ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Trojan Not Removing
mayask


Joined: 22 Sep 2009
Posts: 0
Location: India
Reply with quote
We have installed Clamwin latest update but not able to remove these trojan, can anybody help :
trogen.geneticFF1
trojan.agent-167007
trojan.downder

Thanks in advance.
View user's profileSend private messageSend e-mail
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
That FF detection gets a lot of false positive (not really a virus) detections. Do you have the ClamWin infected option set to the default Report Only? You have three options: Report Only, Remove (not a good idea), or Quarantine. Before you do anything, I suggest you upload the files to Jotti at https://virusscan.jotti.org/en on the web or to Virus Total at https://www.virustotal.com/ on the web. Either service will scan your file (one at a time) with multiple AV programs, including the Clam AV engine used by ClamWin. If more than a few AVs besides Clam see an infection, it is probably for real. If only a few AVs besides Clam see an infection, it is probalby a false positive, and you should temporarily whitelist the file in ClamWin's exclusion filters (exclude matching filenames: filename.extension) and upload the file to Clam AV, starting at https://www.clamav.net/lang/en/sendvirus/ on the web. When you get to the submission form, be sure to tag the file as a false positive and tell the exact name of the false detection in the comments section. Clam will correct the signature within 2/3 days, and you can remove the file from ClamWin's filters then.

Viruses can use the same techniques as "good" files. I like to see at least 10 AVs on Jotti/Virus Total spot an infection before I believe it. If less than 10, I like to see a couple of these AVs spot something before I believe it: AntiVir, Avast, Bitdefender, Nod32, or Sophos.

If the file is infected, you can either remove it manually from its directory, or set ClamWin's infected files option to Quarantine (not remove-just in case).

If you have ClamWin already set to Quarantine or Remove and a virus keeps coming back, there is probably a real infection with a "control" somewhere that re-infects. Try a scan in Safe Mode or get Malwarebytes' free edition and install it and then scan with it (it's good at removing infections but not at stopping them in the first place).

Regards,
View user's profileSend private message
mayask


Joined: 22 Sep 2009
Posts: 0
Location: India
Reply with quote
i have check at virustotal and it show virus and we have installed malwarebytes and it is clean.

thanks

now i want to know can we add malwarebytes signature file in Clamwin ? Pls reply.
View user's profileSend private messageSend e-mail
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You can not use the Malwarebytes' signatures in ClamWin. Each AV its own signature format and may not be able to recognize the signatures of another AV. Malwarebytes is very good at finding viruses AFTER they get on your computer. It does not do a good job of finding viruses BEFORE they get on your computer. Actually, ClamWin is better than Malwarebytes at that--because it has more signatures--almost 950,000 signatures now. ClamWin and Malwarebytes make a good combination if you fp a daily scan with each of them. I use both and scan with ClamWin at noon and scan with Malwarebytes at the end of the day.

You may want to look into the Clam Sentinel project at https://sourceforge.net/projects/clamsentinel/ on the web. It is a separate project that lets you scan with ClamWin in real time--as files are added to, modified, or copied on your computer. Clam Sentinel also has its own heuristic scanning engine which can identify many new viruses for which ClamWin does not yet have a signature. Sentinel can be used on Windows 98 up to Windows 7 computers, and it is constantly being improved. It can monitor USB drives, and it uses the ClamWin quarantine folder.

Regards,
View user's profileSend private message
mayask


Joined: 22 Sep 2009
Posts: 0
Location: India
Reply with quote
Ok. but today when i again scan our computer through Clamwin it show Virus "trojen.geneticFF1 " and clamwin and Malwarebytes is not not able to quarantine / delete ? is any other way for this Trojen ?
View user's profileSend private messageSend e-mail
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Set ClamWin's infected files option to Quarantine and rescan. ClamWin will place it in quarantine. If it does not, please copy the scan report and paste it here.

Regards,
View user's profileSend private message
trinityy


Joined: 21 Apr 2011
Posts: 0
Location: newyork
Reply with quote
I think you have to install any good antivirus. first try to restore settings so that maybe it will remove trojan but if it don't then install any good antivirus and scan your computer.

You can also try the Norton antivirus software, it has 60 days money back warranty. if you want to buy it, you can use the Norton coupon from https://www.dailydeals4you.com/norton-coupon to save you some money.
View user's profileSend private message
Trojan Not Removing
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic