Threat: Rootkit: hidden file

I’ve been fighting with this for a week and have reached the end of my rope. Tying a knot here and hanging on for some light to shine showing me what else I can do to reclaim MY machine.

Started with a linux download for another machine. It brought along a few friends grrr. Think I’ve gotten rid of the friends FINALLY! Unfortunately still have 2 to deal with.

I’ve tried everything - mbam, spybot search& destroy, dds, ansMBR, revo, and manually gone thru the registry. My full boot scans come out clean – YAY! However, the full system scans produce the following results:

2 - Threat: Rootkit: hidden file – I select delete and get:

Action postponed until next reboot

It shows the locations as:

C:\avast! sandbox\S-1-5-21-1499388306-1073519664-2816325193-1005\sfzone\C\Documents and Settings\fuscosue\Local Settings\Temp\CRX_DF399A9B283A\GoogleUpdateSetup.exe

C:\avast! sandbox\S-1-5-21-1499388306-1073519664-2816325193-1005\sfzone\C\Documents and Settings\fuscosue\Local Settings\Temp\CRX_DF399A9B283A\ChromeRecovery.exe

I’ve done numerous full system scans and boot scans. I do not use google nor chrome so I find it interesting it wants to update hah.

Any ideas where I can find these things cuz those paths make no sense to me… nor have my attemptsto find them been successful… help?!

Microsoft Windows XP Professional SP3
Intel(R) Core™2 Duo CPU T7300 @ 2.00GHz
Avast! Internet Security 2014.9.0.2008
Malwarebytes Anti-Malware (PRO) 1.75.0.1300

They are in the Avast sandbox… So clear the sandbox (safezone) and they will disappear

Ah, thank you. Haven’t figured out how to clear the sandbox in v.9x. Not liking the new UI - perhaps a little more help? Thank you.

OK here we go :slight_smile:

Select settings > tools > sandbox > customise > safezone
Then click reset

Thank You! Thank You! Thank You! Very much appreciated - all scans clean WOOHOO!