error while cleaning - operation unavailable for this type of object

Discussion in 'NOD32 version 2 Forum' started by Lollan, Aug 8, 2006.

Thread Status:
Not open for further replies.
  1. Lollan

    Lollan Registered Member

    Joined:
    Feb 2, 2006
    Posts:
    288
    Having difficulty removing an infection from a system today, wanted to see if you could provide me with some assistance. :)

    AMON logs the intrusion as "file C:\WINDOWS\Help\runabr.dll Win32/Agent.CS trojan error while cleaning - operation unavailable for this type of object DDKG7D61\AdAm Event occurred at an attempt to access the file by the application: C:\WINDOWS\explorer.exe."


    Ran a Jotti/Virustotal just to make sure it wasn't an FP, of course it isn't, as all of the scanners caught it as something or other.

    Scans in normal/safe mode do not see it because AMON is setup to clean automatically. (But the file is generated every second according to my threat log) I have attempted to remove this file with killbox as well, but it is unable to remove the file. Any ideas?
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Hello,
    did you have NTFS AD streams enabled in the on-demand scanner setup?
     
  3. Lollan

    Lollan Registered Member

    Joined:
    Feb 2, 2006
    Posts:
    288

    Yes, it is enabled.
     
  4. tsilo

    tsilo Registered Member

    Joined:
    Apr 29, 2006
    Posts:
    376
    Once i cheked my friend computer's nod32 threat log, there was a virus created by mywebsearch and nod32 can't clean it ( error while cleaning - operation unavailable for this type of object...Event occurred at an attempt to access the file by the application: C:\WINDOWS\explorer.exe), so I deleted it manualy without problem, I'am interesting It 's dificult to configure nod32 that way he can delete such kind of viruses automaticly?

    sorry for my english
     
  5. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    AMON is set to move all newly created files to quarantine automatically. If you set AMON to clean infected files, it will not be able to clean uncleanable malware (trojans, backdoors, etc.), but will still block access to such files.
     
  6. tsilo

    tsilo Registered Member

    Joined:
    Apr 29, 2006
    Posts:
    376
    So what to do?
    If I set prohibit accses & show alert window with action option, it will give me option delete that file? or I must unset :move newly created infected files to quarantine?
     
  7. ASpace

    ASpace Guest

    Yes .


    If it is set to Clean automatically , AMON will atempt to clean the file , however trojans, spywares.... cannot be cleaned,they are just deleted . Since Agent is a trojan , AMON can't clean it so it will only prohibit the access to that file .

    Move newly created infected file is quite useful options . It will move all newly created malware to quarantine , however in that case (Event occurred at an attempt to access the file by the application: C:\WINDOWS\explorer.exe) the file is not new
     
  8. tsilo

    tsilo Registered Member

    Joined:
    Apr 29, 2006
    Posts:
    376
    SO why don't add option to avtomatically delete such kind of files?
     
  9. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    For security reasons AMON CANNOT DELETE files AUTOMATICALLY.
     
  10. tsilo

    tsilo Registered Member

    Joined:
    Apr 29, 2006
    Posts:
    376
    Can you tell me please for what kind security reasons AMON CANNOT DELETE files AUTOMATICALLY?
     
  11. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    For instance, having a false positive on system files would render your OS unuseable if AMON deleted certain crucial files automatically. The same goes for files infected with viruses that cannot be cleaned.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.