ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
What is this ---- plugtmp-68\plugin-sinceYearsWord.pdf
zippy32


Joined: 01 May 2009
Posts: 0
Location: Australia
Reply with quote
Hi I have been noticing that my computer has been running very slow so I did a scan with Clamwin 0.95.2 version and it detected this:

Scan Started Sun Aug 02 17:37:07 2009
-------------------------------------------------------------------------------

C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbc2e.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbdam: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbdao: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbeam: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbeao: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbm: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbu2d.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbvm.cf1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbvmh.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\fii.cf1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\fiih.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\rpm.cf1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\rpmh.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF5D52.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF6512.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF6C13.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF766E.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF7F73.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF7F8C.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temporary Internet Files\Content.Word\~WRS0004.tmp: Permission denied

C:\Documents and Settings\Zippy\Local Settings\Temp\plugtmp-68\plugin-sinceYearsWord.pdf: Exploit.PDF-71 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 606492
Engine version: 0.95.2
Scanned directories: 670
Scanned files: 10942
Infected files: 1

Data scanned: 9635.24 MB
Data read: 11458.85 MB (ratio 0.84:1)
Time: 2119.704 sec (35 m 19 s)


I have searched online for this but no idea what it is. Could you please tell me whether this is a serious virus or trojan? I have located that file and cut and pasted it into the quarantine folder.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
The best way to verify a detection is actually a real virus infection and not a false positive is to submit the file to Jotti at https://virusscan.jotti.org/en or to VirusTotal at https://www.virustotal.com/ on the web. Either service will scan your file for free with multiple antivirus scanners, including Clam AV (which provides the scan engine/signatures for ClamWin). If several other AVs besides Clam find an infection, it is probably a real infection. (I like to see at least 5 AVs in total). If it is a real infection, either delete it manually from your computer or temporarily set ClamWin's infected file option to Quarantine or Remove and scan the file again (just the file or its directory--nothing else), and it will quarantine or remove the file with the virus. Don't forget to re-set ClamWin's infected file option to Report Only, which you should use for a standard option.

If it was a false positiive, report it to Clam AV, starting at https://www.clamav.net/sendvirus/ on the web. When you get to the submission/upload page, be sure to indicitate it is a false positive, give them the exact name of the false positive detection, and tell why you think it is a false positive in the comment block. Clam will normally fix the signature within a day or two.

Regards,
View user's profileSend private message
What is this ---- plugtmp-68\plugin-sinceYearsWord.pdf
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic