Please help with Win32:Purityscan trojan

Can someone please help? Avast gives me the following warning:

A Trojan Horse Was Found!

C:\Documents and Settings\AdminAccount\Local Settings\Temporary Internet Files\Content.IE5\U5XPFPDK!update-3595[2].0000[UPX]

Win32:PurityScan-N [Trj]

It will not let me move it to the chest or delete it. When I try I get the following message:
"Cannot process “C:\Documents and Settings\AdminAccount\Local Settings\Temporary Internet Files\Content.IE5\U5XPFPDK!update-3595[2].0000[UPX]” file
The process cannot access the file beause it is being used by another process.

Hello :slight_smile:

Can you try to do a boot-time scan. Open avast! and in the menu choose “Schedule Boot-Time Scan” :wink:
Hope this will help :slight_smile:

I tried it. It deleted the virus but it returned once the computer rebooted. I turned off the System Restore but it did not help.

OK then try scaning your PC with Ewido - http://www.ewido.net/en/ and/or with a-squared FREE - http://www.emsisoft.com/en/ :wink:

I scanned with both of those but the Trojan is still there.

The process cannot access the file beause it is being used by another process.
Did you try scheduling a boot-time scan from within avast ? The file/process won't be in use then, I'm assuming you have XP.

Did you run Ewido or a-squared from safe mode ?

How did it get into here "C:\Documents and Settings\AdminAccount\ what is the significance of the AdminAccount ?
Have you changed the name of the Administrator account, or is this just another user account with admin privileges ?

Were you running the various scans from this account ?

I have tried a boot time scan. It deletes the trojan but it just reappears with the next boot up.
I’m not sure how it got to that location. I was messing around in iTunes when avast notified me of the Trojan.
Admin Account is just a name I put for that user. It has no special meaing or privileges.
I used both of the scanners in safe mode but again the trojan reappears with the next boot up. I still have system restore turned off.

Did you run a-squared and ewido to get clean?

I ran both. When i rebooted the trojan was there again

Did you run from Safe Mode?
Have you tried to delete the temporary Internet files?
To do this go to Internet explorer >Tools > Internet options > Delete files > Click delete all offline content (just to be sure) > click ok.
It might take some time to delete them.

Yes. I ran from safe mode and I also deleted the temporary internet files. It keeps coming back.

Hi mdbrock7,

There is a removal tool here: http://www.spywareremove.com/removePurityScan.html

Update your OS and patch your software fully, after your computer is cleansed install Ad-Aware, Spybot S&D & SpywareBlaster (free). Use one Anti-Virus and one Software Firewall solution only.

polonus

:slight_smile: Hi mdbrock7 :

  I have seen people with "Temporary Internet Files\  
  Content.IE5" on their computers having a difficult 
  time getting it removed ; If Polonus's Purity Scan
  Removal Tool does NOT remove it, I recommend you
  ask for help on the forums of your antiSPYWARE
  provider. Purity Scan is SPYWARE . If you know of no
  antispyware forums, I recommend www.landzdown.com.

Thanks for the help but I still cannot get rid of this trojan. Several of the programs recommended are deleting it but it always reappears at the next reboot.

Hi mdbrock7,

Another link to what this malware is about you can find here:
http://sarc.com/avcenter/venc/data/adware.purityscan.html

Whenever you do not succeed in deleting the malware yourself in safe mode, you could register and post at a specialist forum:
http://www.wilderssecurity.com/forumdisplay.php?f=81

Or download this tool and try to use this on it with the above knowledge:
http://www.majorgeeks.com/download4126.html

A final option you have is try to drive out the devil with beelzebub from here:
http://www.spyany.com/program/article_spw_rm_PurityScan.html

polonus

Thank you guys for all your help. I think that final suggestion has finally worked. ;D
I used the purity scan uninstaller from the last link that was suggested and it looks like that is the one that finally got rid of it.

Howdy mdbrock7,

Better do not mention this link here, because it is adware ridden, or obfuscate it.
Glad we could be of any help, thanx for reporting back to base.
Have a multi-layer defense, update and patch your OS and software, one resident anti-virus, one resident software firewall, ad-aware, spybot s&d, spywareblaster installed against adware/spyware, and on XP SP2 ewido or on older systems a-squared free against trojans. Surf safe and malware free. Welcome to our forum,

polonus

Please help with Win32:Purityscan trojan

Hi angiusandrea@tisca,

It would’ve been better to start a new topic, but have you tried a boot time scan with avast?

Also try these free and effective anti-Trojan/anti-spyware programs:

Ewido (XP’Win2000 only) http://www.ewido.net/en/

 and/or a-Squared [url]http://www.emsisoft.com/en/[/url]

Ad-Aware: http://www.lavasoft.de/

Spybot Search & Destroy: http://www.safer-networking.org/


Welcome to the forums, angiusandrea. :slight_smile:

After trying Frank’s suggestions above, you might also want to re-read another post in this thread at the link below …

http://forum.avast.com/index.php?topic=20203.msg169431#msg169431