Uriel
Joined: 28 Jan 2013 |
Posts: 0 |
|
|
 |
Posted: Mon Jan 28, 2013 4:09 pm |
|
 |
 |
 |
 |
I'm getting a hit for an infected file but ClamWin isn't able to clean or delete the file (even after a reboot), I suspect this is because it's in the WinSxS directory. I've searched for this virus but can't find any information about it anywhere - does anyone know what the name this goes by and/or how to clean it?
Scan result:
C:\Windows\winsxs\Temp\PendingDeletes\$$DeleteMe.authz.dll.01c9f3a32c366170.00d2: Win.Trojan.Agent-121982 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 1670532
Engine version: 0.97.4
Scanned directories: 13416
Scanned files: 49391
Infected files: 1
Not copied: 1
Data scanned: 7675.81 MB
Data read: 9674.71 MB (ratio 0.79:1)
Time: 1510.820 sec (25 m 10 s)
--------------------------------------
Completed
--------------------------------------
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Jan 28, 2013 4:21 pm |
|
 |
 |
 |
 |
It looks to me like the file should be deleted manually. It is in a temp folder, in a Pending Delete subfolder, and there is a "delete me" comment in the name. If you are paranoid, make a backup copy of it and put it somewhere for safekeeping, but I think it is safe to delete. You can usually delete stuff in a temp folder without any problems.
Regards,
|
|
Uriel
Joined: 28 Jan 2013 |
Posts: 0 |
|
|
 |
Posted: Mon Jan 28, 2013 4:26 pm |
|
 |
 |
 |
 |
I already tried that too, it can't be deleted in Explorer or through a Command Prompt. I'm going to try a utility called Unlocker to see if I can get whatever is using it to let go so I can manually delete it.
I'd still like more info about what this virus is supposed to be though.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Jan 28, 2013 4:49 pm |
|
 |
 |
 |
 |
That Clam signature was published Jan 23. It is a generic patcher. Here is some detail about it from Virus Total at https://www.virustotal.com/file/14024A6023A60BC7799235E02B2D3BB419423A57CC62F92880826F37DFE6EA38/analysis/ on the web.
Unlocker works pretty good. If no results, you might get into Windows safe mode and see if you can delete the file there.
Regards,
|
|