Author Topic: StateRepository-Machine.srd-shm  (Read 11416 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
StateRepository-Machine.srd-shm
« on: December 08, 2015, 10:53:14 AM »
After running my AVAST virus scanner, the result window mentioned that some files could not be scanned (Sommige bestanden kunnen niet worden gescand), mentioning:

C:\ProgramData\Microsoft\Windows\AppRepository-Machine.srd-shm
Fout: Het proces heeft geen toegang tot het bestand omdat een gedeelte van het bestand door een ander proces is vergrendeld (33)
(Error: The process does not have access to the file because a part of the file is locked by another process (33) )

What does this mean?
Is this a false positive or a threat? Is this file a valid Windows component?
Many thanks for your advice!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: StateRepository-Machine.srd-shm
« Reply #1 on: December 08, 2015, 11:08:59 AM »
it is normal and not a detection, just a scan error message

How do I handle files that avast! can’t scan? https://blog.avast.com/2014/02/28/how-do-i-handle-files-that-avast-cant-scan/

some files could not be scanned is the most frequently asked question in the forum, so plenty info if you search




REDACTED

  • Guest
Re: StateRepository-Machine.srd-shm
« Reply #2 on: December 08, 2015, 02:43:28 PM »
Dear Pondus,

Thanks a lot for your quick response!
I understand that it happens more often that Avast is not able to scan files, and that this is not necessarily a problem as it does not say anything yet about the file itself.
However, Avast never gave this response before when scanning (I regularly perform a complete system scan). Do you think this is because the file in question (StateRepository-Machine.srd-shm) is related to a Windows update or something like that and therefore new?

In addition, what also made me a bit concerned was the blog post about this file I found elsewhere, with the text copied here below. Does anyone know what kind of file this is, and if it is really innocent? How can I know that its not a problematic file?

http://www.wilderssecurity.com/threads/hitman-pro-support-and-discussion-thread.236732/page-273:

"Suspicious files ____________________________________________________________

C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm
Size . . . . . . . : 32.768 bytes
Age . . . . . . . : 26.1 days (2015-09-10 12:18:50)
Entropy . . . . . : 6.2
SHA-256 . . . . . : A482BAA7ADDC525DEA1A1EC46EF619F66CA3F02B87162BE2B99E181088C2A7C3
Fuzzy . . . . . . : 56.0
The file is hidden from Windows API. This is typical for malware.
The file is completely hidden from view and most antivirus products. It may belong to a rootkit.
The file name extension of this program is not common.
Program is running but currently exposes no human-computer interface (GUI).
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
The file is in use by one or more active processes.
The file is a device driver. Device drivers run as trusted (highly privileged) code.
Forensic Cluster
-1.2s C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\d2abe790c186609ce700d6af614dbda9_a3d6c6f9-8be7-4367-b352-d22eca12c24f
-0.1s C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-wal
0.0s C:\ProgramData\Microsoft\Windows\AppRepository\StateRepository-Machine.srd-shm "


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: StateRepository-Machine.srd-shm
« Reply #3 on: December 08, 2015, 02:57:21 PM »
It is part of Windows 10.
Nothing to worry about.

If you want to clean it up, you can use the following command :
Dism /online /cleanup-image /restorehealth

Some (technical) information:
http://batcmd.com/windows/10/services/staterepository/
« Last Edit: December 08, 2015, 03:06:41 PM by Eddy »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: StateRepository-Machine.srd-shm
« Reply #4 on: December 08, 2015, 03:13:25 PM »
Quote
However, Avast never gave this response before when scanning (I regularly perform a complete system scan)

as avast say ... in use by windows
Quote
(Error: The process does not have access to the file because a part of the file is locked by another process (33) )


if you are suspicious and want to check the file, upload and scan here  www.virustotal.com / www.metascan-online.com / www.jotti.org
if scanned before, always click rescan for a fresh result, use the additional tabs for finding additional info about the file


« Last Edit: December 08, 2015, 03:43:06 PM by Pondus »

REDACTED

  • Guest
Re: StateRepository-Machine.srd-shm
« Reply #5 on: December 08, 2015, 04:00:08 PM »
Dear both,
Thanks a lot for your help!
Much appreciated.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: StateRepository-Machine.srd-shm
« Reply #6 on: December 08, 2015, 04:07:07 PM »
You're welcome.