We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Trojan removal

Hi All,
I have just completed a virus scan using Mcafee. It flagged up 11 files with the prockill.df trojan. According to the scanner it could not clean, delete or quarantine two of the files.

I want to be able to post exact details here but I cannot find the virus scan log within Securty Centre. Any ideas where it is?

What are my next steps...do I run Mcafee again in safe mode?
What I do find concerning is that some files I thought would be safe came up as infected (One was CCleaner set up)

Thanks

SB

Comments

  • Fran
    Fran Posts: 11,280 Forumite
    Part of the Furniture 10,000 Posts Photogenic Combo Breaker
    If you do a google search with the exact terms you'll find out more about the trojans. Antivirus removal software is not so good at removing trojans, you should try running Ewido in safe mode (and any other software you have). You might need to turn off system restore to remove any files that are still there (but check on websites when you do google search to see how to remove, there may be a removal tool).
    Torgwen.......... :) ...........
  • shopbot
    shopbot Posts: 1,022 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    Hi Fran,
    I tried Google without success. Mcafees own website shows that the virus was discovered today and was put into their updates today. It sounds like it has only just surfaced.

    Thanks

    SB
  • shopbot
    shopbot Posts: 1,022 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    On the McAfee website it says:
    Prockill-DF There have been reports of an incorrect identification in the 4629 DAT files of certain installer packages. This will be corrected in the 4630 DATs

    Does that mean that this is highlighting some items as Trojans that are not in fact threats?
    Does that mean my PC is not infected?
  • Fran
    Fran Posts: 11,280 Forumite
    Part of the Furniture 10,000 Posts Photogenic Combo Breaker
    That's how I would interpret it too, but there's no harm in running Ewido anyway as it's good. Perhaps then check back later/tomorrow to see if anything more comes up.
    Torgwen.......... :) ...........
  • shopbot
    shopbot Posts: 1,022 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    Thanks Fran,
    I'm downloading Ewido now and will run overnight.

    SB
  • shopbot
    shopbot Posts: 1,022 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    I ran Ewido overnight. V impressed as it picked up two bits of spyware that MSantispyware/adadware/spybot had missed! It did not pick up the Trojans that McAfee did. I then ran McAcfee (with system restore off and in safe mode) again and it picked up Ewido-setup.exe as a Trojan. This morning there was a another McAfee update available so my guess is that the previous update was corrupted and giving 'false positives'.
    I'll scan again tonight after work and see what hapens!
  • Rather unnervingly, a very similar thing happened with AVG just the other day...
  • shopbot
    shopbot Posts: 1,022 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    All sorted now! I think it was a corrupted definitions file. Might try AVG when my McAfee subscription runs out....
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.