jermbassplayer
Joined: 04 Mar 2008 |
Posts: 0 |
|
|
 |
Posted: Tue Mar 04, 2008 6:53 pm |
|
 |
 |
 |
 |
Can i move files out of the Quarantine to test to see if they were false postives
|
|
sherpya
Joined: 22 Mar 2006 |
Posts: 0 |
Location: Italy |
|
 |
Posted: Tue Mar 04, 2008 7:53 pm |
|
 |
 |
 |
 |
no need just scan them in the quarantine directory
|
|
jermbassplayer
Joined: 04 Mar 2008 |
Posts: 0 |
|
|
 |
Posted: Tue Mar 04, 2008 8:18 pm |
|
 |
 |
 |
 |
so if i use https://www.virustotal.com/ it will tell me if those are false postives?
|
|
budtse
Joined: 14 Jan 2006 |
Posts: 0 |
Location: Belgium |
|
 |
Posted: Tue Mar 04, 2008 8:37 pm |
|
 |
 |
 |
 |
that's right. VirusTotal will scan the file with a dozen or so virus scan engines, so you can compare the different results. If Clam is the only engine reporting the file as infected, it most likely is a false positive.
|
|
jermbassplayer
Joined: 04 Mar 2008 |
Posts: 0 |
|
|
 |
Posted: Tue Mar 04, 2008 8:45 pm |
|
 |
 |
 |
 |
what does it mean if clam does not report it as a virus even though the local one did?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Wed Mar 05, 2008 1:36 pm |
|
 |
 |
 |
 |
If the VirusTotal scan and the ClamWin scans differ, it means that you probably need to update your local Clamwin signatures--OR you need to configure Clamwin's Advanced Preferences to allow detection of PUA signatures (PUAs are potentially unwanted applications). VirusTotal automaticlaly uses the PUA signatures, but you will have to configure ClamWin to use them.
Regards,
|
|
jermbassplayer
Joined: 04 Mar 2008 |
Posts: 0 |
|
|
 |
Posted: Wed Mar 05, 2008 4:50 pm |
|
 |
 |
 |
 |
Thanks all for your response
I will clarify what has happened
I have computer the clamwin had said it found a virus on clamwin moved those to the virus vault then I ran avg and it found nothing
then I run clam win on the virus vault it finds nothing then I take those and run them on virustotal and find nothing.
I guess my question is are these false postive or does clamwin do something to the files that make them look clean.
I thought that clam win did not do that
thanks
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Wed Mar 05, 2008 9:52 pm |
|
 |
 |
 |
 |
ClamWin doesn't do anything to infected files that it puts in quarantine except to put "infected" in front of the filename and add a ".000" extension to the end of the existing filename. If it finds a similar file again on your computer with the same name, when it quarantines it, it overwrites the existing filename in quarantine and changes the the extension to .001, then to .002, etc. It will include the quarantine folder in its scans if you select the folder or do a scan of your entire hard drive.
So, if you scanned the quarantined file(s) on VirusTotal (VT) and no scanner found anything, then it was a false positive. It's strange that ClamWin didn't spot the files as infected once in quarantine. However, if some time (a few hours at least) had elapsed between your original scan and your quarantine folder scan, the Clam signatures could have been updated since your original scan. If the files are not important to you, leave them in quarantine and check them again on VT a day or two later in case the file contains(ed) really new malware that isn't yet in anybody's signatures. If no scanner still doesn't find anything, restore the file(s) and give Clam a copy at https://cgi.clamav.net/sendvirus.cgi on the Web and tell them it's a false positive.
Regards,
|
|