Author Topic: Renamed worm/virus and can't find it?  (Read 8714 times)

0 Members and 1 Guest are viewing this topic.

mm6chic

  • Guest
Renamed worm/virus and can't find it?
« on: July 27, 2006, 01:49:37 AM »
I ran a scan recently and instead of moving the worm to the chest, I accidentally hit move/rename instead.  How do I figure out where this file went to (where it defaulted to) and how do I delete it off my computer? 

I ran a boot-scan after this and it came back clean.  I'm sure I still have that worm on my computer somewhere.....can anybody give me any advice??  Thanks.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Renamed worm/virus and can't find it?
« Reply #1 on: July 27, 2006, 02:14:25 AM »
This is the location of files moved, C:\Program Files\Alwil Software\Avast4\DATA\moved. If it is in there it should effectively have been removed, you could move it back to its original location (if you know where that is) and let avast detect it again and this time send it to the chest.

What makes you sure you still have this on your system ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

mm6chic

  • Guest
Re: Renamed worm/virus and can't find it?
« Reply #2 on: July 27, 2006, 04:12:43 AM »
Well I went to the Moved folder and nothing is there...I guess my question is, if I told it to rename and move the file and it's not in that folder, is it still a threat to me?

I believe the file name is FPUPDATEAX.EXE-1BCF6D6E.pf.  It was something that appeared to come from Macromedia Flash Player, most likely from MySpace.

I have an empty folder named fpupdateax and then I have this above mentioned file.  The virus/worm detected definitely had the letters FPUP in it and these are the only files/programs with those letters in the name.  Should I move it somewhere?  Right now it's just in my Program Files....

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Renamed worm/virus and can't find it?
« Reply #3 on: July 27, 2006, 02:00:14 PM »
Well I went to the Moved folder and nothing is there...I guess my question is, if I told it to rename and move the file and it's not in that folder, is it still a threat to me?
Maybe...
Did you fully scan with avast and another antitrojan (like ewido)?

Should I move it somewhere?  Right now it's just in my Program Files....
Open avast chest and add it there then, if you don't need the file, delete it and clean the recycle bin.

C:\Program Files\Alwil Software\Avast4\ashChest.exe is the avast quarentine.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Renamed worm/virus and can't find it?
« Reply #4 on: July 27, 2006, 02:31:26 PM »
Quote from: mm6chic
I believe the file name is FPUPDATEAX.EXE-1BCF6D6E.pf

If this file name is correct it could be a pre-fetch file to speed loading of programs and if deleted will be replaced by the pre-fetch function later, assuming it was in the C:\WINDOWS\Prefetch folder, check the avast Log Viewer, warning section for more details on the detection. If it wasn't in the pre-fetch folder this would make that .pf file more suspicious (to me). Please let us know what information is contained in the Log Viewer about this detection (virus name, original location, etc.) ?

The first part of the file name, FPUPDATEAX.EXE does appear to be related to Macromedia Flash, a google search only brings up a 5 hits for this all need translating, but this would appear to be the location:
Quote
c:\Documents and Settings\YourUserName\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
Now this file may then have a file in the c:\windows\prefetch folder to speed its loading and that would probably be FPUPDATEAX.EXE-1BCF6D6E.pf.

Why the prefetch file should be detected is strange as I don't believe it contains the original file, just hard disk locations to make it load faster. If it did contain the original file then in theory the original file should also have been detected as infected, very strange.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

mm6chic

  • Guest
Re: Renamed worm/virus and can't find it?
« Reply #5 on: July 28, 2006, 05:10:10 AM »
OK, this is what the log viewer says about this virus:

7/23/2006 11:30:20 PM   Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\Documents and Settings\HP_Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe" file.  I accidentally hit Move and Rename and then it scanned some more and came up with....

7/24/2006 11:22:03 AM   Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\Program Files\Alwil Software\Avast4\DATA\moved\fpupdateax.exe.vir" file. 

Since the file name changed to .vir and I actually deleted that file, does this mean that I am now virus free?  I can still find the original files.  I found the empty folder in the same place - application data\macromedia\flashplayer etc.... but I found the .exe file in C:/WINDOWS/PreFetch??  I moved them into the Avast Moved folder for now - is that OK?
« Last Edit: July 28, 2006, 05:19:44 AM by mm6chic »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Renamed worm/virus and can't find it?
« Reply #6 on: July 28, 2006, 01:59:52 PM »
Since the file name changed to .vir and I actually deleted that file, does this mean that I am now virus free?  I can still find the original files.
No, you're not clean if you have the original files...

but I found the .exe file in C:/WINDOWS/PreFetch??  I moved them into the Avast Moved folder for now - is that OK?
No...
The moved folder is not safe. You need to move the files to Chest (Quarentine of avast).

I suggest you run a full avast scanning and, after, a boot time scanning with avast, moving the infected files to Chest  ;)
The best things in life are free.

mm6chic

  • Guest
Re: Renamed worm/virus and can't find it?
« Reply #7 on: July 29, 2006, 09:29:53 AM »
It's me again.  I ran a full scan and a boot time scan with this file being in the chest folder (not the ashChest).  Both scans came back without a virus.  So, maybe it did delete the virus, but I still have the original .exe file??  Should I delete the file from the chest folder and delete my recycle bin?  Or should I move it to the ashChest?  (I tried doing that but it still left a copy of the file in the chest folder as well, so I deleted it from the ashChest).  Thank you for your help.....

mm6chic

  • Guest
Re: Renamed worm/virus and can't find it?
« Reply #8 on: July 29, 2006, 04:34:49 PM »
I also did a full scan and a boot time  scan with  the .exe file moved into the ashChest (although a copy of it still remained in the chest folder too) and it came back with no viruses.

I also installed and ran ewido and that virus didn't show up.
« Last Edit: July 29, 2006, 05:38:35 PM by mm6chic »