![]() |
![]() | virus found cant remove: netsvcs.exe:worm.gaobot | ![]() |
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
please paste your scan report
|
|||||||||||
|
![]() |
![]() | ![]() |
Vanni
![]() |
![]() |
mabriola,
don't know if this helps, but I had a similar problem with a PC having hard disk problems. The scan detected a virus, only the hard disk was about to fail (died two days later:-( ) and trying to remove it we had errors during write and the file stood still. Obviously the virus was the lesser problem and got solved for the worse two days later... But could explain this behaviour. Best Regards |
|||||||||||
|
![]() |
![]() | ![]() |
mabriola
![]() |
![]() |
vanni,
i'm hoping that's not gonna be the case in my problem. but just in case that would be the worst scenario, im bracing myself. ============== alch, here's the scan report. hope this would help. File excluded 'C:\Documents and Settings\All Users\.clamwin\quarantine\NETSVCS.EXE' ERROR: Can't open file C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp ERROR: Can't open file C:\pagefile.sys C:\Documents and Settings\All Users\.clamwin\quarantine\NETSVCS.EXE: Worm.Gaobot FOUND -- summary -- Known viruses: 66775 Engine version: 0.88.4 Scanned directories: 254646 Scanned files: 369966 Infected files: 1 Not moved: 1 Data scanned: 19323.16 MB Time: 9399.984 sec (156 m 39 s) -------------------------------------- Completed -------------------------------------- |
|||||||||||
|
![]() |
![]() | ![]() |
budtse
![]() |
![]() |
Seems it is already moved into quarantine, so it should be safe. |
|||||||||||||
|
![]() |
![]() | ![]() |
mabriola
![]() |
![]() |
======= that should have been the case but unfortunately it wasn't quarantined when i try to delete it there. that's my dilema, coz i cant find it either in the quarantine folder nor in its's location (as reflected in the report). |
|||||||||||||||
|
![]() |
![]() | ![]() |
Vanni
![]() |
![]() |
mabriola
try using the command prompt. I seem to remember that some executables have +H and/or +S attributes set, and this renders them invisible. but if you use
you can see them right away. If clam for any reason didn't reset the file's attributes, this way you can see it. Then, if this is the case, you can reset it's attributes with
-S resets System attribute -R resets Read only attribute -H resets Hidden attribute and then you can delete it without further hassle. Hope this helps Bye |
|||||||||||||||
|
![]() |
![]() | ![]() |
mabriola
![]() |
![]() |
vanni,
![]() and to all you guys who gave their thoughts for my problem, thanks. |
|||||||||||
|
![]() |
![]() | virus found cant remove: netsvcs.exe:worm.gaobot | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.