ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Question...I'm new
chaos31


Joined: 20 Dec 2006
Posts: 0
Location: Minnesota, USA
Reply with quote
Well a family friend told me about Clamwin and how good it is so I downloaded it and tried it out, seems to work great but had few quests, listed below.

1 - So I ran a scan and when it finished i had 10 infected files...gah. Well does it get rid of them or how do I get rid of these infected files...?
2 - Do I set it to Report only or Remove or Quarentine...or what's a recommendation.

Thanks very much!
David
View user's profileSend private message
budtse


Joined: 14 Jan 2006
Posts: 0
Location: Belgium
Reply with quote
We mostly advise to set to Quarantine. This also answers your first question: infected files are moved to the quarantine folder, where you can delete them if everything is ok or restore them from if they appear to be false positives.
View user's profileSend private message
chaos31


Joined: 20 Dec 2006
Posts: 0
Location: Minnesota, USA
Reply with quote
Wait...so when they get quarintined what do you mean restore them from if they appear to be false positives?
View user's profileSend private message
budtse


Joined: 14 Jan 2006
Posts: 0
Location: Belgium
Reply with quote
Well, these are exceptions, but sometimes a file that is indicated as infected is not (this is called a false positive). The log file will tell you which files are moved to quarantine (from folder x to quarantine folder y). In the case of a false positive, you can manually move the file back using windows explorer.

As i said, these are exceptions, so normally you shouldn't worry about it. It is just the main difference between "Quarantine" and "Remove". Remove does not give you the possibility to restore the file if needed.
View user's profileSend private message
What About False Positives
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You can upload a quarantined item to https://www.virustotal.com/en/virustotalf.html on the Web to see if other antivirus scanners recognize it as a virus. The service is free, usually fast (depending upon work load), and they check the file with 10 or more antivirus programs.

If a couple of the other scanners also recognize it as a virus, it probably is one, so just delete it from the quarantine file on your hard drive.

Regards,
View user's profileSend private message
chaos31


Joined: 20 Dec 2006
Posts: 0
Location: Minnesota, USA
Reply with quote
ok, and to remove infected ifle in quarentine folder do i just right clikc --> delete --> delete forever?
View user's profileSend private message
Delete From Quarantine
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Yes, right click/delete will work. Be certain that it is a virus/malware before you Delete will put the virus in your Recycle Bin, so you will have to also delete it from there at some point (right click on the file in the Recycle Bin folder or use Windows Disk Cleanup to clean up lots of stuff).

Regards,
View user's profileSend private message
chaos31


Joined: 20 Dec 2006
Posts: 0
Location: Minnesota, USA
Reply with quote
Semi problem...well I ran a scan first thing I got it (last night at 9:00 PM and finished at 10:00 AM) so took a bit but anyways I never had it save to a quarentine folder...there was 10 infected files...so do I have to rescan lol?
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
just check the infected file locations from the scan report and if you are in doubt scan them on https://www.virustotal.com. Then delete the infected files from their original locations.
View user's profileSend private message
chaos31


Joined: 20 Dec 2006
Posts: 0
Location: Minnesota, USA
Reply with quote
Also, when they get moved to quarentine folder, if it turns out safe what do i do with it? Put it back where it belongs......?

also out of the 10 infected files only 2 came up infected, so that site did help so thanks!
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
yes, you should copy them back if these are important files (not your browser cache for instance)

can you paste the false positive reports here?
View user's profileSend private message
chaos31


Joined: 20 Dec 2006
Posts: 0
Location: Minnesota, USA
Reply with quote
Sure, false positive = the safe one's? If so they are below.

This was the whole list.
-----------------------------------
C:\Documents and Settings\Daniel\Local Settings\Application Data\Mozilla\Firefox\Profiles\ebcsvb87.default\Cache\0AFB9CCFd01: HTML.Phishing.Gold FOUND
C:\Documents and Settings\David\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-5e55057-7f63cd29.zip: Java.ClassLoader.24564 FOUND
C:\Documents and Settings\David\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv771.jar-7730088f-41bcf564.zip: Java.ClassLoader.24564 FOUND
C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\t9nbe6nj.default\Cache\0AFB9CCFd01: HTML.Phishing.Gold FOUND
C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\t9nbe6nj.default\Cache\7325728Ad01: HTML.Phishing.Bank-983 FOUND
C:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\t9nbe6nj.default\Cache\7354741Bd01: HTML.Phishing.Bank-983 FOUND
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\5SLLPPK5\popup[2].htm: Trojan.Clicker.HTML.Agent FOUND
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\F0MDSTEY\popup[1].htm: Trojan.Clicker.HTML.Agent FOUND
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\F0MDSTEY\popup[2].htm: Trojan.Clicker.HTML.Agent FOUND
C:\WINDOWS\SYSTEM32\SVKP.sys: Trojan.PcClient-42 FOUND

I'll try remember which one's were safe/unsafe that I found out...lemme see if i can find out.
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
The only one of concern is this:
C:\WINDOWS\SYSTEM32\SVKP.sys

Please scan it on https://virustotal.com
View user's profileSend private message
chaos31


Joined: 20 Dec 2006
Posts: 0
Location: Minnesota, USA
Reply with quote
ok thanks.
View user's profileSend private message
Question...I'm new
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic