Confused

Hey all. I am having problems with viruses. I am 15 years old and I am having problems with Avast 4 Home Edition. It found 5 viruses but I could only delete 1 of them. I have a print screen to show you.

http://i139.photobucket.com/albums/q295/UnrealTournament99/untitled.jpg

It’s kinda small but the 4 highlighted viruses found I can’t delete. 3 of them are in my C:\Sound Volume Information flder, but there is 1 problem. I don’t have a Sound Volume Information folder in my C drive. I can’t delete them through Avast 4 or manually(because I can’t find them, and I don’t know how to delete them other than send them to my Recycle Bin. If I delete it manually should I send it to my Recycle Bin and then empty the Recycle Bin?) Is there a way to delete these viruses throught Avast? Also my homepage on the internet has changed to a fake AntiVirus program, and every time I try to change it, it switches back to the fake AntiVirus site. Is there a way to fix that also?

Thanks all for any help!

First deletion isn’t really a good first option (you have none left), ‘first do no harm’ don’t delete, send virus to the chest and investigate.

It is System Volume Information not ‘sound’ this folder is usually hidden so you nee to ‘show hidden files and folders’ in Explorer, Tools, Folder Options to see them.

The C:\System Volume Information folder is a part of the system restore function and as such is protected by windows, the only really effective way to clean infected _restore points is to disable system restore and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore.

Well I can’t get it to show up. You are right it is System not Sound. But when I click on show hidden folders and files all I get is files. I don’t know what they are of but it’s not showing that folder. What should I do now?

Also how can I fix my homepage. I switch it but it just goes back to the other one I don’t want. It’s a fake site I think and the address bar just says http//asecurityservice.com. If that turns into a link please don’t click it. It might give you a virus. But also a popup comes up. This is what it looks like:

http://i139.photobucket.com/albums/q295/UnrealTournament99/untitled-1.jpg

Again I’m sorry it’s so small. But it still hopefully will get the point across and you will maybe be able to read it.

Did you try to scan with avast at boot time?
Did you try antitrojan scanners (AVGas, SpywareTerminator, SuperAntispyware) and antirootiks?

You don’t really need to be able to see the system volume information folder to be able to clear it out by disabling system restore and rebooting.

I can’t be much practical help as I don’t have the system restore enabled (I use something else to provide that protection) and don’t have those folders displayed on my system even though they were empty, they used to be there. So I don’t know if this is a security update giving extra hidden status.

Windows XP System Restore Guide

Your browser has effectively been hijacked so the tools mentioned by Tech should be able to root out that issue.

If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode.
AVG anti-spyware (formerly Ewido). Or SUPERantispyware Or Spyware Terminator.

If you have been getting any pop-ups related to your infected warnings it may also be a rogue program at work. A new tool RogueRemover, available here http://www.malwarebytes.org/rogueremover.php

Thats what I have are trojans. Which would be the most effctiv do youboth think. I’m not really sure of what to use.

I recommend using Spyware Terminator for real-time protection. Use AVG anti-spyware (formerly Ewido) & SUPERAntispyware for on-demand scanning. Turn off scheduled scanning in Spyware Terminator, its an annoyance.

Spyware Terminator is completely free. The free versions of AVG anti-spyware & SUPERAntispyware are
on-demand only.

I would start with what is the easiest to download and run RogueRemover it is a one of specialist tool and see if that returns and report back.

Then I would download and try AVG-AS followed by the others in order if required.

WOW! RougeRemover worked great. It was a super fast scan, but it seemed to be VERY accurate on what it was scanning. I can keep my homepage, it won’t change. I’m not sure if I still have viruses but I am scanning with avast! right now to check. Thanks everyone!

No problem, welcome to the forums.

Though it would have been nice to see what rogueremover reported/removed.

Yoy would also be advised to have a specialist anti-spyware application installed, either AVG-AS 30 day trial with resident protection then reverts to free version no resident protection or auto updates and on-demand scans.

That would allow you to also use SuperAntiSpyware after the avg-as trial period (or disable the resident protection in avg-as) which as rdmaloyjr mentioned gives resident protection.

Yes, that’s the secret. It does very well what it is intended to do.