DECOMPRESSION BOMB!...?

??? I recently scanned my computer with the avast! Home Edition, and it picked up what seems to be a decompression bomb. Avast! is unable to delete it, move it, scan it, or store it in the chest. The file is an exe. located in System Volume Information so I can’t manually delete it either (access to that folder is denied) :cry: Can anyone help me delete this bomb?

Thank you for your time and effort.

Roger

To clean System Restore:

Create a clean restore point then delete all previous infected restore points

Firstly, deletion isn’t really a good first option (you have none left), ‘first do no harm’ don’t delete, send virus to the chest and investigate. Because of size it may exceed the size to move to the chest, these sizes could adjusted, Program Settings, Chest.

What is the suspect file name, where was it found e.g. (C:\windows\system32\suspected-file-name.xxx) ?
Check the avast! Log Viewer (right click the avast icon), Warning section, this contains information on all avast detections. It may not be there because it is just a suspected decompression bomb (just a file that when unzipped would be very large.

A long time ago this was a tactic to overwhelm your system possibly crashing it, so basically avast isn’t going to unpack it (just in case) because it could be very large. So it may not be a confirmed piece of malware just suspect.

However, if I had any suspicions about the future use of system restore I would clear all _Restore points so I had a clean start point.
The C:\System Volume Information folder is a part of the system restore function and as such is protected by windows, the only really effective way to clean infected _restore points is to disable system restore and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore.

The file’s name is MSSetup.exe in System Volume Information…

Actually, I believe it is a once downloaded setup application of the game MapleStory, but I remember deleting it a long time ago…

I would imagine that it would be very large (a setup file) file once unpacked. Normally it is only files that are in the system folders that are saved to the system volume information _Restore points by system restore upon deletion.

MapleStory Client Install - FileFront.com MapleStory Client Install from FileFront.com - Download MSSetup.exe. ... Filename, MSSetup.exe. File Size, 204.38 MB (214308696 Bytes) ...
And that is before it is unpacked, so quite large.

Since you are sure you previously deleted it I would say clear the restore points either using Franks suggestion or mine.

Decompression bomb is a file that may be rather small, but decompresses to an enormous amount of data (when processed as a packed archive). Such file are not malicious per se, but they may block an antivirus program when it tries to scan them. This kind of files is rather hard to detect (and avoid) precisely - so, it is possible that there are some false alarms. It’s not a big problem in this case, however - the “decompression bomb” announcement actually means something like “The file has a very high, maybe even suspicious, compression ratio and the AV is not going to scan the archive content”.

I’d suggest to ignore these files.
But you can change values into avast4.ini file to configure how avast should work with these files.
Click ‘Settings’ in my signature for more info :wink: