You’re giving me credit for being much smarter than I am…
- I don’t know how to “disable system restore” or what it does
- I don’t think Avast Home has a “task manager”
- I’m not smart enough to fool with registries
- what is “disinfect”
In looking for logs, I didn’t find much, but here are recent entries from a couple I did find:
from Resident Protection log:
- avast! Report
- This file is generated automatically
- Task ‘Resident protection’ used
- Started on Thursday, March 11, 2004 6:11:03 PM
- VPS: 0403-7, 03/11/2004
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
During the file delete, error occurred: The process cannot access the file because it is being used by another process
During the file delete, error occurred: The process cannot access the file because it is being used by another process
During the file delete, error occurred: The process cannot access the file because it is being used by another process
During the file repair, error occurred: The process cannot access the file because it is being used by another process
During the file repair, error occurred: The process cannot access the file because it is being used by another process
During the file repair, error occurred: The process cannot access the file because it is being used by another process
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
During the file rename/move, error occurred: The process cannot access the file because it is being used by another process
During the file rename/move, error occurred: The process cannot access the file because it is being used by another process
During the file rename/move, error occurred: The process cannot access the file because it is being used by another process
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
C:\WINDOWS\SYSTEM32\EWDLHQD.DLL [L] Win32:Trojan-gen. {Other} (0)
- Task stopped: Thursday, March 11, 2004 7:07:09 PM
- Run-time was 56 minute(s), 6 second(s)
Note: multiple entries above are because Avast! continually bugged me about that file and wouldn’t delete it so I had to stop Avast! in order to do anything else with the computer.
from ASW Boot log:
11/03/2004 11:10
Scan of all local drives
File C:\Documents and Settings\Me\Local Settings\Temp\arcebxe.dll is infected by Win32:Trojan-gen. {Other}
11/03/2004 11:13
Scan of all local drives
File C:\Documents and Settings\Me\Local Settings\Temp\arcebxe.dll is infected by Win32:Trojan-gen. {Other}
11/03/2004 11:21
Scan of all local drives
11/03/2004 19:08
Scan of all local drives
File C:\Documents and Settings\Me\Local Settings\Temp\arcebxe.dll is infected by Win32:Trojan-gen. {Other}
Note: entries above appear to have been generated whilst the system was rebooting after I asked for a scan on restart; none of those scans on restart seemed to finish as I only got a blank screen after the initial WinXP logo, and WinXP never came back up.
My questions, though, are a bit more generic:
-
Why doesn’t Avast! run a scan on WinXP startup as it says it will and seems to try to do? (ie, something is failing there)
-
If Avast! can’t delete a file because it is hidden or in use, and the scan on startup doesn’t work, then how DO you get rid of the file?