Won’t allow me to delete the files nor put them in the chest. Just tells me cannot due to type of archive. Any suggestions?
edit : I forgot to mention that it is Win32 - Adware -gen
Won’t allow me to delete the files nor put them in the chest. Just tells me cannot due to type of archive. Any suggestions?
edit : I forgot to mention that it is Win32 - Adware -gen
What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?
Check the avast! Log Viewer (right click the avast ‘a’ icon), Warning section, this contains information on all avast detections. C:\Program Files\Alwil Software\Avast4\ashLogV.exe
Depending on that, some archive files make extraction difficult or impossible without causing corruption, so the above information can help to determine what you can do.
Deletion isn’t really a good first option (you have none left), ‘first do no harm’ don’t delete, send virus to the chest and investigate.
Thanks, David.
This is what the log stats
1/17/2009 8:25:37 PM MCGINNIS 3188 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\RECYCLER\S-1-5-21-3983314188-3980874844-3158068552-1004\Dc10.tmp[Embedded_R#01640]$0\keenfinder.exe” file.
1/17/2009 10:03:34 PM MCGINNIS 3188 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{A565A346-C059-4B57-B395-64CE223DCFC0}\RP274\A0026910.msi\Binary.kfsetup_122_keenwebd.exe[Embedded_R#01640]$0\keenfinder.exe” file.
1/17/2009 10:03:35 PM MCGINNIS 3188 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{A565A346-C059-4B57-B395-64CE223DCFC0}\RP274\A0026912.msi\Binary.kfsetup_122_keenwebd.exe[Embedded_R#01640]$0\keenfinder.exe” file.
1/17/2009 10:25:08 PM MCGINNIS 3188 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\WINDOWS\Installer\1c8bc0.msi\Binary.kfsetup_122_keenwebd.exe[Embedded_R#01640]$0\keenfinder.exe” file.
1/19/2009 9:46:43 PM MCGINNIS 2716 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{A565A346-C059-4B57-B395-64CE223DCFC0}\RP274\A0026910.msi\Binary.kfsetup_122_keenwebd.exe[Embedded_R#01640]$0\keenfinder.exe” file.
1/19/2009 9:47:18 PM MCGINNIS 2716 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{A565A346-C059-4B57-B395-64CE223DCFC0}\RP274\A0026912.msi\Binary.kfsetup_122_keenwebd.exe[Embedded_R#01640]$0\keenfinder.exe” file.
1/19/2009 9:47:51 PM MCGINNIS 2716 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{A565A346-C059-4B57-B395-64CE223DCFC0}\RP274\A0026961.msi\Binary.kfsetup_122_keenwebd.exe[Embedded_R#01640]$0\keenfinder.exe” file.
1/19/2009 10:19:17 PM MCGINNIS 2716 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\WINDOWS\Installer\1c8bc0.msi\Binary.kfsetup_122_keenwebd.exe[Embedded_R#01640]$0\keenfinder.exe” file.
I think the problem one would have related to the [Embedded_R#01640]$0\keenfinder.exe, the others I guess would have gone through OK as they don’t appear to have been in archives.
Empty your Recycle bin.
You probably aren’t going to be able to extract those in the sustem volume information _restore points, but you don’t want to leave them there as they could bite you in the reare if you use system restore in the future.
So I would suggest clearing everything out and create a clean restore point, this is likely to release a lot of space on your hard disk. The C:\System Volume Information folder is a part of the system restore function and as such is protected by windows, the only really effective way to clean infected _restore points is to disable system restore and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore.