Help! My avast deteceted two virus yesterday C:\windows\system32\config\SOFTWARE

I tried to boot scan but avast couldn’t detected it. And when I try to run full scan avast detects this two virus :-\ I tried to delete,move to chest or fix it automatically but it says action postponed until next reboot and when i try to delete or move it to chest it says access denied (5)
http://s240.photobucket.com/user/gohan312/media/Untitled1.png.html

http://s240.photobucket.com/user/gohan312/media/Untitled.png.html

https://forum.avast.com/index.php?topic=53253.0

I tried to delete,move to chest or fix it automatically but it says action postponed until next reboot and when i try to delete or move it to chest it says access denied (5)
where are detected files located? .... full file path

EDIT: sorry, did not read your topic title …so guess this is the location

C:\windows\system32\config\SOFTWARE

follow instructions in the guide Eddy gave link to

I tried to scan it with malwarebytes and it couldn’t detect this two virus. :-\ But when I triy to full scan with avast it detects this virus :o :o :o

what malware name does avast give?

oh thanks ! ::slight_smile:

here is it. sir
http://s240.photobucket.com/user/gohan312/media/Untitled.png.html
http://s240.photobucket.com/user/gohan312/media/Untitled1.png.html
I tried to delete it or move it to chest but doesn’t do anything, why?

I tried to delete it or move it to chest but doesn't do anything, why?
probably because the file is in use .....

[quote author=Pondus link=topic=167426.msg1191001#msg1191001 date=1425629305]

probably because the file is in use .....

Is there anyway to fix this? :frowning: :-\ ???

Follow the instructions in the link I gave you.

Here is it, eddy. Tell me if I’ve left any important details out :open_mouth: So what do I do next? Thanks!

Let me know if the alerts cease after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: c:\windows\system32\config\software.log1 c:\windows\system32\config\software.log2 EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that