ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Can't remove virus permission denied
DannyT


Joined: 21 May 2012
Posts: 0
Reply with quote
Clamwin has been reporting an infected file for some time so I just tested it with jotti and it definitely seems infected:

Quote:
C:\Windows\System32\DriverStore\FileRepository\lsi_sas.inf_amd64_neutral_a4a3b4a2006efbc9\wdcfg.exe: Worm.Tenga.A FOUND


However, Clamwin hasn't been quarantining the file and I just tried to manually remove it and can't being given a Permission Denied error.

It seems somehow it's been completely locked down and even as administrator I'm unable to add, change or remove permissions on this particular folder (apparently I need permission from SYSTEM).

This is on a Win2008 machine, is there some higher privileges I can get somehow (command line perhaps?)

Any help much appreciated!
View user's profileSend private message
DannyT


Joined: 21 May 2012
Posts: 0
Reply with quote
Finally managed to change permissions by issuing the following from cmd run as Administrator:

Code:
takeown /f myinfectedfile.exe
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Thanks for the info, Danny--it might help someone else. I'm glad you were able to remove the file. You may have been able to do so with the free Unlocker program. Malwarebytes also comes with a tool called File Assassin that does the same thing. Also, you may have been able to remove the file when in Windows Safe Mode.

If 2 of these AVs see an infection on Jotti or Virus Total, I will believe it: Avira AntiVir, Bitdefender, NOD32, Kaspersky, or Sophos.

Regards,
View user's profileSend private message
Can't remove virus permission denied
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic