Boot scan asking if sure file is in Windows folder, infected w/ Webcake-A [Adw]

I just downloaded avast and ran my first Boot scan…78% in with 13 threats sent to the Chest the following threat popped up…

C:\Windows\Temp_avast_\unp19548534.tmp … Threat: Win32:Webcake-A [Adw] …it asks me…

File is in Windows folder, are you sure? 1-Yes, 2-Yes all, 3-No, Esc-Exit …which should I choose???

The threat has the word Avast in it which really puzzles me as to how my brand new antivirus software flagged itself and is labeled in a detected threat…

I didn’t know what to do so I hit Esc and exited the scan…the detailed report said… Error: The system cannot find the file specified (2)…

I was wondering if anyone could please please help me and let me know what I should do before I take further action or go running the scan again…any help would be greatly appreciated :slight_smile:

Thanks,
Chris

The threat has the word Avast in it which really puzzles me as to how my brand new antivirus software flagged itself and is labeled in a detected threat...
it is not flagging itselfe...it is the folder where avast unpack files for scanning
C:\Windows\[b]Temp[/b]\_avast_\unp19548534.tmp
you can clear temp folders with TFC cleaner

TFC-cleaner http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/

That file A) isn’t in a windows folder as such, but a temporary folder, B) it is only there because avast extracted it there for scanning. That folder may subsequently have been cleared by avast and why you got the Error: The system cannot find the file specified. So I don’t think you have any further action to take in regard to this file.

The avast folder is where avast unpacks archives and or sends copies of files for scanning. It isn’t flagging itself but a temporary file sent to that location for scanning.

The issue is that after successful scanning the contents of that avast folder should be cleared, so something appears to have prevented that happening. This is commonly down to having other security based software installed on the system that would lock the file so that it can scan it.

  • Have (or did) you another Anti-Virus installed in this system, if so what was it and how did you get rid of it ?

Thanks so much for your help I think I’m starting to understand…I was wondering then…if it asks me again if its in a Windows File I should say NO?

To answer your question…I previously had Mcafee which came on this Dell Inspiron Laptop(Windows Vista) and has long since expired…I don’t remember how I originally got rid of it but right before I downloaded Avast I deleted the only McaFee thing I saw left in the program files…I havnt seen anything pop up from them in ages…maybe it’s not completely gone? The only thing I have had running was Windows Defender…I don’t know if its still active or if Avast stopped it but I know after scans by Avast some of the problems I was having were instantly gone.

run McAfee removal tool and reboot. http://singularlabs.com/uninstallers/security-software/

Unfortunately there isn’t a simple Yes, No answer as there are many sub-folders within the Windows folder and there are also many files within the windows sub-folder structure that actually aren’t ‘windows’ a.k.a. Microsoft/system files. So it would only apply to contents in this avast sub-folder.

As for ensuring other AV remnants are gone:

Antivirus Remover is a handy application that will bring you the uninstallation program for any of the supported security software listed in the main window.
Requires .NET Framework 4.0

Re Windows Defender (WD):
This shouldn’t be a problem if you aren’t using windows 8.0 or 8.1 as that version is essentially Microsoft Security Essentials re-badged as WD. So for other OSes not an issue, but it brings very little to the party, so most would disable it in windows 7 as it can’t be installed. For earlier OS versions I think that WD has to be downloaded and installed, in which case I would suggest uninstalling it.

Again thanks for the helpful information…I ran the McAfee removal tool…it said it was removing a bunch of stuff then rebooted…not long after that my computer completely froze…I had to hold the power button and reboot.

I decided to run the McAfee removal tool again…one more time as I was curious to see if it worked the first time and to see what would happen and what it would tell me…sure enough the same progress bar went across telling me it was removing the same things it said it had the last time…taking the same amount of time too…

So now I’m wondering if McAfee is full of it…why would it say it was removing stuff that it had already removed last time I ran it? I think this might even be the same method I used to remove McAfee back in the day. If it really is off of my computer why wouldn’t it just tell me there’s nothing to be removed? Any thoughts on this? It’s driving me insane…is it really removing it or wasting my time?

Thanks again,
Chris

Attach OTL diagnostic log then essexboy will take a look inside later today

Instructions here http://forum.avast.com/index.php?topic=53253.0