ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
clamwin not removing virus
pretty useless


Joined: 12 Jan 2009
Posts: 0
Reply with quote
Forgive me, but I am a complete noodle with computers. I have run a clamwin scan and it has found infected file C:\DRIVERS\POSTOOBE\NEC:VBS:Generic. It has not been able to quarantine the file.
Could someone please advise me (preferably in words of one syllable!), what to do next? Thanks folks.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
ClamWin will Report Only, Remove (be careful) or Quarantine malware it finds--depending upon what is set up in the Infected File option selected in its General Preferences. The default is Report Only, so that's all it does if you haven't changed. If ClamWin finds a virus in a file and you are sure it is a REAL infection, change the option to Remove or Quarantine, and do another scan. It will be removed/quarantined then.

I keep it set at Report Only because if you use the other two options, you may lose access to your system if there is a false positive in an important Windws system file if ClamWin Removes it or Quarantines it. The ClamWin scan report will tell you where the file is located on your system. Be careful with files in any Windows directory. What I do when it finds an infection is upload a copy of the "infected" file to Jotti at https://virusscan.jotti.org/ or to VirusTotal at https://www.virustotal.com/ on the web. Either service will scan it for you for free with multiple antivirus programs, including Clam. If several other AVs besides Clam find an infection, it is probably a real infection. If only Clam and a couple of other AVs find something, it is probably a false positive. You can tell Clam about false positives(FP) and upload the FP file at https://www.clamav.net/sendvirus/ on the web, and they will change the signature.

Regards,
View user's profileSend private message
pretty useless


Joined: 12 Jan 2009
Posts: 0
Reply with quote
Thanks GuitarBob, only one other scan came up with a problem, so I will report to clamav, as suggested.
Out of interest, what would happen if it was real?
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
If it was a real infected file, you would probably see five or more antivirus programs on Jotti/VirusTotal that detect it. Some AVs have their heuristic detection set pretty high and detect lots of stuff (not Clam though--it's low on heuristics), but I think that it's hard to fool five of them--it happens sometimes though because several of them share databases.

If the file had been really infected, you could either remove it manually or temporarily set ClamWin to either remove/quarantine and run a scan. Watch for infections in any Windows directory/subdirectory though--verify them really good before you remove/quarantine them. Files in other directories aren't so critical. Keep data backup for all your programs that produce data.

Regards,
View user's profileSend private message
clamwin not removing virus
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic