How to remove Win32/Small.CAvirus?

Solved/Closed
Report
Posts
9
Registration date
Monday October 15, 2012
Status
Member
Last seen
November 16, 2012
-
Posts
47367
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
-
Hello,
I am not knowledgeable in the field of IT.Mostly i use my pc to surf on the net and for personal use.However since the 20th of October,windows action center detected an issue to be addressed. It said 'remove the Win32/Small.CAvirus'. Unable to remove it,it was automatically moved to archived messages.
The solution was to go to this site: https://docs.microsoft.com/en-us/windows/security/threat-protection/intelligence/safety-scanner-download
However on activating the scan,halfway through it,the scan froze.And the system shut down by itself.
I was using AVG and AVira,but none of the above AV detected the virus win32.
Since then I am having same kind of problem.Unexpected shutdowns.I downloaded Microsoft Security Essentials,but again the AV cannot run the scan. It always shut down halfway,be it am running a quick or whole system scan.
Kindly help out please.



28 replies

Hello...
http://speedy.sh/t8Ymv/mbam-log-2012-11-26-22-46-27.txt

This is the malwarebyte log link..
Am sorry if i aint got it right..
Posts
47367
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,270
You got it right!
The Malwarebyte log shows no malicious files.

I trust you deleted the files I mentioned before.

You may still be getting a warning which is a fake alert, I believe it comes from: Max Spyware Detector.
If you remove it, I think it should stop. Having more than one antivirus will create conflicts, resulting in fake alerts or letting viruses in.

Please launch ZHP Fix and copy the following lines:

G1 - GCS: Preference [User Data\Default] http://www.search.ask.com/?o=10148&l=dis
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} Orphean Key
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Orphean Key
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} Orphean Key
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} Orphean Key
O2 - BHO: (no name) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} Orphean Key
O3 - Toolbar: (no name) - [HKLM]{95B7759C-8C7F-4BF1-B163-73684A933233} . (...) -- (.not file.)

Click on the second icon, looks like a clipboard and the above lines which you have just copied will paste. The Go button will appear. Click it and close ZHP Fix.

In you programme files, you have a programme called Bandoo, it's adware and spyware. Using CCleaner, please remove it.

You also have the following Microsoft Net Framework and Visual ++, if you are in the programming business, keep them, if not they take space needlessly. You can remove them with CCleaner.

Again, using CCleaner, delete all of your temp files, they are crudding your harddisk.

Good luck and let me know if you are experiencing more difficulties.

Please, keep a close eye on Nadeem, he is very imprudent with the system.

Regards
Hi..followed ur instructions n i aint having the same prob..I thank u load 4 ur time n patience..
Posts
47367
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,270
Faraa,

Please correct me if I'm wrong.

1. Nadeem has not been on the computer since my last message.

2. You have deleted all files pertaining key gens.

3. You ran ZHP Fix as directed.

4. You ran Combofix.

5. You ran a full system scan with Malwarebyte after updating it.

6. You deleted Max Spyware Detector.

7. You ran CCleaner for both temp and registry files.

You say that you still:

1. Get a message asking to remove win32/small.ca virus

2. You still experience surprised shutdowns.

Please send me a brand new ZHP Diag log.
Hi.. I no longer experience unexpected shut downs.. It has stopped completely!!!!
The message asking to ask to remove the win32/small virus is still in the archived messages in the Action Center.
Here is a new ZHP Diag log :
http://speedy.sh/tqH7v/ZHPDiag.txt
Posts
47367
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,270
Hi

This is a typical bug with Win 7 action center.

Go to the Action Center (by clicking Control Panel | System and Security | Action Center) and select to Change Action Center Settings. This allows you to disable specific types of messages, including messages about Windows Update, Internet security settings, User Account Control, Windows Backup, and more.

Uncheck virus notification.
Posts
47367
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,270
Faraa,

I am still getting a log showing full of all kinds of malware, the same as before.

This is very frustrating as I question if you followed my instructions to the letter. I would hate having to repeat everything.

You must insure that all of the previous ZHP Diag logs have been removed from your machine.

Make a search for ZHPDiag and delete all .txt files. There could still be one in the programme files under ZHP.

Then you can generate and upload another log. If the new log shows all of malware again, I will eat my shirt, but I will leave the collar and sleeves for you to chew on.

Regards
Hi..I followed ur instructions clearly..
Am sending u a malwarebyte log..here it is :
http://speedy.sh/zSdUp/mbam-log-2012-12-05-21-56-50.txt
I do not have any unexpected shut downs or any other prob with my pc..and thanx to u 4 having taken the time 4 me..
Posts
47367
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,270
Malwarebyte has not found malware.

What I understand from your message is that you no longer have any problems and that you computer is running like new.

I was glad to help you.

Regards