avast!WEBforum
February 09, 2010, 01:08:47 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: avast! Home Edition - free for home non-commercial use!
 
   Home   Help Search Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: A sort of a report on an infection that I've managed to solve  (Read 776 times)
satyr
Jr. Member
**
Offline Offline

Gender: Male
Slovenia Slovenia

Posts: 31


an ex-architecture student


WWW Personal Message (Offline)
« on: August 19, 2006, 03:35:06 PM »

Hello all, I just though that I might let you know about the infection with the "Haxdoor" trojan that I've managed to solve with help of Filemon, Autoruns, but especially Regmon (i.e. with it I noticed the ID of a non-visible process) programs from Sysinternals ...


This were the two Avast's Event Viewer events:

AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of D:\WINDOWS\system32\ydsvgd.dll failed, 00000005.

AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: D:\WINDOWS\system32\ydsvgd.dll (D:\WINDOWS\system32\ydsvgd.dll) returning error, 00000005.


I anyone wants to, please see the "/Fixed: HELP: My computer was probably infected and now I am afraid to reboot" thread: http://episteme.arstechnica.com/eve/forums/a/tpc/f/99609816/m/464002950831 that I opened on Ars Technica (or alternatively the one at CastleCops similarly titled "/Fixed: My PC probably infected; now I am afraid to reboot") and in which I described the solution (and varous interesting techniques I used) to this infection in great details, of course, with graphical screenshots added ...


satyr

« Last Edit: August 19, 2006, 03:52:43 PM by satyr » Logged

Hey everybody, if you are interested, please check out my personal website: http://tadej-ivan.50webs.com/ and enjoy in my computing articles, discoveries, principles, rules, tips etc.
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Brazil Brazil

Posts: 48112



Personal Message (Offline)
« Reply #1 on: August 20, 2006, 03:38:39 PM »

failed, 00000005
Scan access denied. Access denied means, generally, that the file is in use by another process (program) and cannot be repaired/cleaned/moved/handled by avast!
You need boot time scanning:

Click on the Menu button.
Choose Schedule Boot Time Scan.
Doing so displays a dialog allowing you to schedule virus scanning.
Check Archives, if you want scan all the archives.
Specify whether all the disks or just a specific folder should be scanned.
Select Advanced options for scheduling details.
Select how to automatically process infected files.
Choose how to automatically process infected system files.
Click the Schedule button to confirm the settings.

Or just run:
C:\Program Files\ALWIL Software\Avast4\sched.exe /A:*
Logged

avast4 Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2.512 Gb extra free remote backup space.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2010, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 1.008 seconds with 17 queries.