 |
 | Trojan Not Removing |  |
mayask
Joined: 22 Sep 2009 |
Posts: 0 |
Location: India |
|
 |
Posted: Tue Apr 19, 2011 9:55 am |
|
 |
 |
 |
 |
We have installed Clamwin latest update but not able to remove these trojan, can anybody help :
trogen.geneticFF1
trojan.agent-167007
trojan.downder
Thanks in advance.
|
|
 |
 | |  |
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Apr 19, 2011 12:51 pm |
|
 |
 |
 |
 |
That FF detection gets a lot of false positive (not really a virus) detections. Do you have the ClamWin infected option set to the default Report Only? You have three options: Report Only, Remove (not a good idea), or Quarantine. Before you do anything, I suggest you upload the files to Jotti at https://virusscan.jotti.org/en on the web or to Virus Total at https://www.virustotal.com/ on the web. Either service will scan your file (one at a time) with multiple AV programs, including the Clam AV engine used by ClamWin. If more than a few AVs besides Clam see an infection, it is probably for real. If only a few AVs besides Clam see an infection, it is probalby a false positive, and you should temporarily whitelist the file in ClamWin's exclusion filters (exclude matching filenames: filename.extension) and upload the file to Clam AV, starting at https://www.clamav.net/lang/en/sendvirus/ on the web. When you get to the submission form, be sure to tag the file as a false positive and tell the exact name of the false detection in the comments section. Clam will correct the signature within 2/3 days, and you can remove the file from ClamWin's filters then.
Viruses can use the same techniques as "good" files. I like to see at least 10 AVs on Jotti/Virus Total spot an infection before I believe it. If less than 10, I like to see a couple of these AVs spot something before I believe it: AntiVir, Avast, Bitdefender, Nod32, or Sophos.
If the file is infected, you can either remove it manually from its directory, or set ClamWin's infected files option to Quarantine (not remove-just in case).
If you have ClamWin already set to Quarantine or Remove and a virus keeps coming back, there is probably a real infection with a "control" somewhere that re-infects. Try a scan in Safe Mode or get Malwarebytes' free edition and install it and then scan with it (it's good at removing infections but not at stopping them in the first place).
Regards,
|
|
 |
 | |  |
mayask
Joined: 22 Sep 2009 |
Posts: 0 |
Location: India |
|
 |
Posted: Tue Apr 19, 2011 1:17 pm |
|
 |
 |
 |
 |
i have check at virustotal and it show virus and we have installed malwarebytes and it is clean.
thanks
now i want to know can we add malwarebytes signature file in Clamwin ? Pls reply.
|
|
 |
 | |  |
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Apr 19, 2011 7:34 pm |
|
 |
 |
 |
 |
You can not use the Malwarebytes' signatures in ClamWin. Each AV its own signature format and may not be able to recognize the signatures of another AV. Malwarebytes is very good at finding viruses AFTER they get on your computer. It does not do a good job of finding viruses BEFORE they get on your computer. Actually, ClamWin is better than Malwarebytes at that--because it has more signatures--almost 950,000 signatures now. ClamWin and Malwarebytes make a good combination if you fp a daily scan with each of them. I use both and scan with ClamWin at noon and scan with Malwarebytes at the end of the day.
You may want to look into the Clam Sentinel project at https://sourceforge.net/projects/clamsentinel/ on the web. It is a separate project that lets you scan with ClamWin in real time--as files are added to, modified, or copied on your computer. Clam Sentinel also has its own heuristic scanning engine which can identify many new viruses for which ClamWin does not yet have a signature. Sentinel can be used on Windows 98 up to Windows 7 computers, and it is constantly being improved. It can monitor USB drives, and it uses the ClamWin quarantine folder.
Regards,
|
|
 |
 | |  |
mayask
Joined: 22 Sep 2009 |
Posts: 0 |
Location: India |
|
 |
Posted: Wed Apr 20, 2011 10:01 am |
|
 |
 |
 |
 |
Ok. but today when i again scan our computer through Clamwin it show Virus "trojen.geneticFF1 " and clamwin and Malwarebytes is not not able to quarantine / delete ? is any other way for this Trojen ?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Wed Apr 20, 2011 1:37 pm |
|
 |
 |
 |
 |
Set ClamWin's infected files option to Quarantine and rescan. ClamWin will place it in quarantine. If it does not, please copy the scan report and paste it here.
Regards,
|
|
trinityy
Joined: 21 Apr 2011 |
Posts: 0 |
Location: newyork |
|
 |
Posted: Tue Apr 26, 2011 1:24 pm |
|
 |
 |
 |
 |
I think you have to install any good antivirus. first try to restore settings so that maybe it will remove trojan but if it don't then install any good antivirus and scan your computer.
You can also try the Norton antivirus software, it has 60 days money back warranty. if you want to buy it, you can use the Norton coupon from https://www.dailydeals4you.com/norton-coupon to save you some money.
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
|  |