Forum Home
Press F1
 
Thread ID: 96151 2008-12-31 06:36:00 Invisible (?infected) file macuser (14462) Press F1
Post ID Timestamp Content User
733801 2008-12-31 06:36:00 Hi - don't know if this will make sense or anyone will be able to help, but there's no harm in asking!

I have an iMac running OS-X and via Bootcamp I'm running Windows Vista 32-bit Ultimate, so the Windows partition appears and is searchable, etc from OS-X. I bought a double packaged security 'suite' which included Intego Virus Barrier X5 for the Mac and BitDefender Internet Security 2008 for Windows.

Recently when running Windows I managed to become infected with some Malware, but then thought I'd successfully removed it with a combination of Spybot S&D and 'SuperAntiSpyware', and nothing would come up thereafter with scans by BitDefender, Spybot S&D, or Superantispyware. However today in Mac OS-X Virus Barrier X5 alarmed and said it found a virus in the Windows partition, in C:\Windows\Downloaded Program Files, in a file called "FP_AX_CAB_INSTALLER.exe", saying that it was infected with "W32.Malware.Antispycheck". It tries to Quarantine this file but can't due to permissions set from Vista, also I am unable to delete it via OS-X due to the same permission settings. Apparently this file (from an internet search) is usually a legitimate file for installing Adobe Flash.

If I then reboot into Windows and run a scan, nothing comes up. Looking in the C:\Windows\Downloaded Program Files folder there is only one file "Shockwave Flash Object" which cannot be deleted (Hidden files are being shown). If you right click on this file and look at it's properties, under the dependency tab, then apparently Shockwave Flash Object is dependent on FP_AX_CAB_INSTALLER.exe, but I can't otherwise find this file or show it anywhere, no matter how I search, so I can't delete it.

Is there any way of showing this file in Windows so I can delete it? Or should I even be worried about it and just ignore it?

Thanks!
macuser (14462)
733802 2008-12-31 06:43:00 Ignore it.
Its a legit file. Macs don't have enough experience with malware, especially Windows designed malware.
pctek (84)
733803 2008-12-31 06:44:00 It maybe a false +

Send it to whoever made the program. If you delete it, flash probably wont work.
Speedy Gonzales (78)
733804 2008-12-31 07:45:00 W32.Malware.Antispycheck is a misleading application that may give exaggerated reports of threats on the computer.

You should remove it though as it installs a lot of files and registry items.
Info and manual removal instructions at this link

www.symantec.com
Safari (3993)
1