Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kiwi11fortinet
New Contributor

FortiClient-Worm-W32/Brontik.C@mm

Dear all, I would like assistance to delete worm W32/Brontik.C@mm and help to attach or better otherwise submit logs files linked to my post here. After running FortiClient and rebooting, as directed, FortiClient was NOT able " FAILED" to quarantine the worm W32/Brontik.C@mm plus perhaps others said to be running. First manual scan identified one threat (SoftronicDownloader_for_pocket-killbox.exe)and realtime monitoring revealed 57 others after rebooting. W32/Brontik.C@mm successively failed to be Quarantine this worm within ~4seconds of each quarantine action attempt until FortiClient gave up. Also the Fortinet web page ' http://support.fortinet.com/forum/post.asp?do=add&appid=8 ' prevents me from attaching any log files with error message of " C:/fakepath.... not supported " Regards, Robert
2 REPLIES 2
kolawale_FTNT

Try AV scanning in safe mode using FortiClient 5.0.6. If you still have issues with it, contact Technical Support for assistance.
Dave_Hall
Honored Contributor

I would try one of the offline Live CD virus scanners, such as AVG Rescue CD, F-Secure Rescue CD, Kaspersky Rescue Disk, etc.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Labels
Top Kudoed Authors