E Chen
Joined: 12 May 2008 |
Posts: 0 |
Location: UK |
|
 |
Posted: Fri Jul 10, 2009 5:11 pm |
|
 |
 |
 |
 |
Hi folks
On a very slow booting and running laptop the Start up file "microsoft office" has been found.
Searching on the net found at https://www.bleepingcomputer.com/startups/Microsoft_Office.exe-13745.html
states:
This is an undesirable program.
This file has been identified as a program that is undesirable to have running on your computer. This
consists of programs that are misleading, harmful, or undesirable.
If the description states that it is a piece of malware, you should immediately run an antivirus and
antispyware program. If that does not help, feel free to ask us for assistance in the forums.
Command: C:\Windows\System32\Microsoft Office.exe
Description: Added by the Troj/Bancban-LH Internet banking Trojan.
File Location: %System%
Startup Type: This startup entry is started automatically from a Run, RunOnce, RunServices, or
RunServicesOnce entry in the registry.
A Clamwin scan failed to identify this Trojan.
Does Clamwin recognise this problem or might Clamwin have been attacked/corrupted by its activity.
Anyone know how to remove this Tojan?
TVM in anticipation
E.Chen
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sun Jul 12, 2009 2:14 am |
|
 |
 |
 |
 |
I suggest you uploat the file in question to Jotti at https://www.clamwin.com/content/view/18/46/ on the web. Jotti will scan it for free with about 20 AVs, including Clam AV (which furnishes the scanning engine/signatures for ClamWin). If several other AVs besides Clam find an infected file, it is probably a real infection. If only a couple of AVs find an infection, it is probably a false positive detection (a false detection) and not a real infection. If the infection is real, and you need the file, delete the file from your computer and replace it with a "good" one if you can. Report false positives to Clam AV at https://www.clamav.net/sendvirus/ on the web. When you get to the upload page, be sure to check the false positive block, tell them the exact name of the false positive virus, and tell in the comment section why you think it is a false positive.
ClamWin doesn't have a very high profile, so the chances of a virus targeting it are not very high--but it could happen. I suggest you use ClamWin as a backup scanner to a real-time antivirus scanner (ClamWin is only an on-demand scanner) that scans files when they are put on your computer. There are several decent free real-time scanners, including AVG, AntiVir, Avast, PC Tools, and the Microsoft Security Essentials scanner (now in beta testing).
Regards,
|
|