ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Quarantine
jermbassplayer


Joined: 04 Mar 2008
Posts: 0
Reply with quote
Can i move files out of the Quarantine to test to see if they were false postives
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
no need just scan them in the quarantine directory
View user's profileSend private message
jermbassplayer


Joined: 04 Mar 2008
Posts: 0
Reply with quote
so if i use https://www.virustotal.com/ it will tell me if those are false postives?
View user's profileSend private message
budtse


Joined: 14 Jan 2006
Posts: 0
Location: Belgium
Reply with quote
that's right. VirusTotal will scan the file with a dozen or so virus scan engines, so you can compare the different results. If Clam is the only engine reporting the file as infected, it most likely is a false positive.
View user's profileSend private message
jermbassplayer


Joined: 04 Mar 2008
Posts: 0
Reply with quote
what does it mean if clam does not report it as a virus even though the local one did?
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
If the VirusTotal scan and the ClamWin scans differ, it means that you probably need to update your local Clamwin signatures--OR you need to configure Clamwin's Advanced Preferences to allow detection of PUA signatures (PUAs are potentially unwanted applications). VirusTotal automaticlaly uses the PUA signatures, but you will have to configure ClamWin to use them.

Regards,
View user's profileSend private message
jermbassplayer


Joined: 04 Mar 2008
Posts: 0
Reply with quote
Thanks all for your response
I will clarify what has happened
I have computer the clamwin had said it found a virus on clamwin moved those to the virus vault then I ran avg and it found nothing
then I run clam win on the virus vault it finds nothing then I take those and run them on virustotal and find nothing.
I guess my question is are these false postive or does clamwin do something to the files that make them look clean.
I thought that clam win did not do that
thanks
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
ClamWin doesn't do anything to infected files that it puts in quarantine except to put "infected" in front of the filename and add a ".000" extension to the end of the existing filename. If it finds a similar file again on your computer with the same name, when it quarantines it, it overwrites the existing filename in quarantine and changes the the extension to .001, then to .002, etc. It will include the quarantine folder in its scans if you select the folder or do a scan of your entire hard drive.

So, if you scanned the quarantined file(s) on VirusTotal (VT) and no scanner found anything, then it was a false positive. It's strange that ClamWin didn't spot the files as infected once in quarantine. However, if some time (a few hours at least) had elapsed between your original scan and your quarantine folder scan, the Clam signatures could have been updated since your original scan. If the files are not important to you, leave them in quarantine and check them again on VT a day or two later in case the file contains(ed) really new malware that isn't yet in anybody's signatures. If no scanner still doesn't find anything, restore the file(s) and give Clam a copy at https://cgi.clamav.net/sendvirus.cgi on the Web and tell them it's a false positive.

Regards,
View user's profileSend private message
Quarantine
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic