ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Need help identifying virus
Uriel


Joined: 28 Jan 2013
Posts: 0
Reply with quote
I'm getting a hit for an infected file but ClamWin isn't able to clean or delete the file (even after a reboot), I suspect this is because it's in the WinSxS directory. I've searched for this virus but can't find any information about it anywhere - does anyone know what the name this goes by and/or how to clean it?

Scan result:

C:\Windows\winsxs\Temp\PendingDeletes\$$DeleteMe.authz.dll.01c9f3a32c366170.00d2: Win.Trojan.Agent-121982 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 1670532
Engine version: 0.97.4
Scanned directories: 13416
Scanned files: 49391
Infected files: 1

Not copied: 1
Data scanned: 7675.81 MB
Data read: 9674.71 MB (ratio 0.79:1)
Time: 1510.820 sec (25 m 10 s)

--------------------------------------
Completed
--------------------------------------
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
It looks to me like the file should be deleted manually. It is in a temp folder, in a Pending Delete subfolder, and there is a "delete me" comment in the name. If you are paranoid, make a backup copy of it and put it somewhere for safekeeping, but I think it is safe to delete. You can usually delete stuff in a temp folder without any problems.

Regards,
View user's profileSend private message
Uriel


Joined: 28 Jan 2013
Posts: 0
Reply with quote
I already tried that too, it can't be deleted in Explorer or through a Command Prompt. I'm going to try a utility called Unlocker to see if I can get whatever is using it to let go so I can manually delete it.

I'd still like more info about what this virus is supposed to be though.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
That Clam signature was published Jan 23. It is a generic patcher. Here is some detail about it from Virus Total at https://www.virustotal.com/file/14024A6023A60BC7799235E02B2D3BB419423A57CC62F92880826F37DFE6EA38/analysis/ on the web.

Unlocker works pretty good. If no results, you might get into Windows safe mode and see if you can delete the file there.

Regards,
View user's profileSend private message
Need help identifying virus
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic