Author Topic: Virus that is difficult to remove, need help!!!!  (Read 4116 times)

0 Members and 1 Guest are viewing this topic.

AlwaysAskingQuestions

  • Guest
Virus that is difficult to remove, need help!!!!
« on: May 03, 2011, 11:12:30 PM »
i am using the free avast version and this is what happened...(re-posted from yahoo answers)
There are two viruses(or so it seems) and i can't delete them? Help please..?
i've been restarting and scanning my computer since yesterday trying to crack down this stupid virus that i have on here. my computer's running the way it was before igot it but the virus is in these files and avast! is finding it in boot time scan but not in normal mode scan
they are :
File C:\Windowsa\System32\config\systemprofil… Windows OneCareBackup staging Area\Part 150.ZIP|>D\JOHNSTONTREAS-PC\Backup Set 2 009-08-24 105730\Backup Files 2010-2-14 220119\Part##1 of Backup files 1.z ip|>C\Users\johnston.treasury\Downloads\… Error 42127 {CAB archive is corrupted}

and

File C:\Windows\System32\config\systemprofile… Windows OneCare Backup Staging Area\Part 150.zip\>D\JOHNSTONTREAS-PC\Backup Set 2009-08-24 105730\Backup Files 2010-02-14 220119\Part##1 of Backup files 1.z ip| >C\Users\johnston.treasury\AppData\Local… is infected by win32:Mywebsearch-R [PUP]

the thing is i don't know WHAT it's doing in the backup files from '09 and i uninstalled the zinky search thing ages ago....like back in early 2010

i try to delete it but it says its part of the windows folder, try to repair it try to move it to chest but its either error or decompression bomb. and this is a boot scan using avast!
Help?
42 minutes ago - 4 days left to answer.
Additional Details
thanks but i already have malwarebytes and for some reason it never picked it up....
and i'm confused on the itunes thing as well...


i am currently scanning with malwarebytes but it passed the files a few minutes ago and i am very worried now...
EDIT: **NOTE: I DO NOT HAVE WINDOWS LIVE ONE CARE ON MY COMPUTER IT WAS UNINSTALLED IN 2010 OR SO. the itunes setup is what i didn't delete yet i think...
« Last Edit: May 03, 2011, 11:16:55 PM by AlwaysAskingQuestions »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Virus that is difficult to remove, need help!!!!
« Reply #1 on: May 03, 2011, 11:31:03 PM »
Quote
File C:\Windowsa\System32\config\systemprofil… Windows OneCareBackup staging Area\Part 150.ZIP|>D\JOHNSTONTREAS-PC\Backup Set 2 009-08-24 105730\Backup Files 2010-2-14 220119\Part##1 of Backup files 1.z ip|>C\Users\johnston.treasury\Downloads\… Error 42127 {CAB archive is corrupted}

Quote
File C:\Windows\System32\config\systemprofile… Windows OneCare Backup Staging Area\Part 150.zip\>D\JOHNSTONTREAS-PC\Backup Set 2009-08-24 105730\Backup Files 2010-02-14 220119\Part##1 of Backup files 1.z ip| >C\Users\johnston.treasury\AppData\Local… is infected by win32:Mywebsearch-R [PUP]

first this semms to be located in a zip.file and Malwarebytes does not scan inside archives
malware in zip.files are dead untill you unzip and run the file, MBAM only look for active malware or unzipped malware installers

as i can se the first one is just a scan error warning, that the file is corrupted....not a malware warning
the second is detected as PUP

PUP = http://searchsecurity.techtarget.com/definition/PUP

if you want to delete these files you can try opening Malwarebytes > more tools > file assassin > browse to the files you want to kill


Toolbar:W32/MyGlobalSearch / w32:Mywebsearch
http://www.f-secure.com/sw-desc/toolbar_w32_myglobalsearch.shtml

« Last Edit: May 03, 2011, 11:44:09 PM by Pondus »

AlwaysAskingQuestions

  • Guest
Re: Virus that is difficult to remove, need help!!!!
« Reply #2 on: May 03, 2011, 11:43:56 PM »
have you used F secure before? i jsut wanna make sure

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Virus that is difficult to remove, need help!!!!
« Reply #3 on: May 03, 2011, 11:45:50 PM »
have you used F secure before? i jsut wanna make sure
make sure what ?

AlwaysAskingQuestions

  • Guest
Re: Virus that is difficult to remove, need help!!!!
« Reply #4 on: May 03, 2011, 11:51:39 PM »
make sure i'm not downloading something that will potentially harm my computer lol

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Virus that is difficult to remove, need help!!!!
« Reply #5 on: May 03, 2011, 11:53:30 PM »
make sure i'm not downloading something that will potentially harm my computer lol
an why would you download F-secure ? 

i posted that link to give you some info about W32:Mywebsearch   but you can always google the name and find the info yourselfe

« Last Edit: May 03, 2011, 11:57:04 PM by Pondus »

AlwaysAskingQuestions

  • Guest
Re: Virus that is difficult to remove, need help!!!!
« Reply #6 on: May 03, 2011, 11:56:31 PM »
Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions....

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Virus that is difficult to remove, need help!!!!
« Reply #7 on: May 04, 2011, 12:01:08 AM »
Quote
File C:\Windowsa\System32\config\systemprofil… Windows OneCareBackup staging Area......

How to delete a Windows Live OneCare Backup file
http://support.microsoft.com/kb/943904

you may also try running Liveoncare removaltool nr #23a
http://uninstallers.blogspot.com/
« Last Edit: May 04, 2011, 12:03:02 AM by Pondus »

AlwaysAskingQuestions

  • Guest
Re: Virus that is difficult to remove, need help!!!!
« Reply #8 on: May 04, 2011, 12:03:11 AM »
thanks! but for paranoid reasons, i think i'll wait until i can get another form of backing up the computer before i try to tamper with that lol

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user

AlwaysAskingQuestions

  • Guest
Re: Virus that is difficult to remove, need help!!!!
« Reply #10 on: May 04, 2011, 12:11:54 AM »
i'll try it now

AlwaysAskingQuestions

  • Guest
Re: Virus that is difficult to remove, need help!!!!
« Reply #11 on: May 04, 2011, 12:18:12 AM »
it seemed to have worked. i thought i uninstalled it ages ago O.O
i'll run a boot scan tomorrow and see if it works lol.