ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
clamav kills winME when quaratine and detect broken EXEs
galen


Joined: 13 Jan 2007
Posts: 0
Location: NS, Canada
Reply with quote
do not do this unless you know you can restore your OS.
I set clamav to move detected items to quarantine
and
check for broken EXEs.
ClamAV falsely detected windows' EXE and DLLs and install CABs as being defective,
hence moving them to quarantiine.
If I had rebooted my OS would have been fatally wounded.
I have yet to reboot after this scan and repair from the scanning...
I sent in a report. Confirm if you dare.
View user's profileSend private message
Re: clamav kills winME when quaratine and detect broken EXEs
b0ne


Joined: 26 Oct 2006
Posts: 0
Reply with quote
galen wrote:
I set clamav to move detected items to quarantine and check for broken EXEs.
Umm, not the greatest of ideas. Broken exe's aren't neccesarily malicious. It just means clamav cannot navigate them properly.
View user's profileSend private message
drgoa.r


Joined: 20 Nov 2006
Posts: 0
Location: Bulgaria
Reply with quote
it seems that "--detect-broken" combined with "--remove" (or "--move=" ) is VERY dangerous.
my suggestion is to completely REMOVE this option ("detect broken executables") from the GUI.
leave it, of course, as command line option for users who are awared what it can cause.
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
@drgoa.r

it seams? Very Happy It's very dangerous for sure, I suspect all mingw binaries would be also detected as broken executable (the PE structure it's a bit uncommon)
View user's profileSend private message
drgoa.r


Joined: 20 Nov 2006
Posts: 0
Location: Bulgaria
Reply with quote
Detecting is not dangerous by itself, but combined with "remove" and "move" - here is the problem.
The bad thing is that these options are not on the same screen.
Thus way users can just not be aware how they will reflect on the system.
So, I see two ways to "fix" this:
1. Remove completely "detect broken executables" from the GUI.
or
2. Put it on the General tab in Preferences and if "detect broken executables" is activated - then "report only" to be selected automaticaly.

@sherpya: at my place marked as broken (and MOVED...hehe, how lucky it was not "remove" option enabled...) were all files in windows\system32\drivers folder Smile
View user's profileSend private message
budtse


Joined: 14 Jan 2006
Posts: 0
Location: Belgium
Reply with quote
Hi,

Removing the option from the GUI preferences seams to be a good option. There are a lot of questions about the broken executable detection here, most people do not understand what it is for and think they are safe turning it on.

Unless of course there is a way that we could prevent an executable that has been detected as broken to be quarantined/removed, and just report this in the log in stead.
I believe this imposes some changes to clamscan, so i'm not sure if it can be easily implemented.

A third option (and maybe the easiest) is to show some popup-warning whenever a user checks the option in the preferences, warning him about possible risks and explicitly saying this should not be used in normal scans.
View user's profileSend private message
Broken Executables
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Perhaps you could "qualify" the broken executables and don't worry about them unless they are in certain directories that might indicate they are dangerous.

Regards,
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
I vote for removing it Very Happy it's not good as heuristic detection
View user's profileSend private message
Broken Exe
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Removal is probably best.

Regards,
View user's profileSend private message
clamav kills winME when quaratine and detect broken EXEs
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic