 | Need help identifying virus |  |
Uriel
Joined: 28 Jan 2013 |
Posts: 0 |
|
|
 |
Posted: Mon Jan 28, 2013 4:09 pm |
|
 |
 |
 |
 |
I'm getting a hit for an infected file but ClamWin isn't able to clean or delete the file (even after a reboot), I suspect this is because it's in the WinSxS directory. I've searched for this virus but can't find any information about it anywhere - does anyone know what the name this goes by and/or how to clean it?
Scan result:
C:\Windows\winsxs\Temp\PendingDeletes\$$DeleteMe.authz.dll.01c9f3a32c366170.00d2: Win.Trojan.Agent-121982 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 1670532
Engine version: 0.97.4
Scanned directories: 13416
Scanned files: 49391
Infected files: 1
Not copied: 1
Data scanned: 7675.81 MB
Data read: 9674.71 MB (ratio 0.79:1)
Time: 1510.820 sec (25 m 10 s)
--------------------------------------
Completed
--------------------------------------
|
|
 |
 | |  |
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Jan 28, 2013 4:21 pm |
|
 |
 |
 |
 |
It looks to me like the file should be deleted manually. It is in a temp folder, in a Pending Delete subfolder, and there is a "delete me" comment in the name. If you are paranoid, make a backup copy of it and put it somewhere for safekeeping, but I think it is safe to delete. You can usually delete stuff in a temp folder without any problems.
Regards,
|
|
Uriel
Joined: 28 Jan 2013 |
Posts: 0 |
|
|
 |
Posted: Mon Jan 28, 2013 4:26 pm |
|
 |
 |
 |
 |
I already tried that too, it can't be deleted in Explorer or through a Command Prompt. I'm going to try a utility called Unlocker to see if I can get whatever is using it to let go so I can manually delete it.
I'd still like more info about what this virus is supposed to be though.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Jan 28, 2013 4:49 pm |
|
 |
 |
 |
 |
That Clam signature was published Jan 23. It is a generic patcher. Here is some detail about it from Virus Total at https://www.virustotal.com/file/14024A6023A60BC7799235E02B2D3BB419423A57CC62F92880826F37DFE6EA38/analysis/ on the web.
Unlocker works pretty good. If no results, you might get into Windows safe mode and see if you can delete the file there.
Regards,
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by
phpBB © phpBB Group
Design by
phpBBStyles.com |
Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.