Avast WEBforum

Other => Viruses and worms => Topic started by: biseto on October 16, 2010, 09:12:30 AM

Title: Using Avast! Repair or moving to virus chest...Access is Denied!?
Post by: biseto on October 16, 2010, 09:12:30 AM
Hi,
I have Avast and when I try to Repair, Move to chest, delete it, it says Error: Access is Denied (5). The threat is rootkit. Windows/winsxs/amd64.....  How do I fix this?

   
Title: Re: Using Avast! Repair or moving to virus chest...Access is Denied!?
Post by: SafeSurf on October 16, 2010, 09:27:29 AM
Hello biseto and welcome to the forum.

What is the exact name of the malware?  What were you doing when you got this malware?

1.   What is your OS, 32 or 64-bit?
2.   What version of Avast did you install?  5.0.677 is the current version.
3.   What product of Avast did you install?  Free, Pro, AIS?
4.   Are the Avast definitions (updates) current?
5.   Was your machine acting strangely prior to this happening or now?

Check your computer for malware with Malwarebytes’ Anti-Malware (MBAM).
·   Download free http://www.malwarebytes.org/ (http://www.malwarebytes.org/) for an on-demand scanner.
·   Double Click mbam-setup.exe to install the application.
·   After install, click update so you have latest database before scanning.
·   Under Settings:
o   General: Automatically Save File After Scan Completes is checked off
o   Scanner SettingsCheck all boxes
o   Updater: Download and install update if available is checked off
·   Once the program has loaded, select "Perform FULL Scan", then click Scan.
·   The scan may take some time to finish, so please be patient.
·   When the disinfection scan is complete, a log will appear in Notepad and you may be prompted to Restart. (See Extra Note).
·   Click the “remove selected” button to quarantine anything found.  You will find the infection details under the Quarantine tab.
·   The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
·   Copy & Paste the entire report in your next reply.



Title: Re: Using Avast! Repair or moving to virus chest...Access is Denied!?
Post by: biseto on October 16, 2010, 01:47:57 PM
Hi SafeSurf,
TY for your help!

My Avast version is 5.0.677, free
Windows Vista
64 bit

My PC was a bit slow
and that's what I got after the Avast scan
C:\Windows\winsxs\amd64_microsoft.vc80.atl_fc8b.....,    Threat: Rootkit: hidden file,   Move to chest,    Error: access is enied(5)

After your response I ran a Malwarebytes scan and I got Trojan but managed to remove it
Title: Re: Using Avast! Repair or moving to virus chest...Access is Denied!?
Post by: SafeSurf on October 17, 2010, 10:53:52 AM
Threat: Rootkit: hidden file,   Move to chest,    Error: access is enied(5)

After your response I ran a Malwarebytes scan and I got Trojan but managed to remove it.
With MBAM, did you put the threat into quarantine or delete it?  I can't tell from your snapshot.

With Avast, are all the items in the Virus Chest now?

Check the information on the first post of this thread under Virus/Worms for you to check your machine for malware: http://forum.avast.com/index.php?topic=53253.0 (http://forum.avast.com/index.php?topic=53253.0). 

Follow the directions for obtaining an OTL logs.  Post the two (2) OTL log as an attachment (Additional Options > Attach > Browse (the logs will be on your desktop > Post). 

I will be contacting a Certified Malware Expert, named Essexboy, to assist you after you post your OTL logs.  In the meantime, I will continue to provide you with assistance, then remain in the background once he starts his malware removal process. 

Please check this thread at least daily for his instructions (he is on UK time zone).  Once you post your OTL logs, do not make any further changes to your machine or you will have to repeat these steps.  Do you have any questions?