Welcome, Guest. Please login or register.
November 19, 2008, 05:30:48 AM

Login with username, password and session length

212388 Posts
24553 Topics
57740 Members

Latest Member: pino

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  win32 adware gen [Resolved]
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: win32 adware gen [Resolved]  (Read 17488 times)
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« on: June 24, 2007, 01:32:39 PM »

My avast 4.7 has found this adware, no mattert how many times i delete it the thing returns ! Herlp would be appreciated
« Last Edit: June 30, 2007, 10:13:46 AM by justin1278 » Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #1 on: June 24, 2007, 04:35:09 PM »

Hi stuartm,
Do you have the last release of CBO installed and updated?
Logged

Parched dry and thirsty, knee deep in the river of life.
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #2 on: June 25, 2007, 02:04:18 PM »

Yes i have! Tried trends housecall aswell! It keeps coming back
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #3 on: June 25, 2007, 02:27:33 PM »

When you say "It keeps coming back", are you saying Avast detects it on a manual scan?
What is the name and location of the detected file?
Logged

Parched dry and thirsty, knee deep in the river of life.
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #4 on: June 25, 2007, 03:16:13 PM »

Avast detects it during normal protection! It says i have a sign of win32 adware found in the c files. Stuart
Logged
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #5 on: June 25, 2007, 03:19:08 PM »

That should have been win32 adware gen[adw]
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #6 on: June 25, 2007, 03:32:48 PM »

Avast detects it during normal protection! It says i have a sign of win32 adware found in the c files.
Can you be more specific as to the name and location of the detected file(s)?
Did you turn off System Restore?
Logged

Parched dry and thirsty, knee deep in the river of life.
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #7 on: June 25, 2007, 03:39:00 PM »

Avast says its a virus in local disc c originally it was called something like spam blockability no i havent turned off system restore or done a restore!
Logged
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #8 on: June 25, 2007, 03:54:55 PM »

avast mentioned it was in karnell32.dll c:\windows\system 32 & winsock.dll
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #9 on: June 25, 2007, 08:56:18 PM »

Couple more things.. Has CBO updated?
Try rebooting to see if CBO sees it then.
Turn off your System Restore so it doesn't cache a copy then re-scan in safe mode to see if your AV will catch it then.
Logged

Parched dry and thirsty, knee deep in the river of life.
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #10 on: June 26, 2007, 10:12:07 AM »

Boclean upto date. I'm new at this game could you run me through how i do your to suggestions
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #11 on: June 26, 2007, 04:05:03 PM »

Sure, assuming your running an NT OS such as 2k or XP and not anything earlier...
First, to turn off your System Restore you'll need to access your "System Properties" (which can be done by right clicking the "My Computer" icon either on your desktop or in your Start menu) and choosing "Properties".
In the System Properties window, click on the "System Restore" tab and check the box "Turn off System restore on all drives" and then hit the "Apply" button.
To turn it back on simply recheck the box and apply again. Rescan with AV.

Next, turn your computer off and restart it, this allows CBO a chance to kill the infection before it initializes.
If CBO doesn't see anything at this point you'll want to get into safe mode.
Restart your computer again but this time as your computer restarts but before Windows launches, press F8.
Use the arrow keys to highlight the safe mode option, and then press ENTER.
There might be a prompt asking if you want to use System Restore that you'll have to decline.
After you're logged into your account see if you can run your AV scan.
Logged

Parched dry and thirsty, knee deep in the river of life.
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #12 on: June 27, 2007, 09:40:51 AM »

Virus seems to have been deleted now! If it returns i shall do what you advised. When i turn off (apply)system restore im told if i press yes all restore points will be lost is this advisable? Thanks
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #13 on: June 27, 2007, 01:20:56 PM »

Virus seems to have been deleted now!

May I inquire what you did that deleted it?

Quote
If it returns i shall do what you advised. When i turn off (apply)system restore im told if i press yes all restore points will be lost is this advisable? Thanks
That is correct, once System Restore is seeded with an infection, there's no point in keeping the restore points unless you want to re-infect your box.
Logged

Parched dry and thirsty, knee deep in the river of life.
stuartm
Comodo Loves me
****
Offline Offline

Posts: 136



« Reply #14 on: June 28, 2007, 08:57:57 AM »

Yes i ran superantispy, lavasoft adware and trend micro all had adware for me to remove since then avast has detected nothing. I have also scanned online with a squared scan only that detected nothing. I now remember how i got this adware it was on a site where an item appeared which said press now  to recieve no spam! Stupidly i pressed cos my attention was elsewhere(think it was called spamblockability) Thanks Stuart. ps I hope it don't come back
Logged
Tags: win32 adware gen 
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.657 seconds with 20 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com