Please Help With Removing This

pinktrol
edited July 2007 in Malware talk

hey there,


i have a problem, i run an online bitdefender scan and it found stuff but it didnt remove it. so now i dont know how to get rid of it :( please tell me what to do with it. i'm attaching the report. and the stuff found is: Generic.Malware.sp!.FC7A718F

/applications/core/interface/file/attachment.php?id=355" data-fileid="355" rel="">raport.rar

Comments

  • best of all download a trial version of bitdefender antivirus and make a complete scan.

  • Hello pinktrol


    Can you please copy the logfile into your next reply? So I can help you further. The reason is that only virus researchers can download attachments to prevent infections when somebody accidentaly downloads it. That is for all attachtments also for textfiles.


    Regards


    Niels

  • Hello.


    I've copied below the relevant sections of the log:


    C:\Documents and Settings\monisia\Moje dokumenty\My Music\Adware Away 2.2.6\AdwareAway.exe=>(Inno Installer o)=>(Inno Module 9)


    Infected with: Generic.Malware.sp!.FC7A718F


    C:\Documents and Settings\monisia\Moje dokumenty\My Music\Adware Away 2.2.6\AdwareAway.exe=>(Inno Installer o)=>(Inno Module 9)


    Disinfection failed


    C:\Documents and Settings\monisia\Moje dokumenty\My Music\Adware Away 2.2.6\AdwareAway.exe=>(Inno Installer o)=>(Inno Module 9)


    Deleted


    C:\Documents and Settings\monisia\Moje dokumenty\My Music\Adware Away 2.2.6\AdwareAway.exe=>(Inno Installer o)


    Update failed


    C:\System Volume Information\_restore{113B218D-ECEC-42B4-B883-AD5EFC861947}\RP110\A0025969.exe=>(Inno Installer o)=>(Inno Module 9)


    Infected with: Generic.Malware.sp!.FC7A718F


    C:\System Volume Information\_restore{113B218D-ECEC-42B4-B883-AD5EFC861947}\RP110\A0025969.exe=>(Inno Installer o)=>(Inno Module 9)


    Disinfection failed


    C:\System Volume Information\_restore{113B218D-ECEC-42B4-B883-AD5EFC861947}\RP110\A0025969.exe=>(Inno Installer o)=>(Inno Module 9)


    Deleted


    C:\System Volume Information\_restore{113B218D-ECEC-42B4-B883-AD5EFC861947}\RP110\A0025969.exe=>(Inno Installer o)


    Update failed


    My first suspicion was that this is a FP (False Positive), however I downloaded the program (I assume that the program in question is this), and it's not detected (the second set of files detected is from a system restore point and most probably is a copy of the same file). So:


    Please run an online scan again (so that you check with the latest signatures).


    And if the file is still detected, please attach the file in question (C:\Documents and Settings\monisia\Moje dokumenty\My Music\Adware Away 2.2.6\AdwareAway.exe) to your next post, so that we can take a look at it and determine the exact situation.


    Best regards.

  • Hello Cd-MaN


    I found this about Adware Away: http://www.spywaredata.com/spyware/threat_...AWAY/result.php


    and this http://www.malwarebytes.org/database.php?id=196 If you take a look these two sites labels adware away as a rogue application. But here it's labelled as a trustfull application: http://www.2-spyware.com/review-adware-away.html


    Regards


    Niels

  • The one I found looks quite legit (it doesn't try to scare the user into buying the full version or other things like that), however the broader picture needs to be known before any judgment can be passed (for example are other sites installing it without user consent). So it would be useful if pinktrol could confirm that this is indeed the application in question.


    Best regards.