ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Can Clam block or remove "Bagle Virus" ?
Donny17


Joined: 15 Feb 2008
Posts: 0
Reply with quote
I was using Avast Antivirus and it did not detect this virus. While searching through forums read where Clam may
solve this problem.
This virus deactivates anti virus programs and will not allow any new one to be installed. I located a couple of
this viruses files but they cannot be deleted. Also it will not allow you to go into safe mode.
I got this virus three time recently and had to redo my computer.
I would appreciate any feed back on this subject.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
It's hard to remove much of today's malware once it infects a computer. There can be thousands of variants of a single virus, and the virus writers change their "product" very quickly. If you have used/are using a paid commercial antivirus product, you should contact the vendor of the antivirus for help. Stick with them and have patience, because it may take some time to help you remove it, and you will help the antivirus company improve their product.

ClamWin spots viruses that are in its signature database unless they are packed/obfuscated with a method that it is not familiar with, and this sometimes happens when rootkits/special packers are used by the virus writer. ClamWin will notify/quarantine/remove any malware it finds (depending upon how you configure it), but it cannot disinfect/undo damage the virus may have done to your computer.

Below are some links that might help, but I suggest you stick with your paid commercial AV.

Experienced Free Malware Removal Assistance
A-Squared (Emsisoft) (with initial self help) at https://forum.emsisoft.com/Default.aspx?g=topics&f=38
Bleeping Computer Dot Com (with initial self help) at https://www.bleepingcomputer.com/<br>
Castle Cops (with initial self help) at https://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
Malwareteks (same personnel at Emsisoft) (with initial self help) at https://www.malwareteks.com/forum.html
Spyware Warrior has free help and a list of rogue antispyware products at https://www.spywarewarrior.com/index.php

On Line Hard Drive Scanners That Are Easy On Resources And Not Invasive</b></font>
A-Squared (Emsisoft) malware scan at https://www.emsisoft.com/en/software/ax/
ESET (NOD32) malware scan at https://www.eset.com/onlinescan/index.php
Microsoft Live One Care Scan for malware at https://onecare.live.com/site/en-us/default.htm?s_cid=sah/?s_cid=sah
Panda NanoScan for malware at https://www.nanoscan.com/
Secunia tracks software vulnerabilities and provides free software vulnerability inspections at https://secunia.com/
Trend Micro Housecall scan for malware at https://housecall.trendmicro.com/

Regards,
View user's profileSend private message
polecat


Joined: 19 Mar 2008
Posts: 0
Reply with quote
Whenever I had a customer bring me a computer that was similarly infested with viruses and spyware, and they didn't want me to reformat, I would do one of two things:

1) Remove their hard drive, install it in another computer as a slave drive and then scan that drive with up-to-date antivirus and antispyware programs.

OR

2) Boot with a BartPE (or similar) live CD that contains antivirus and antispyware tools on it and then scan the hard drive.

Also, be sure that once you do boot back into Windows that you delete all of your system restore points (XP, Vista) because they can keep a copy of the virus even after you thought you removed it.
View user's profileSend private message
Re: Can Clam block or remove "Bagle Virus" ?
JMR


Joined: 15 May 2008
Posts: 0
Reply with quote
Donny17 wrote:
I was using Avast Antivirus and it did not detect this virus. While searching through forums read where Clam may
solve this problem.
This virus deactivates anti virus programs and will not allow any new one to be installed. I located a couple of
this viruses files but they cannot be deleted. Also it will not allow you to go into safe mode.
I got this virus three time recently and had to redo my computer.
I would appreciate any feed back on this subject.


I had a similar problem with a Windows integrity scan pop up on IE every time I would load it up. I use Panda Internet Security 2008 (I am getting ready to scrap it though and am search for an new AV to use) and it would not find the problem. I ended up finding the two files in the System folder and was having a difficult time deleting the files. I did find a perfect solution with this free little program called unlocker (https://ccollomb.free.fr/unlocker/). Worked like a charm, you may want to give it a try next time your run into one of those annoying programs that wound delete.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
If you are sure a file is infected, and it's not one you need, you can usually rename it and then delete it. F-Secure's Blacklight offers to rename rootkit files it finds, and then you have to go in and manually delete them yourself. Example: just rename malfile.exe to infectedmalfile.exe and manually delete it.

Once you get an active infection, it's Game Over for many antivirus programs. I recently ran a test on the Srizi rootkit, and it made 12 pages of changes to my virtual machine. That's a lot to ask a small antivirus program without many development/analytical resources to undo! It much better to detect a dropped malware file before it becomes active. Thankfully, a lot of files associated with malware are benign once the file containing the actual malware is removed.

Regards,
View user's profileSend private message
Can Clam block or remove "Bagle Virus" ?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic