Author Topic: Boot scan found infected files but could not delete them  (Read 4994 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Boot scan found infected files but could not delete them
« on: April 22, 2016, 07:49:27 PM »
Hello, I ran a scheduled boot scan and got the following results, should I be concerned?  Looks like files could not be deleted by AVAST, but I'm not sure how to interpret.  After Windows 7 booted up, I scanned each listed file and got "no threat found" on each.  Thanks for any help, I'm a novice at this!

File C:\$WINDOWS.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\bcdboot.exe is infected by Other:Malware-gen [Trj], Delete: Error 0xC0000279 {The layered file system driver for this IO tag did not handle it when needed.}
File C:\$WINDOWS.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\cscript.exe is infected by Other:Malware-gen [Trj], Delete: Error 0xC0000279 {The layered file system driver for this IO tag did not handle it when needed.}
File C:\$WINDOWS.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-bcdboot-cmdlinetool_31bf3856ad364e35_10.0.10586.0_none_eddb7cede87b99bf\bcdboot.exe is infected by Other:Malware-gen [Trj], Delete: Error 0xC0000279 {The layered file system driver for this IO tag did not handle it when needed.}
File C:\$WINDOWS.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-scripting_31bf3856ad364e35_10.0.10586.0_none_d4edeb6eaab124ac\cscript.exe is infected by Other:Malware-gen [Trj], Delete: Error 0xC0000279 {The layered file system driver for this IO tag did not handle it when needed.}
Number of searched folders: 45345
Number of tested files: 884987
Number of infected files: 4

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Boot scan found infected files but could not delete them
« Reply #1 on: April 22, 2016, 08:14:38 PM »
seems to be False positive on Win10 update files


REDACTED

  • Guest
Re: Boot scan found infected files but could not delete them
« Reply #2 on: April 22, 2016, 08:26:15 PM »
Thanks!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Boot scan found infected files but could not delete them
« Reply #3 on: April 22, 2016, 08:29:23 PM »
any special reason why you did a boot scan?


REDACTED

  • Guest
Re: Boot scan found infected files but could not delete them
« Reply #4 on: April 22, 2016, 08:56:35 PM »
It had been a while since I did one.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Boot scan found infected files but could not delete them
« Reply #5 on: April 22, 2016, 09:09:10 PM »
It is not meant to be used as a regular scanner and it does not give any better detection, what it give is better removal of some infections




REDACTED

  • Guest
Re: Boot scan found infected files but could not delete them
« Reply #6 on: April 22, 2016, 10:33:30 PM »
How often should one do a "boot scan" then?  I've never done one...I just run the regular scan... Quick Scan, every day.   Is that enough?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89711
  • No support PMs thanks
Re: Boot scan found infected files but could not delete them
« Reply #7 on: April 22, 2016, 10:52:40 PM »
How often should one do a "boot scan" then?  I've never done one...I just run the regular scan... Quick Scan, every day.   Is that enough?


For me it was once, when I first installed avast 12 years ago. It is a special scan that is generally only used if there is a problem dealing with an infection in normal windows mode.

Or if you get a detection by avast in a normal scan it will most likely suggest running a boot-time scan.

With a resident on-access antivirus like avast, the need for frequent on-demand scans is much depreciated. For the most part the on-demand scan is going to be scanning files that would be otherwise be dormant or inert. If they were active files then the on-access file system shield would be scanning them before being created, modified, opened or executed.

I used to have avast set to do a scheduled weekly Quick scan, set at a time and day that I know the computer will be on. But I have ceased this practice for some time now, based in the above.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.875) UI 1.0.820/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

REDACTED

  • Guest
Re: Boot scan found infected files but could not delete them
« Reply #8 on: April 24, 2016, 06:09:48 PM »
I just got the same issue. Boots scans always fixed problem but this can not be fixed by Avast. Probably get a different virus scanner and try again?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Boot scan found infected files but could not delete them
« Reply #9 on: April 24, 2016, 06:12:45 PM »
I just got the same issue. Boots scans always fixed problem but this can not be fixed by Avast. Probably get a different virus scanner and try again?
what was detected?
what location of detected file(s) ... full file path


REDACTED

  • Guest
Re: Boot scan found infected files but could not delete them
« Reply #10 on: April 24, 2016, 06:36:48 PM »
Exactly what FrankH initially described in this email . Having the same virus alert as he describs. No fix automatically or delete is possible (Avast says cant access file) . When I searched the file manually and run a Avast scan just on this file , it says the same "no access" . So I dont know if I simply just delete the file and remove it from the PC but I do not know what the file is needed for in Windows OS?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Boot scan found infected files but could not delete them
« Reply #11 on: April 24, 2016, 06:39:33 PM »
Quote
Exactly what FrankH initially described in this email ........
Then as said above, it is a False Positive detection on Win10 update files


Offline novakl

  • Avast team
  • Newbie
  • *
  • Posts: 7
Re: Boot scan found infected files but could not delete them
« Reply #12 on: April 25, 2016, 12:06:06 AM »
Hello, this FP was fixed 22.04.  Upgrade your virus database please.

REDACTED

  • Guest
Re: Boot scan found infected files but could not delete them
« Reply #13 on: April 27, 2016, 02:44:31 PM »
Great , the fix worked . thanks