Help! Avast found infections in \desktop\setupxv.exe and can’t move them to chest.
Previously Avast had found other problems which I moved to the chest. I also ran a bootscan which seemed to clear some others. Avast showed problems in C:\System Volume Information_restore… so I also disabled System Restore and ran another bootscan which left only this last problem untreated. This final scan was just of the C:\Documents and Settings\rich\Desktop folder.
I don’t seem to have any symptoms of a virus at the moment.
Thanks for your help.
Report file for the last scan is:
C:\Documents and Settings\rich\Desktop\SecureTD.zip\SecureTD.exe\AutoPlay\autorun.cdd_detect.dat [E] Archive is password protected. (42056)
C:\Documents and Settings\rich\Desktop\SecureTD.zip\SecureTD.exe\AutoPlay\autorun.cdd_proj.dat [E] Archive is password protected. (42056)
C:\Documents and Settings\rich\Desktop\SecureTD.zip\SecureTD.exe\AutoPlay\autorun.cdd_fonts.dat [E] Archive is password protected. (42056)
C:\Documents and Settings\rich\Desktop\setupxv.exe\ErrorSmart.msi\Icon.Icon.exe [L] Win32:Adware-gen [Adw] (0)
C:\Documents and Settings\rich\Desktop\setupxv.exe\ErrorSmart\ErrorSmart.exe [L] Win32:Rootkit-gen [Rtk] (0)
While moving file to chest, error occurred: The operation is not supported for this type of archive.
While moving file to chest, error occurred: The operation is not supported for this type of archive.
Infected files: 2
Total files: 1968
Total folders: 16
Total size: 987.6 MB.
Hijackthis gives:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:26 AM, on 11/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Remainder of file to follow in subsequent post.