Win32:PurityScan-X [Drp]

The original file name of this virus is A0012789.exe. I looked at previous posts, including the following:

http://forum.avast.com/index.php?topic=23450.msg193508#msg193508

When I click on the link for the automatic remover found in this post, Avast warns me that it is a virus. Is this normal?

When I received the virus warning, I followed the manual removal suggestion instead. The registry keys that are listed in this post were not found in my registry. Does this mean that the file never executed? The file has been moved to the Chest in Avast. Should I simply delete this file, or are there other steps I need to take?

Thanks in advance for the help,

aumber

Hi aumber,

Use the information here: http://forums.majorgeeks.com/showthread.php?t=95465

The link given there is clean, so probably a FP.
This were the results of DrWeb online URL scan:
Anti-virus engine version: 4.44.0.9170
File size: 105.9K

ps_uninstaller.exe packed by BINARYRES

ps_uninstaller.exe - archive NSIS

ps_uninstaller.exe/data001 - OK
ps_uninstaller.exe/data002 packed by UPX

ps_uninstaller.exe/data002 - OK
ps_uninstaller.exe/data003 - OK
ps_uninstaller.exe - OK

polonus

Since this is in the ?:\System Volume Information folder is a part of the system restore function it was most likely previously removed from a system folder whilst system restore was enabled and saved to a restore point only to be detected again by avast.

This area protected by windows, the only really effective way to clean infected _restore points is to disable system restore (on all drives) and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore, this will create a new clean restore point.

What is on the g:\ drive or are you using g:\ as a dual boot drive ?

The drive is a simple external/backup drive. Removing the restore point was effective in removing the virus. A new scan verified that it is now gone.

Is it necessary to run the uninstaller after the file has been removed?

I don’t think you have anything further to do, though I’m unsure which uninstaller you are talking about.