Author Topic: found a worm but won't let me move it to chest-access denied  (Read 6985 times)

0 Members and 1 Guest are viewing this topic.

cidder

  • Guest
found a worm but won't let me move it to chest-access denied
« on: November 07, 2008, 07:50:00 PM »
hi i downloaded avast for home when we received several thousand spam emails. it has found a worm but when i ask to move to chest it flashes 'access denied' cannot process "c:\WINDOWS\winlogon.exe" file.
gives malware name WIN32:Netsky-BD (Wrm)
type Worm
VPS version 080923-0,23-09-2008
i chose continue to process and so far no more detected (finished scan in two/half hours).
gave list at end which showed the file infected as just the one, but again did'nt allow me to do anything.
is it prob whats causing all the emails and how do we get rid of as cant use email(all full of spam and when delete more come)
help please??
is it because it is a system file that it cant delete it?

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: found a worm but won't let me move it to chest-access denied
« Reply #1 on: November 07, 2008, 07:57:53 PM »
Hi cidder,

Try a boot time scan with avast! Right click the scanner screen, select 'schedule a boot time scan' and reboot when requested. (Or open the tab at the top left of the scanner screen and select the boot time option from there.)
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

cidder

  • Guest
Re: found a worm but won't let me move it to chest-access denied
« Reply #2 on: November 07, 2008, 08:04:58 PM »
Hi cidder,

Try a boot time scan with avast! Right click the scanner screen, select 'schedule a boot time scan' and reboot when requested. (Or open the tab at the top left of the scanner screen and select the boot time option from there.)
thanks fwf,got to go and pick my lad up from his club but i'll try that tomorrow and report back to you.have a great weekend!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: found a worm but won't let me move it to chest-access denied
« Reply #3 on: November 08, 2008, 02:55:12 AM »
I also suggest:

1. Clean your temporary files.
2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
3. Use SUPERantispyware, MBAM or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
4. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
5. Make a HijackThis log to post here or this analysis site. Or even submit the RunScanner log to to on-line analysis.
6. Disable System Restore and then reenable it again.
7. Immunize your system with SpywareBlaster or Windows Advanced Care.
8. Check if you have insecure applications with Secunia Software Inspector.
The best things in life are free.

cidder

  • Guest
Re: found a worm but won't let me move it to chest-access denied
« Reply #4 on: November 10, 2008, 02:04:42 PM »
Hi cidder,

Try a boot time scan with avast! Right click the scanner screen, select 'schedule a boot time scan' and reboot when requested. (Or open the tab at the top left of the scanner screen and select the boot time option from there.)
hi frank.the worm is successfully in the virus chest and appears no other problems, so did a scan on our other machine and discovered its memory is infected with a trojan, whilst doing a memory scan. when try to move to chest again we get 'access denied', and option to schedule a time boot scan isnt available to click on.
message is cannot process "C:\windows\system\drufhoks.exe" file
trojan horse malware Win32:Trojano-214(Trj)
VPS version 0809 23-0 23-09-2008
can anybody help??

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: found a worm but won't let me move it to chest-access denied
« Reply #5 on: November 10, 2008, 03:05:33 PM »
What is the operating system?
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

cidder

  • Guest
Re: found a worm but won't let me move it to chest-access denied
« Reply #6 on: November 10, 2008, 03:38:06 PM »
What is the operating system?
windows 98 and a server with windows NT

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: found a worm but won't let me move it to chest-access denied
« Reply #7 on: November 10, 2008, 03:45:05 PM »
I don't think a boot time scan is available in Win98.

Can you run a scan in Safe Mode?

http://www.computerhope.com/issues/chsafe.htm#01
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

cidder

  • Guest
Re: found a worm but won't let me move it to chest-access denied
« Reply #8 on: November 10, 2008, 05:30:56 PM »
I don't think a boot time scan is available in Win98.

Can you run a scan in Safe Mode?

http://www.computerhope.com/issues/chsafe.htm#01
hi again frank
ran it in safe mode and got about quarter way through scan then found another trojan, but again doesnt allow removal, gives these details:
RPC server is unavailable
cannot process "C:\WINDOWS\TEMP\optimize.exe" file
malware name Win32: DyfucDldr-F@UPX (Trj)
Trojan Horse
VPS version 081109-0,11/09/2008
any ideas??

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: found a worm but won't let me move it to chest-access denied
« Reply #9 on: November 10, 2008, 06:09:25 PM »
I'm not familiar with how avast! works (or doesn't) in Win98, but you could try manually renaming or moving the file in safe mode.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

cidder

  • Guest
Re: found a worm but won't let me move it to chest-access denied
« Reply #10 on: November 10, 2008, 07:28:30 PM »
I'm not familiar with how avast! works (or doesn't) in Win98, but you could try manually renaming or moving the file in safe mode.
i'll try that frank. this has to be done in safe mode i presume. is it possible that avast is not ideal for w.98 users? do i need to upgrade system maybe, or is there a recommended anti virus/ad/spyware for win.98? i tried avg(which reports on your forum dont seem to recomm anyway, but their latest version doesnt work with win98.  maybe i need to update-thats what my wife says(but i dont think she was talking about windows!!)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89678
  • No support PMs thanks
Re: found a worm but won't let me move it to chest-access denied
« Reply #11 on: November 10, 2008, 07:42:25 PM »
As far as win98 goes, I would say avast is your best bet as it is a very small list of AVs that support win9x or winME, it has nothing to do with ideal the limitation is win9x not the AV, there are many forum members still using win9x.

The point of going into safe mode is that some malware doesn't run and that is why avast couldn't deal with it in normal mode (file in use or protected, etc.) and why FWF suggested safe mode. Being in safe mode should give you a better shot at renaming the files detected in normal and safe mode than they would in normal mode.

These tools might also help:
- MoveOnBoot http://www.download.com/EMCO-MoveOnBoot/3000-2094_4-10397293.html
- Unlocker http://ccollomb.free.fr/unlocker/ is also good as it also has a few additional features to not only delete the files but stop any process that is stopping you from deleting a file.

You would have to check if they work with win9x as there is less an less software that will work with old OSes, especially security applications.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog