The Mudcat Café TM
Thread #147407   Message #3416087
Posted By: JohnInKansas
07-Oct-12 - 08:57 PM
Thread Name: Tech: Virus help 2012.10.07
Subject: RE: Tech: Virus help 2012.10.07
A common reason for your AV being unable to quarantine (or delete) something is that a file that is "open" can't be moved or deleted. This sometimes happens even with the relatively innocuous "tracking cookies" that most AV sets try to keep cleaned out.

Some malware inserts itself into the Startup folder so that it's launched (and has files open) whenever you boot, so a "Clean/Safe Boot" is necessary to prevent the Startups from running.

Restarting in Safe Mode, with minimal other trash running, sometimes will allow your regular AV to rescan and omplete the quarantine, if you can get a clean enough start that the AV program is the only thing with open files.

SOME AV programs can run from a Recovery Disk that boots the machine only to a Command Prompt (still called a "boot to DOS" by some) which is perhaps the "cleanest" boot that you can get easily, but that capability is less frequently included with "modern" protection suites than for older (or just simpler) ones, partly because some newer programs use Windows service functions and won't run all their functions from a "pure" Command Prompt boot.

If your AV allows you to make a recovery disk of this kind, the disk should of course be made on a "clean machine" and then moved to the possibly infected one to boot it for cleaning.

John