xcyanx
Joined: 21 Jan 2009 |
Posts: 0 |
Location: Athens |
|
 |
Posted: Tue Jul 07, 2009 11:42 pm |
|
 |
 |
 |
 |
Hello, after using clamwin i got this report
C:\Windows\Installer\1d7be6.msp: W32.Virut.Gen.D-163 FOUND
C:\Windows\Installer\1d7c08.msp: W32.Virut.Gen.D-163 FOUND
C:\Windows\Installer\1ef309.msp: W32.Virut.Gen.D-163 FOUND
C:\Windows\Installer\2222d5.msp: W32.Virut.Gen.D-163 FOUND
C:\Windows\Installer\80aa6d.msp: W32.Virut.Gen.D-163 FOUND
C:\Windows\Installer\80aa7e.msp: W32.Virut.Gen.D-163 FOUND
C:\Windows\SoftwareDistribution\Download\e17ee63510c0cc0f7e0abe192f3fe49fea1ddea3: Worm.VB-740 FOUND
The strange this is that those files were fine the last time i scanned my pc. So it is a false positive or do i rly have those viruses? thx in advance.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Wed Jul 08, 2009 1:23 am |
|
 |
 |
 |
 |
It looks like to me that they are false positives. When you have several files with the same virus detected, it is often a sign of a false positive. I would send one of those Virut files to Clam AV, starting at https://www.clamav.net/sendvirus/ on the web. When you get to the upload page, be sure to tell them it is a false positive, give the exact name of the falsely detected virus, and tell in the Comments section why you think it is a false positive. Clam will adjust the signature for Clam/ClamWin in a couple of days. The Virut signatures have a lot of false positives, but they can't remove them because they are designed to detect the Virut file infector family, which is a bad group of viruses.
The Worm detection looks to me to be a false detection of a file hash of a Microsoft download of some kind. It looks like the file hash was in the name. Clam has some signatures consisting of file hashes, so that's probably why the false detection. I don't think you can do anything about that--although you could also upload it to Microsoft. If you don't need the file any more, you can just delete it.
Regards,
|
|