Clamwin has been reporting an infected file for some time so I just tested it with jotti and it definitely seems infected:
Quote: |
C:\Windows\System32\DriverStore\FileRepository\lsi_sas.inf_amd64_neutral_a4a3b4a2006efbc9\wdcfg.exe: Worm.Tenga.A FOUND |
However, Clamwin hasn't been quarantining the file and I just tried to manually remove it and can't being given a Permission Denied error.
It seems somehow it's been completely locked down and even as administrator I'm unable to add, change or remove permissions on this particular folder (apparently I need permission from SYSTEM).
This is on a Win2008 machine, is there some higher privileges I can get somehow (command line perhaps?)
Any help much appreciated!