S. Tang
Joined: 22 Dec 2008 |
Posts: 0 |
Location: Canada |
|
|
Posted: Mon Dec 22, 2008 9:40 pm |
|
|
|
|
|
Is ClamWin itself infected?
It happened to 2 of my USB sticks after they were updated via internet (as per ClamWin) from 2 different XP machines!
Scan Started Mon Dec 22 15:13:34 2008
-------------------------------------------------------------------------------
*** Scanning Programs in Computer Memory ***
*** Memory Scan: using ToolHelp ***
Unloading program E:\PortableApps\ClamWinPortable\ClamWinPortable.exe from memory
*** Scanned 30 processes - 389 modules ***
*** Computer Memory Scan Completed ***
E:\PortableApps\ClamWinPortable\ClamWinPortable.exe: Trojan.Agent-65355 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 478292
Engine version: 0.94.1
Scanned directories: 0
Scanned files: 419
Infected files: 1
Data scanned: 168.95 MB
Time: 155.543 sec (2 m 35 s)
--------------------------------------
Completed
--------------------------------------
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
|
Posted: Mon Dec 22, 2008 11:47 pm |
|
|
|
|
|
It could be that Clamwin didn't have that trojan signature in its database until the latest update. Also, see the previous post on how to verify whether a file is infected and what to do if it is a false positive.
Regards,
|
|
S. Tang
Joined: 22 Dec 2008 |
Posts: 0 |
Location: Canada |
|
|
Posted: Tue Dec 23, 2008 4:19 am |
|
|
|
|
|
Thank you GuitarBob for your prompt & accurate response!
As per your suggestion, I submitted ClamWinPortable.exe to Jotti's & Virus Total; only ClamAV reported positive. It is most likely a false positive. I have also submitted the file and finding to ClamAV.
Best regards!
|
|