zippy32
Joined: 01 May 2009 |
Posts: 0 |
Location: Australia |
|
 |
Posted: Sun Aug 02, 2009 10:33 am |
|
 |
 |
 |
 |
Hi I have been noticing that my computer has been running very slow so I did a scan with Clamwin 0.95.2 version and it detected this:
Scan Started Sun Aug 02 17:37:07 2009
-------------------------------------------------------------------------------
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbc2e.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbdam: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbdao: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbeam: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbeao: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbm: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbu2d.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbvm.cf1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\dbvmh.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\fii.cf1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\fiih.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\rpm.cf1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Application Data\Google\Google Desktop Search\rpmh.ht1: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF5D52.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF6512.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF6C13.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF766E.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF7F73.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\~DF7F8C.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temporary Internet Files\Content.Word\~WRS0004.tmp: Permission denied
C:\Documents and Settings\Zippy\Local Settings\Temp\plugtmp-68\plugin-sinceYearsWord.pdf: Exploit.PDF-71 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 606492
Engine version: 0.95.2
Scanned directories: 670
Scanned files: 10942
Infected files: 1
Data scanned: 9635.24 MB
Data read: 11458.85 MB (ratio 0.84:1)
Time: 2119.704 sec (35 m 19 s)
I have searched online for this but no idea what it is. Could you please tell me whether this is a serious virus or trojan? I have located that file and cut and pasted it into the quarantine folder.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sun Aug 02, 2009 4:56 pm |
|
 |
 |
 |
 |
The best way to verify a detection is actually a real virus infection and not a false positive is to submit the file to Jotti at https://virusscan.jotti.org/en or to VirusTotal at https://www.virustotal.com/ on the web. Either service will scan your file for free with multiple antivirus scanners, including Clam AV (which provides the scan engine/signatures for ClamWin). If several other AVs besides Clam find an infection, it is probably a real infection. (I like to see at least 5 AVs in total). If it is a real infection, either delete it manually from your computer or temporarily set ClamWin's infected file option to Quarantine or Remove and scan the file again (just the file or its directory--nothing else), and it will quarantine or remove the file with the virus. Don't forget to re-set ClamWin's infected file option to Report Only, which you should use for a standard option.
If it was a false positiive, report it to Clam AV, starting at https://www.clamav.net/sendvirus/ on the web. When you get to the submission/upload page, be sure to indicitate it is a false positive, give them the exact name of the false positive detection, and tell why you think it is a false positive in the comment block. Clam will normally fix the signature within a day or two.
Regards,
|
|