When I run MBAM, it finds nothing but when I do a boot scan in Avast, it turns up a few files infected with Win32 Malware-gen. It won’t delete them, Quarrantine them or repair them. The only thing I can do is ignore them.
Ive run SuperAntiSpyware, MS Essentials, AVG and a few others but I can’t get rid of it.
Check the C:\Documents and Settings\All Users\Application Data\AVAST Software\Avast\report\aswBoot.txt (XP) or C:\ProgramData\AVAST Software\Avast\report\aswBoot.txt (Vista, Win7) using notepad that contains information on the boot-time scan.
Copy and paste the information on the detections into your next reply.
Check the C:\Documents and Settings\All Users\Application Data\AVAST Software\Avast\report\aswBoot.txt (XP)
I have XP (home) but when I navigate to C:\Documents and Settings\All Users\ I see folders for Desktop, Favorites, Shared Documents and Start Menu and a file marked NTUSER—No Application Data
This is an archive file within another archive file, and looks like it is within yet another archive file. First A0367550.msi, then DATAL.cab, then EIshowspyabout.exe (zro google info on this file) and possibly another UXP archive after that and it looks like that is the protected one.
So I would say avast’s detection is correct:
Infected Restore Points - There really is little benefit in chasing a detection in the system volume information folder. It is only there because it had previously been deleted or moved from the system folders and this is a back-up created by system restore.
Worst case scenario it isn’t infected and you delete it, you can’t use that restore point in the future, not much of a loss and the older the restore point is the less of an issue it is.
So if there is any suspicion about a restore point then it is best removed from the system volume information folder or it could bite you in the rear at some point in the future when you use system restore if it included that restore point.
I would suggest manually clearing your restore points (disable, reboot, enable):
Windows XP System Restore General Information System Restore Guide
[quote author=DavidR link=topic=84456.msg686685#msg686685 date=1315579217]
I would suggest manually clearing your restore points (disable, reboot, enable)