SLOW. oh my gosh, is it ever slow.

What are you waiting for? ;D

I forgot to mention that prior to the steps mentioned in my last message, I had also run avast’s simple interface scan of the offending archives in Windows safe mode. It had found the same files but also been unable to delete them without errors.

Anyhow, now I’ve done the full restart with the scheduled boot-time scan.
That came up with no virii, but if I understand correctly, the boot-time scan does not scan archives, so I’m not clear on how that tip was helpful.

I am now back in standard Windows (evidenced, I suppose, by the fact that I am able to post here), and I’m running a simple interface scan of the C:/D&S./Me/Local Settings/AppData./MS./Outlook folder, which is where the .pst files are kept on my computer, including the archives. Well, now there is just the one archive, since I deleted the outlook backup.

Aha! it just finished. 0 infected files. 2.6GB scanned in 13,080 files in the 1 Outlook folder.
That’s using VPS: 0531-0, 08/01/2005
I’m releasing my breath for a second.

Avast does seem, after much wrangling, to have at least found the 30 OLD infected files that Norton AntiVirus did not, after running nightly for YEARS, in the case of some of the infected files.

My book: that’s HUGE, even though avast could not successfully address the threats without my manually deleting the specific files that it found.

Avast appears to have addressed several major infections, at least for the moment.
I’m running the downloaded avast cleaner again, to be on the safe side, and to see if it will also yield zero.

A question I have is whether the Avast Cleaner Tool digs into the archives. By the way, the icon for that service, a blue & purple glazed pouring vessel, ranks high among the loveliest icons I have EVER seen.

I’m going to go ahead & track down the two much-previously mentioned anomalies, which I am perceiving as somewhat less onerous in comparison to the infections.

I also forgot to mention that my other important reason for recording the drama here is to preserve my own sanity by protecting against repetition of steps. Lest ye find my last comment nauseatingly pseudo-altruistic, as did I. :smiley:

Another detail I’m digging on is that the earlier boot-time scan report showed the following errors:

08/01/2005 16:37 PST
Scan of all local drives
File C:\Config.Msi\10ae5b1.rbf Error 0xC0000022
File C:\Config.Msi\17d60ef.rbf Error 0xC0000022
File C:\Config.Msi\edb2f3.rbf Error 0xC0000022
File C:\Config.Msi\ffab47.rbf Error 0xC0000022

Number of searched folders: 10706
Number of tested files: 140388
Number of infected files: 0

Ah.
I see that this also yields the answer to another question I asked earlier. Since the 3-day scan involved over 300,000 files tested, I think it can be safely said that the boot-time scan does not dig into archives.
Probably says that elsewhere in the forum.

Avast Cleaner still scrubbing…

Nothing found googling on the specific config.msi errors…Anybody?

No reference to any of the number-named .rbf files, anywhere else on the web, per google.

However,
http://filext.com/detaillist.php?extdetail=RBF
yields the following:
.rbf probably=Rollback File (MS). (There are a few other possibilities, but I don’t use the other programs mentioned.)
The .RBF files and the config.msi folder are used by the Windows Installer rollback process. The rollback script (.RBS) file is always stored in the Config.Msi folder on the drive where the operating system is installed. The .RBF files are stored in the Config.Msi folder located on the drive where the application that is being backed up currently resides. This is done so that there is no crossing of drives when backing up the application files. Files with a RBS file extension are rollback script files and files with a RBF file extension are backups of existing files. All rollback files and the Config.Msi folder are deleted when the installation completes successfully.

Also, http://castlecops.com/print-1-21024.html
indicates
“Rollback script files (.rbs and .rbf) are backups of existing files. Files with a .rbs file extension are rollback script files and files with a .rbf file extension are backups of existing files, both are stored in hidden folders called Config.msi. The Config.msi folders are created when Msiexec.exe starts copying from the installation point.
Office 2000 allows you to rollback an installation of Office if installation unexpectedly quits before completion or you intentionally quit the installation process. This means that your previous installation of Office is restored to its original state even if you cancel Setup in the middle of overwriting your Office files.”

The “Error 0xC0000022” seems to connote that “The application failed to initialize properly”, in a wide variety of contexts.
According to Microsoft, 0xc0000022 means that a program needs administrator rights in order to run.

I have no idea how to integrate this information into the problem at hand.
Does it mean that Avast is unable to scan .rbf files?
Why would that be?
Also, why would the files be there at all, if Office was properly installed?


Furthermore, the avast cleaner has finished its scan, with the following results:
avast! Virus Cleaner Tool - version 1.0.207 Unicode

Creating log file: C:\Documents and Settings\Pat Duff\My Documents\My Downloads\Avast\aswclnr.log

8/1/2005, 6:44:29 PM
Memory scanning started…
No virus body found in memory.
Memory scanning finished (31.0s).

Files scanning started…
C:\WINDOWS\Temp\Perflib_Perfdata_57c.dat… file could not be scanned!
C:\WINDOWS\Temp\Perflib_Perfdata_65c.dat… file could not be scanned!
C:\WINDOWS\Temp\ZLT0711c.TMP… file could not be scanned!
No virus body found.
Files scanning finished (139174 files, 0 infected, 4365.0s).
Drives scanned: C:

more questions, now: Why can’t these files be scanned?
I would like to return to my usual life very soon.

On the perflib issue:
http://support.microsoft.com/default.aspx?scid=kb;en-us;285798

"SUMMARY
Files with the name Perflib_Perfdataxxx.dat may accumulate under the %SystemRoot%\System32 folder, where xxx is a random number.
MORE INFORMATION
These files are generated by processes in the normal course of operation; however, files are orphaned when you do not shut down a computer properly, such as by pressing the power button on a computer.

Note: It is also possible that these files can be orphaned while a server is running. Microsoft is researching this problem and will post more information in this article when the information becomes available.

To delete the orphaned files, you can use an automated logon script."

(Which MS does not reveal)
However, at
http://www.experts-exchange.com/Operating_Systems/Q_20351139.html
I found:
"The best way to remove these files is to add a command in a logon script:

del /q %SystemRoot%\System32\Perflib_Perfdata*.dat"

This seems appropriate, since I show 4 instances (not one), but I’d love some confirmation on that, if anyone has experience. ???

Also, is there a similar routine for the 4 .rbf files previously mentioned in this thread? ???Since they too seem to be the results of improperly terminated processes, would that be appropriate? ???

Also specific instructions on the process for entering such commands in a logon script would be very helpful. ???

One of the problems when dealing with email folders especially in Outlook is the folder is in fact a single file (database) containing all the emails and the difficult part is removing/extracting a single email without corrupting the database file.

This is not just a problem for avast but other AVs as well and is more to do with the method that these emails are contained in the database file. avast! can remove individual emails from within Outlook Express email folders (.dbx files) without corrupting them. Some AVs don’t even attempt to extract infected emails from the folder rather delete the complete .pst or .dbx file.

So the obvious advantage in avast is the scanning of email before it is send to your inbox, etc. and not having to do it in a routine HDD scan.

You’re fully right. Besides this, some users recomment the Standard Shield to do this job. The problem will be the same: *.dbx or *.pst could be corrupted. Better is to use the specific email provider.

What I do before scan the virus are to delete files in internet temp dir and cookies dir. This will cut down on time to scan. :smiley:

If someone could provide a link to the details on how to either ‘upload’ or ‘paste’ a screenshot here, that would be very helpful.

I hadn’t gotten 'round to canceling the scheduled early-morning quick scan yet, so it did another one this morning.
One oddity I noticed was that the final
‘avast! QuickScanner’ window notes the ‘Number of tested files: 485697’,

whereas the overlaying popup report
‘Final statistics for last scan’
notes a smaller number:
Number of scanned files: 483913
Number of scanned folders: 10725
Total size of scanned files: 41.7 GB
Number of infected files: 0
“C:”
What’s that about?

Well, there are so many questions in this thread that it’s really hard to find what to answer. So, a few things:

  • decompression bomb is just something that unpacks to an unusually big amount of data even though it’s rather small (i.e. has a high compression ratio, for example). It’s nothing to worry about, you are just informed that avast! will not try to unpack the archive (you may not even know that it’s an archive, but it seems like it is) because it may take VERY long to process.

  • avast! Virus Cleaner doesn’t scan archives and the report you received is perfectly normal (some files cannot be accessed during the runtime of the operation system becase the operation system doesn’t allow it).

  • the scan time you posted (days) seems really way too long for 40GB of data (unless you are using a very slow machine, or running some other CPU or disk-intensive application on background).
    Aren’t you running multiple scans together (Quick scanner, Simple UI, Cleaner…)

  • the Quick scanner was meant to be used for simple “quick” scanning, not for full system scans, even using Scheduler (that’s why the Professional version of avast! has its own task scheduling). While you can use Windows scheduler to start ashQuick, you don’t get very thorough output. Also, whenever a malware is found, the scanner stops and waits for your input (action to take).
    I’d suggest to run just a single scan using Simple UI (in my opinion, Standard scan including Archives should almost always be enough), and possibly turn on the creation of the report file in program settings (including everything, even “OK files” there) before you start. This way, you can always check the end of the report file and see what is being scanned - if you think avast! is stuck.
    If archive scanning is enabled, it really can take a lot of time to scan the Outlook mailboxes, for example (depending on how much emails you have archives, of course).

  • are you saying the the Quick scanner “progress” window shows 485697 files and the “Final statistics” window of the same Quick scanner, at the same moment, shows 483913 files? That certainly would be strange… no idea how anything like that could happen.