Deleting trojan files.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Voom, Apr 21, 2012.

  1. Voom

    Voom Private E-2

    clamav found 4 files that were trojans with an offline scan (clamscan) on windows 7 x64. Is it ok to simply delete these files or will it break the system?

    /mnt/local/Windows/SysWOW64/DevicePairingWizard.exe: Trojan.TDSS-8065 FOUND
    /mnt/local/Windows/SysWOW64/LocationNotifications.exe: Trojan.TDSS-8047 FOUND
    /mnt/local/Windows/winsxs/x86_microsoft-windows-devicepairingapp_31bf3856ad364e35_6.1.7600.16385_none_6f74b7d163601da2/DevicePairingWizard.exe: Trojan.TDSS-8065 FOUND
    /mnt/local/Windows/winsxs/x86_microsoft-windows-m..cationnotifications_31bf3856ad364e35_6.1.7600.16385_none_175ab6276b721d6a/LocationNotifications.exe: Trojan.TDSS-8047 FOUND
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Those are likely just programs for your BlueTooth device.

    I suggest that you run the below procedure and also you may want to look into using a better antivirus program than Clam AV.



    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
    Last edited: Apr 21, 2012
  3. Voom

    Voom Private E-2

    Here are the logs. SPTD I assume is for daemon tools and is correct to be locked. I don't know what SwitchBoard is. I'm going to try an avast boot time scan.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes SPTD is from Daemon Tools and SwitchBoard is just part of Adobe.

    It seems you are just having false detection issues from Clam; however if you are really concerned that you have malware or if you are actually having problems, you can run the below cleaning procedure:

    READ & RUN ME FIRST. Malware Removal Guide
     
  5. Voom

    Voom Private E-2

    It's either all the anti virus programs except for clamav screwed up, or clamav did. Either way there probably won't be conclusive answers but I guess I have to go with the majority. Though I've been using clamav for years and never got a false positive, so that's why I'd be at all doubtful. I'll just leave it for now. I'll scan it again at a later date, in case it's a correction to the clamav definitions.

    Thank you for the replies.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not that good a program and it is only an after the fact scanner. It provides no protection and as such, it is not recommended.
     
  7. Voom

    Voom Private E-2

    Just in closing, it was a false positive since I updated clamav and those files aren't marked as trojans anymore.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know, that is what I said earlier. ;) But thanks for acknowledging that an with an update, they are no longer detected.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds