Virus! Can't moved to chest. Please help.

I have Avast scanned and found I have Trojan Horse Win32 Swizzor-gen(trj).
I have tried to move it to chest but it will not go. Message comes up saying process cannot access the file being used by another process. I do not have any other windows open. I am really new to this and am worried about the virus. Scanning cannot complete due to this. Hope you can help. It’s still flashing on my screen, what can I do? I mean’t to say I have xp windows.

Hi cottage. Welcome to the forum.

First make sure Windows is up to date on your computer. Then download, install and update the free version of Ewido:

http://www.ewido.net/en/

Turn off System Restore, schedule a boot time scan in avast! and re-boot. Then scan with Ewido and, if swizzor has been removed, you can turn Sustem Restore on again if you wish.

Please post again with the results.

Files in use or in the system folders are protected by windows, even malware.
What was the virus name, what was the file name, where was it found example (C:\windows\system32\infected-file-name.xxx)?

Try the, schedule boot-time scan in avast’s menu (or try the ‘Schedule Boot-Time Scan’ using RejZoR’s AEC avast! External Control Tool

http://img.photobucket.com/albums/v325/for-dwr/boottime.jpg

Cottage, the boot time scanning could solve this as David posted.
Access denied means, generally, that the file is in use by another process (program) and cannot be repaired/cleaned/moved/handled by avast!

Are you using the last avast version or the beta version?

Thankyou everyone, I will get onto it and try what you recommend.
C/ Program Files/Alwil Software/ Avast4/Data/ report/ Resident protection.txt is what it says. Will get back later on bye

How do I turn off system restore?
Am downloading ewido now. Then I will try it.
Also what does it mean chest is full. This is when I tried to move virus to chest.

Win XP-ME - How to disable System Restore

Once you have disabled system restore, reboot, that should automatically delete the contents of the _Restore folders.

If avast has been cleaning out a lot of viruses it may be possible that you have run out of space allocated to it (or you have limited space left on your hard drive, unlikely). Check the Program Settings, Chest and increase the maximum size of the chest.

After a couple of weeks you can do some house keeping and clear out some of the old detections (older than two or more weeks) in the Infected Files section.

??? Hi David, hey thanks for the great info, I think this site is awesome. When you say house keeping and clear old detections from infected files section do you mean delete them from here or restore or ??? I n the chest it says maximum size 256MB - files sending parameters maximum size file to be sent 1024KB. Also I have infected files going back to 2005, CHEERS COTTAGE

Cottage,

Files go into the chest in case the virus detection is a false positive. This is not too common but when it happens it is usually corrected after an update or two. The two week wait David suggests gives plenty of time for any needed corrections to be made.

You can re-scan the older chest files if you wish and, if they are still indicated as infected, they should be deleted. Infected files should normally never be restored.

btw, have you had any luck with the recommended scans?

David - the link you provided is broken.

Thanks mauserme, looks like they have been doing some house keeping, I can’t find it anywhere on the site either, so I have another link - Win XP-ME - How to disable System Restore


Also, be sure to NOT delete the file in the Chest listed under System files. :wink:

These are not infected files but are backup files just in case they are ever needed.


Hello, all, I have been worried about doing the wrong thing so I haven’t turned off xp systen restore yet. I have printed off info for it , reading it throughly first. I think for me I will get someone to help here at home. Dont want to do the wrong thing. I’m really green with this tec, but this forum is fantastic.
But went to infected files, scanned files that were there and found most of them came up with no virus. So went to chest restored one by one then deleted them, hope this was right. Whowwwwww!! Left the ones that said still had a virus. Is this ok? I thought after that having lots of room that virus I have would go to chest but no, no it won’t.
Till I hear, Cottage

Strange… Did you have that many false positives?

If you updated avast and they’re shown as clean, seems right.
But to judge we need to know the full name of the file (with the path) and the name of the virus.

Sure.

Can you rephrase? Do you mean get ‘free’ space in the disk? In the Chest?

Hello Tec, yes I thought it would give me space in the chest so I could moved the virus to chest, also yes I had alot that wern’t virus or they healed themselves. Don’t know. Saw a lady fron a interent business today and asked her opinion about this so called virus, she said it was serious that she thinks something has got into my avast files and I need to let avast know about it. I don’t know if I should take her word or not on the matter she wants to have my computer in her shop in the morning. I have been conned before so I leaving it for now. The info is: C.Program Files/Alwil Software/Avast4/Data/ Report/ Resident protection txt = it comes up as Trojan Horse Win32 Swizzor - gen (trj).
cottage

This is avast scanning report of the Standard Shield (resident).
It should not be infected itself… it is just a text file.
Is there any other file listed there that is detected as infected? It is a report…

Thankyou Tec, so why does it come up as a virus? What do you think if I remove Avast then reinstall it again, would it help. What will happen to the virus in chest if I do this? I have boot scanned a few times. I will take this info to a man here that worked with Avast programme. Cheers. Cottage.

Are you sure? Can you post a screenshot of the detection?

I don’t think so… Can you just delete the file and empty your recycle bin?

What? A virus into Chest is not ‘related’ to a file outside of there… I mean, the report has nothing to do with the file in Chest…
What do you mean?

Tec, I hope you are there online, I have the warning up on my screen now but I have no idea how to send it to you.
Can you tell me?
Cottage. I’ll wait.


Hi cottage,

Take a screenshot of the warning message and then read the first post at the link below on how to add it to a post in the forum.

http://forum.avast.com/index.php?topic=8982.0


Hey Tec, how do I take a screen shot? Cottage