Unable to repair or move to chest (Help Needed)

Hi,

I cannot repair or move it to chest.
File name = C:\Windows\explorer.exe
Status = Treat: Win32:Patched-TV [Trj]
When i am trying to repair = Error: Access is denied (5)
Move to chest = Error: the specified file is read only (6009)

I am using avast!FREE ANTIVIRUS version 5.

Help Needed,thanks.

check your computer for malware with this

Malwarebytes Anti-Malware 1.50.1 http://filehippo.com/download_malwarebytes_anti_malware/
always update before scanning so you have latest database
click the remove selected button to quarantine anything found
report back the result and post the scan log here

Nothing changes after remove infected files using Malwarebytes Anti-Malware 1.50.1 …
Win32:Patched-TV still here.
LOGS: http://www.megaupload.com/?d=D8U2794K

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully.

  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix:
    http://www.bleepingcomputer.com/forums/topic114351.html

Remember to re-enable them afterwards.

  1. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt

Win32:Patched detection has to do with detection in system files,
so removing fixing this you should know what you are doing

I recomend you follow this guide form our trained and certified expert malware remover Essexboy and post the log`s here
http://forum.avast.com/index.php?topic=53253.0

To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTL.Txt and Extras.Txt.)

Essexboy will be notified when you have posted the log`s
he is usually in here from 8:00pm - 11:59Pm UK time

Okay,Pondus.
Thanks for your help :slight_smile:

@Neos

Post/attach the logs her in this tread, not in the guide…

How you wish http://www.mycity.rs/Arhiva-Ambulante/Prekid-interneta-zbog-cfdrive32-exe-i-msvmiode-exe.html


http://img411.imageshack.us/img411/7647/20110110134749.jpg

As this file is patched then we have two options open to us I will use the easy one first

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[*]Double click on ComboFix.exe & follow the prompts.

[*]As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.

http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Thank you very much! :slight_smile:
Malware was successfully removed.

Have a Nice Day~

Could you run OTL now please as there may be some remnants

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in

[b]netsvcs
%SYSTEMDRIVE%*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%*. /mp /s
CREATERESTOREPOINT

[/b]

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.