Boot time scan

Hi,

Recently I had a logon/logoff loop problem with Windows XP. I was able to get back in, and I installed the Avast! antivirus home edition 4.8 in safe mode. I installed it from a CD I burned using my other computer. I restarted the computer, and it proceeded to do a boot time scan.

As the boot time scan was going, it would stop and ask me what I wanted to do with certain files. I was unsure in what to do, so I would always tell it move it to the chest. Towards the end of scan, it started showing up files from the C:\WINDOWS folder. I told it to move it to the chest, but then it asked if I was sure. I had no clue what to do, so I just chose to select ignore for all the files in the WINDOWS folder.

When the scan was done, I accidentally logged back into normal mode and I immediately logged out and rebooted in safe mode. As I logged back in into safe mode, nothing from Avast! popped up, so I went into the folder in program files and tried to open the log. The thing is I can’t open any text files in safe mode or right click on any files without it flashing and closing all my windows. I also tried to open the chest, but it either wasn’t working or wouldn’t show anything (I forget). I didn’t know what to do at this point, so I then started Avast! through the shortcut. It started to search the operating memory or something (I forgot the exact words). When an infected file showed up, I tried to send it to the Chest, but it said “Virus chest server is not running. RPC communication failed.”. I had disconnected my network cable earlier when it suggested to do this. It kept searching the memory still, but then it found a virus. It told me to do a boot time scan as it was dangerous to continue.

So right now I’m doing the boot time scan again, but I’m unsure as to what I need to with all of the affected files and the ones it finds in the WINDOWS folder. At this moment, it stopped at another file, but I don’t know what to do.

The file it’s on right now is C:\System Volume Information_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0197388.dll infected by win32:Trojan-gen {Other}

I did read something about restore files or something, would this classify as I see the word restore in the file name?

Sorry, I don’t have any experience with Avast! and removing viruses at all.

You might have quarantined important windows files.
Try using system restore.
If that doesn’t work, get your windows cd and run system recovery.
Then scan the PC again.

a file that locked doesn’t mean it is infected.

Here’s some information I was able to write down on a piece of paper as the first boot time scan was running.

These were some of the things that were affecting it.

win32:Trojan-gen {Other}
win32:Agent-ADXT [trj]
JS:Fake AV-G [trj]
win32:Adware-gen [Adw]
win32:JunkPoly [Cryp]
win32:Rootkit-gen [Rtk]

These were the files in the SYSTEM folder that I ignored.

C:\WINDOWS\KBDCME.dll affected by - win32:Trojan-gen {Other}
C:\WINDOWS\SYSTEM32:svchosm.exe infected by - win32:Agent-ADXT [trj]
C:\WINDOWS\SYSTEM32\BNetAuth.dll infected by - win32:Trojan-gen {Other}
C:\WINDOWS\SYSTEM32\legadeto.dll.tmp infected by - win32:Rootkit-gen [Rtk]
C:\WINDOWS\SYSTEM32\sdfgerfgf34.dll infected by - win32:Trojan-gen {Other}
C:\WINDOWS\SYSTEM32\sewoladu.dll.tmp infected by - win32:Rootkit-gen [Rtk]
C:\WINDOWS\SYSTEM32\tipigola.exe infected by - win32:JunkPoly [Cryp]
C:\WINDOWS\SYSTEM32\zafekewu.dll.tmp infected by - win32:Rootkit-gen [Rtk]
C:\WINDOWS\Temp\bip7a1q2.exe infected by - win32:Trojan-gen {Other}

This is the one file from the SYSTEM folder that I moved to chest.

C:\WINDOWS\SYSTEM32\DRIVERS\2558dc14.sys infected by - win32:Trojan-gen {Other}

All other affected files that showed up, I moved to the chest.

Try cleaning the filesthat you have ignored. If they can’t be cleaned, send them to virus chest.
It looks like that the files you ignored are viruses/malware because they have weird names.

do you have malwarebytes anti-malware?
If not, download, install, update, and run a scan with it.
http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button

post here the results.