| Uriel
 
 
 
			| Joined: 28 Jan 2013 |  | Posts: 0 |  |  |    |  | 
	
		|  Posted: Mon Jan 28, 2013 4:09 pm |  |  |  |  
		|  |  |  I'm getting a hit for an infected file but ClamWin isn't able to clean or delete the file (even after a reboot), I suspect this is because it's in the WinSxS directory.  I've searched for this virus but can't find any information about it anywhere - does anyone know what the name this goes by and/or how to clean it?
 Scan result:
 
 C:\Windows\winsxs\Temp\PendingDeletes\$$DeleteMe.authz.dll.01c9f3a32c366170.00d2: Win.Trojan.Agent-121982 FOUND
 ----------- SCAN SUMMARY -----------
 Known viruses: 1670532
 Engine version: 0.97.4
 Scanned directories: 13416
 Scanned files: 49391
 Infected files: 1
 
 Not copied: 1
 Data scanned: 7675.81 MB
 Data read: 9674.71 MB (ratio 0.79:1)
 Time: 1510.820 sec (25 m 10 s)
 
 --------------------------------------
 Completed
 --------------------------------------
 | 
	| 
 | 
	| GuitarBob
 
 
 
			| Joined: 09 Jul 2006 |  | Posts: 9 |  | Location: USA |    |  | 
	
		|  Posted: Mon Jan 28, 2013 4:21 pm |  |  |  |  
		|  |  |  It looks to me like the file should be deleted manually.  It is in a temp folder, in a Pending Delete subfolder, and there is a "delete me" comment in the name.  If you are paranoid, make a backup copy of it and put it somewhere for safekeeping, but I think it is safe to delete.  You can usually delete stuff in a temp folder without any problems.
 Regards,
 | 
	| 
 | 
	| Uriel
 
 
 
			| Joined: 28 Jan 2013 |  | Posts: 0 |  |  |    |  | 
	
		|  Posted: Mon Jan 28, 2013 4:26 pm |  |  |  |  
		|  |  |  I already tried that too, it can't be deleted in Explorer or through a Command Prompt.  I'm going to try a utility called Unlocker to see if I can get whatever is using it to let go so I can manually delete it.  
 I'd still like more info about what this virus is supposed to be though.
 | 
	| 
 | 
	| GuitarBob
 
 
 
			| Joined: 09 Jul 2006 |  | Posts: 9 |  | Location: USA |    |  | 
	
		|  Posted: Mon Jan 28, 2013 4:49 pm |  |  |  |  
		|  |  |  That Clam signature was published Jan 23.  It is a generic patcher.  Here is some detail about it from Virus Total at https://www.virustotal.com/file/14024A6023A60BC7799235E02B2D3BB419423A57CC62F92880826F37DFE6EA38/analysis/ on the web.  
 Unlocker works pretty good.  If no results, you might get into Windows safe mode and see if you can delete the file there.
 
 Regards,
 | 
	| 
 |