo
    Overall activity: 0%

    Join Date
    Jul 2009
    Location
    Singapore, the "Little Red Dot" on the map
    Posts
    6,159
    Liked
    476 times
    Points
    61,007
    Quote Originally Posted by ceyfer View Post
    If your box is rootkited then it requires high level work of disinfection. Time to back-up your files and start the war...

    Avast or any AV solution can kill this threat if its detected before execution, but once executed inside the system then it is a very different story.
    Mind telling us what's the different story like? How do we go about removing such deep-level infections?
    They call me the mysterious one...
    my motto is...when it's hot, chill baby

 

 
Page 1 of 3 123 LastLast

Similar Threads

  1. Replies: 177
    Last Post: 01-06-2011, 11:08 PM
  2. how a Mac user can be tricked into a malware infection
    By leofelix in forum Spyware/Viruses
    Replies: 4
    Last Post: 06-12-2010, 12:30 AM
  3. manual instalação avast - segurança avast
    By jupreta in forum Software
    Replies: 2
    Last Post: 04-23-2010, 09:24 AM
  4. Replies: 39
    Last Post: 03-27-2009, 06:50 PM
  5. Replies: 8
    Last Post: 10-23-2008, 12:58 AM
All times are GMT +8. The time now is 08:53 AM.