ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Virus that uses rootkit
last_desp


Joined: 18 Dec 2006
Posts: 0
Reply with quote
I'm new to clamwin antivirus. I have this removable storage that was infected. The infected file was hidden and can only be seen when I unchecked "Hide protected operating system files" in folder option. I tried to full scan the storage but it did not detect any viruses but when I scanned with other antivirus it detected something.

Can clamwin detect viruses that uses rootkit?
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
it would help if you were a bit more specific than "detected something". You can always scan a file online at https://www.virustotal.com and see what different AV vendors detect
View user's profileSend private message
ClamWin Versus Rootkits
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
As Alch said, you need to be more specific. There are several rootkit viruses around, and some antivirus programs are not set up to detect them or will only detect a few. ClamWin uses the Clam signature database. A search of the ativirus signature database at the ClamAV web site using the term "rootkit" turned up one name: Trojan.Rootkit-6. This is Clam's name for it--other antivirus software will have their own name for it. There are some free rootkit removal tools available on the Web--especially for the Sony Rootkit.

Regards,
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
use this tool https://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx https://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx

and look for files hidden to the api
please note you can get false positives if you are doing something in background
so temp file and internet cache can be ignored
you need to focus on .sys or .dll that are hidden to api
often you have a .sys driver that starts and hides the malware executable.
I was happy to notice that clamwin can detect some of rookit hidden files
because of using unc paths Smile
View user's profileSend private message
Virus that uses rootkit
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic