avast!WEBforum
November 22, 2009, 01:36:02 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Wow! - more than 60 000 registered forum users!
 
   Home   Help Search Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: A sort of a report on an infection that I've managed to solve  (Read 700 times)
satyr
Jr. Member
**
Offline Offline

Gender: Male
Slovenia Slovenia

Posts: 31


an ex-architecture student


WWW Personal Message (Offline)
« on: August 19, 2006, 03:35:06 PM »

Hello all, I just though that I might let you know about the infection with the "Haxdoor" trojan that I've managed to solve with help of Filemon, Autoruns, but especially Regmon (i.e. with it I noticed the ID of a non-visible process) programs from Sysinternals ...


This were the two Avast's Event Viewer events:

AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of D:\WINDOWS\system32\ydsvgd.dll failed, 00000005.

AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: D:\WINDOWS\system32\ydsvgd.dll (D:\WINDOWS\system32\ydsvgd.dll) returning error, 00000005.


I anyone wants to, please see the "/Fixed: HELP: My computer was probably infected and now I am afraid to reboot" thread: http://episteme.arstechnica.com/eve/forums/a/tpc/f/99609816/m/464002950831 that I opened on Ars Technica (or alternatively the one at CastleCops similarly titled "/Fixed: My PC probably infected; now I am afraid to reboot") and in which I described the solution (and varous interesting techniques I used) to this infection in great details, of course, with graphical screenshots added ...


satyr

« Last Edit: August 19, 2006, 03:52:43 PM by satyr » Logged

Hey everybody, if you are interested, please check out my personal website: http://tadej-ivan.50webs.com/ and enjoy in my computing articles, discoveries, principles, rules, tips etc.
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Spain Spain

Posts: 47062



Personal Message (Offline)
« Reply #1 on: August 20, 2006, 03:38:39 PM »

failed, 00000005
Scan access denied. Access denied means, generally, that the file is in use by another process (program) and cannot be repaired/cleaned/moved/handled by avast!
You need boot time scanning:

Click on the Menu button.
Choose Schedule Boot Time Scan.
Doing so displays a dialog allowing you to schedule virus scanning.
Check Archives, if you want scan all the archives.
Specify whether all the disks or just a specific folder should be scanned.
Select Advanced options for scheduling details.
Select how to automatically process infected files.
Choose how to automatically process infected system files.
Click the Schedule button to confirm the settings.

Or just run:
C:\Program Files\ALWIL Software\Avast4\sched.exe /A:*
Logged

avast Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2,200 Mb for free remote backup. Enjoy its safety!
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 15 queries.