Virus/Worm Parite

Hi, Avast 4.7 home detects 6 infections when doing a scan, all in System Volume Information_restore{…} Avast recommended action is repair, but it fails. Can’t either do Move to chest or Delete. What to do?

regards
Lennart

Hi lelilj,

Create a clean system restore point:

http://www.bleepingcomputer.com/tutorials/tutorial56.html#manual

Then delete all previous infected system restore points:

http://www.bleepingcomputer.com/tutorials/tutorial56.html#delete

After doing that, I suggest:

  1. Clean your temporary files. You can use the Windows Advanced Care features for that.

  2. Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot. Other option is scanning in SafeMode (repeatedly press F8 while booting).

  3. It will be good if you download, install, update and run other trojan remover tools: a-squared and/or Free AVG Antispyware (trojan removers). Some users recommend SUPERantispyware or Spyware Terminator.

  4. Use the immunization of [url=http://SpywareBlaster or, which is better, the Windows Advanced Care features of spyware/adware cleaning and removal.

Hi again,

thank you for good advice, the trick with system restore point fixed the problem!

Thank you
from
Lennart

Will Webroot Spysweeper work?

Only for number 3.
Although the other antitrojans are free and won’t install any resident protection (with the free version). You could test them too 8)

That’s the same thing as W32.Pinfi, AFAIK! That virus will corrupt any .exe file on the HDD that Windows allows write access to! Symptoms are the following:

Files recently downloaded are corrupted, you get an error message, usually from the installer, about the file being corrupted.

Also there probably is this symptom, too:

A file with a random filename in the temporary file directory that Windows won’t let you delete, you will get an access denied error message or about the file being in use by another person or program.

Sounds like an argument in favor of a boot scan - just to play it safe.