[b]UPDATE:
Ok, long story ahead, so please bear with me. This may stray out of the Avast subject, but since the initial occurence deals with Avast, I think I’m still on topic.
After I posted here, I also e-mailed Avast Tech Support and posted on another forum that I frequent.
Here is the reply from Avast Tech Support:[/b]
“Hi,
Don’t be afraid of some active infection. Your infected files are a parts of
webShield temporary stream. Avast saves downloaded data to your temp
directory, scans them and then forwards (if clean) or deletes (if infected)
them. But in this case the archive webplugin.cab was corrupted. This caused
some error (not critical, don’t worry), so Avast stopped the testing of
stream, blocked it, but didn’t delete these two files. That’s why Avast
found the infection again. As you said - Avast did correct cleaning by
“on-demand” scan, so now you are safe again.”
To which I replied:
"What is this archive “webplugin.cab” and if I deleted it, then will I have
issues in the future?
Why can’t i find the path C:\DOCUME~1\Paul\LOCALS~1\Temp ? Is this a Temp
folder that is created and then deleted by Avast?
Everytime that I have done an “on demand” scan (boot scan, regular scan,
boot scan with System Restore off, regular scan with System Restore off),
nothing has been found. The second time that the virus was detected by Avast
while running another product’s scan, I had Avast move it to the Chest and
then deleted it manually.
Is there anything else I can do to make sure that I am clean??? I really
try to keep security tight on my system and get very frustrated when stuff
like this happens."
I have not received a reply yet.
Someone on the other forums gave me a link to a Symantec tool specifically designed to remove te wupdt.exe virus. (fxIEplgn.exe) I ran this program and it provided this log:
Symantec Adware.IEPlugin Removal Tool 1.0.5
C:\Documents and Settings\All Users\Application Data\Microsoft\Money\11.0\Webcache\clear.gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\MPZ4D8RM\CAI3S16R.gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\OD2R8DQR\blank[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\OD2R8DQR\p_trans[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\STMJ09E7\blank[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\YVYYMV2P\blank[1].gif: (deleted)
C:\Documents and Settings\Paul\My Documents\General Computer Info\Belarc Advisor Current Profile_files\trans.gif: (deleted)
C:\Documents and Settings\Paul\My Documents\My Downloads\iRiver MP3 player\Regular Software and Firmware\firmware.aspx_files\s.gif: (deleted)
C:\Documents and Settings\Paul\My Documents\My Downloads\iRiver MP3 player\UMS Info and Firmware\ums.aspx_files\s.gif: (deleted)
C:\Program Files\Adobe\Photoshop Elements 4.0\shared_assets\webcontactsheet\antique paper\images\trans.gif: (deleted)
C:\Program Files\Adobe\Photoshop Elements 4.0\shared_assets\webcontactsheet\portfolio\images\trans.gif: (deleted)
C:\Program Files\Adobe\Photoshop Elements 4.0\shared_assets\webcontactsheet\vacation\images\trans.gif: (deleted)
C:\Program Files\Belarc\Advisor\System\local\images\trans.gif: (deleted)
C:\Program Files\Common Files\InstallShield\UpdateService\images\spacer.gif: (deleted)
C:\Program Files\Microsoft Picture It! 7\1033\Movies\spacer.gif: (deleted)
C:\System Volume Information: (not scanned)
C:\WINDOWS\I860\English\Windows\Photo\Other\spacer.gif: (deleted)
registry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main: Search Bar (value deleted)
registry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main: Use Custom Search URL (value deleted)
registry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main: Use Search Asst (value deleted)
registry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search: SearchAssistant (value deleted)
registry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl (key deleted)
registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main: Search Bar (value deleted)
registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl (key deleted)
registry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components: GeneralFlags (value set to 0x00000004 (4))
registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search: SearchAssistant (value set to “http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm”)
registry: HKEY_USERS\S-1-5-21-299502267-1425521274-725345543-1004\Software\Microsoft\Internet Explorer\Main: Search Page (value set to “http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch”)
Adware.IEPlugin has been successfully removed from your computer!
Here is the report:
The total number of the scanned files: 83404
The number of deleted files: 16
The number of threat processes terminated: 0
The number of other processes terminated: 0
The number of registry entries fixed: 10
[b]The guy (who I trust) said that most of these files were in my Temp Internet directory, so don’t worry about those. The others are just GIFs which are expendable too. He said that the “:” indicates that they may have been infected.
I then ran McAfee online scan, which also turned up nothing.
I also ran Spybot, also nothing.
Just to be sure, I ran the Symantec tool again, but it came back reporting that it cleaned 6 more files.
Log:[/b]
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\3FHFRXOW\blank[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\9O4RX189\p_trans[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\ATBOLKV2\1x1[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\CHY7QIBT\dotclear[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\CHY7QIBT\transpix[1].gif: (deleted)
C:\Documents and Settings\Paul\Local Settings\Temporary Internet Files\Content.IE5\OD2R8DQR\blank[1].gif: (deleted)
C:\System Volume Information: (not scanned)
registry: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components: GeneralFlags (value set to 0x00000004 (4))
Adware.IEPlugin has been successfully removed from your computer!
Here is the report:
The total number of the scanned files: 84759
The number of deleted files: 6
The number of threat processes terminated: 0
The number of other processes terminated: 0
The number of registry entries fixed: 1
[b]I was very confused by this point, since the tool alread said that it had removed the malware.
The guy said to consider it clean. He said he was not 100% sure that the tool just does not simply clean out GIFs from the temp directory and throw the “:” on the end of all GIFs for display purposes.
I then ran TrendMicro AntiSpyware Web Scan, which yielded these results:[/b]
Adware_ABetterInternet
Adware_ClearSearch
Dialer_7AdPower
None of my other scans turned up these programs.
I then went on a scanning rampage. Here is what i did yesterday:
System Restore OFF
TrendMicro AntiSpy for the Web
Detected:
Cookies (cleared out of browser after scan)
Adware_ABetterInternet - did not take action yet
Adware_ClearSearch - did not take action yet
Dialer_7AdPower - did not take action yet
MS Defender
- Found nothing in nightly scheduled full scan
- Found nothing in quick scan.
Ad-Aware SE - Full Scan Options - NO critical objects
Spy-Bot - No Threats Found
Rebooted to move Avast interface so I could see it in Safe Mode and download Symantec Tool.
Restarted in SAFE MODE
MS Defender - Found nothing in quick scan.
Ad-Aware SE - Full Scan Options - NO critical objects
Spy-Bot - No Threats Found
Avast! - Deep scan options - Nothing found
Ran Symantec Tool again - IEPlugin not found.
Rebooted into regular mode.
Ran TrendMicro Spyware Web Scan again, let it remove the 3 threats.
Ran HouseCall again, only cookies detected.
[b]Is this damn thing gone now or what? I can provided a HiJack This log if anyone can read it for me. Did Avast block the malware or not? Others suggest that it did block it, just not quickly enough. What is this directory that Avast claims the malware was located in the second and third time (while i was doing the other scans) and how did it get there if i deleted it??
I REALLY like Avast, and would actually consider paying for it if it were not free (which is a definate bonus), but I have to say that my confidence in it is a bit shaken.[/b]
PK