Hello,
A few days ago, just after I had turned on my laptop and was opening my internet browser (Google Chrome) I received an
Avast warning that a threat had been detected. The recommended action was to perform a boot scan. The boot scan identified one infected file:
File C:\Documents and Settings\All Users\Application Data{A2A58654-12AA-408A-B411-58A76959BE7F}\default.msi|>Data1.cab|listener.exe is infected by Win32:Malware-gen
However, when I tried deleting the file or moving it to the chest I received the following error message:
{The operation is not supported for this type of archive.}
I pressed Esc to exit the Avast boot-scan and ran MalwareBytes, which did not detect any infection.
I decided to also run MalwareBytes on my sister’s laptop which I had borrowed. Again MalwareBytes did not detect a problem
while the Avast boot-scan identified an infected file:
File C:\Program Files\Online Services\EarthLink\EarthLink Setup.exe|>$_OUTDIR\Windows\access\SpywareBlocker.msi|>Data1.cab|>ElShowSpyAbout.exe|>[UPX] is infected by Win32:Malware-gen
I chose “Move to Chest”, and Avast reported that the file had been moved to the chest. The boot-scan then continued and reported the following infection:
File C:\System Volume Information_restore{1368902D-6A36-4B35-812D-DDC763090AC0\RP207\A0038286.exe|>$_OUTDIR\Windows\access\SpywareBlocker.msi|>Data1.cab|>ElShowSpyAbout.exe|>[UPX] is infected by Win32:Malware-gen
I chose “Delete”, and Avast reported that the file had been deleted, and the boot-scan was eventually completed.
I am not sure why the removal appears to have been successful for the second laptop but not for the first. I’ve read some posts about Avast occasionally issuing false-positives so I don’t know if the alert (relating to “listener.exe” on the 1st laptop) should be a cause for concern.
I would be grateful if I could receive advice on how to identify and resolve the potential source of the problem.
I followed the instructions under the “Logs to assist in cleaning malware” topic by running OTL and aswMBR, and I have attached the generated files for both laptops (named A and B to differentiate the two laptops), since I am not so confident that the “ElShowSpyAbout.exe” has been deleted from the second laptop.
Is asking for help on two computers acceptable in the same post? If not, then help with either one of the laptops would be appreciated.
Thank you.
Mees