attitudezen
Joined: 01 Nov 2007 |
Posts: 0 |
Location: Belgium |
|
 |
Posted: Thu Nov 01, 2007 9:32 pm |
|
 |
 |
 |
 |
Good evening everybody,
I am a new member of this forum : i live in Belgium. Please excuse me if I make some mistakes in English ok ?
The PC of one of my friend has found 3 virus :
1) C:\ANCIEN-C\Program Files\Executive Software\Diskeeper Setup\Data.Cab: Trojan.Downloader.Small-829 FOUND
2) C:\ANCIEN-C\Program Files\Executive Software\Diskeeper Setup\DiskeeperServer.msi: Trojan.Downloader.Small-829 FOUND
3) C:\Documents and Settings\admin\Mes documents\Downloads\(Release) oui, mais... 1 35.zip: Adware.Advertmen-1 FOUND
She has the Clamwin too but did not how to remove these infections.
Could you please help us ?
Do not hesitate to contact me per mail if you need more info
Many thanks
Mireille
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Fri Nov 02, 2007 1:26 am |
|
 |
 |
 |
 |
ClamWin doesn't remove any viruses/malware it finds--it is a "lean" antivirus program. If you have configured ClamWin to quarantine viruses/malware, it will put the infected file in a quarantine folder, and you can go to that folder in Windows Explorer and delete it manually. You can go to the General tab in the ClamWin configuration menu and find out where the quarantine folder is--in Windows XP it is usually on your computer at C:\Documents and Settings\All Users\.clamwin\quarantine .
If you have not configured ClamWin to quarantine malware, look at ClamWin's scan report to find out where the quarantine file is located on your computer. Go to that folder in Windows Explorer and delete the file it manually.
I prefer to configure ClamWin to Report malware to me instead of quarantining it. ClamWin could have a false positive and recognize a file as containing malware when it does not--it happens sometimes. If this happens, and the file is an important one (such as a Windows file), you could have a problem using your computer. Before I delete a file, I always upload it to Jotti or VirusTotal, which are free services on the Web that will scan a file for you and give you a report telling you what other antivirus scanners say about the file. If a couple of other scanners besides Clam find the file is infected, it is probably a real virus--not a false positive, and you can safely delete it if it is not an important Windows file. You can find Jotti at https://virusscan.jotti.org/ and VirusTotal is at https://www.virustotal.com/ on the Web.
Regards,
|
|
attitudezen
Joined: 01 Nov 2007 |
Posts: 0 |
Location: Belgium |
|
 |
Posted: Fri Nov 02, 2007 8:31 am |
|
 |
 |
 |
 |
> Guitarbob
Good morning,
Thanks a lot for your prompt and precise answer.
I will check and revert if the problem persists.
Have a nice day!
|
|