Avast finding tons of infections

Discussion in 'Malware Help (A Specialist Will Reply)' started by gasparny, Nov 20, 2008.

  1. gasparny

    gasparny Private E-2

    Hello,

    I am trying to disinfect my son's computer. After running the usual Ad-Aware, Spybot and Malware bytes SitfraudFix and SDfix and detecting and removing quite a few infections (Trojans, Rootkit, downloader etc) I installed Avast and it is detecting many more infections. I am questioning if they are real because the files infected include notepad.exe and regedit.exe as well as other normal Windows files. My question is "Are these true infections?" or has a virus hijacked the Avast tool and making everything show up as an infection. The thing won't scan for more than a second and it pops up a detection. Some appear to be legitimate and some are questionable. I ran a scan the other day and it said we had 898 infections.

    Additionally it will not repair any files and it won't move them into the chest. It says files were not repaired and that there was an RPC communication error. I am not sure what that means. The only option is to delete the files, but then Windows XP wont boot because there aren't any system files left.

    Any ideas?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please attach a log from Avast.

    It sounds to me like you have one of the infections (there are quite a few) that will infect ALL executable files on a PC. If most cases, it is simplier and actually safer to reinstall when this occurs.
     
  3. gasparny

    gasparny Private E-2

    Hello,

    Yes you are correct. It turns out that the infection is win32.viru or virtob. my son has so many programs that I do not think it would be easier to reinstall windows plus all the other stuff. They are mostly online and offline computer games. The problem with Avast is that it does not remove (repair) the added script from the files. It just deletes the entire file even if I move them the the chest. So pretty much every exe and scr file on the system was infected and was deleted. I did a repair install of XP and found myself back to square one. Found Drweb Cure it and it seems to be working. Going to run it several times and do a few folders at a time because it seems to lose itself if there are too many files to scan continuously.

    If this fails I will reformat and reinstall. But I'd rather not. Thanks again for the reply. I uninstalled the Avast because I think the virus messes with it during install. So I have no log to post right now.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes these kinds of infections are quite nasty. And it is not unique to Avast to find a scanner deleting the files rather than cleaning the infections. Sometimes they can fix some files but not others. Normally what happens after infections like this is that the system becomes unstable/unreliable and over a period of time you find more and more programs that do not run or do not run properly. Thus the reason why a reinstall is often a better idea. If the infection is caught in very early stages then you would have better chances on cleaning it up without requiring a reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds