GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Fri May 08, 2009 8:03 pm |
|
 |
 |
 |
 |
You can set ClamWin's Infected File Preference to Report, Quarantine or Remove. Report is the default preference, and most people should leave it like that. There have been lots of false positives lately. A false positive detection occurs when ClamWin thinks a safe file is infected, due to code that is similar to some virus code in its signature database. If you get a false positive in an important Windows file and ClamWin is set to Remove or Quarantine, you could lose access to your Windows operating system if it was a system file. If there is a false positive on an important program file, you may have to reinstall the program.
I always leave my ClamWin set to Report. When I get a detection of an infected file, I will submit the file to Jotti or VirusTotal where they will be scanned by multiple antivirus products, including Clam (which furnishes the scanning engine and detection signatures for ClamWin). If several other AVs besides Clam spot a file as infected, I assume it is a real infection, and then I can manually remove the file from my computer or temporarily set ClamWin to Remove or Quarantine and run another scan. Then I re-set it back to Report. In the case of a false positive, report it to Clam starting at https://www.clamav.net/sendvirus/ on the web so they can adjust the signature. When you get to the submission form, be sure to indicate it is a false positve, give the exact name that is detected, and tell them why you think it is a false positive detection.
When ClamWin scans, it will do whatever the Infected File Preference tells it--Report, Remove, or Quarantine. If the file is still there with Remove or Quarantine set, that means the file has a "control" process that replaces it that ClamWin is unable to detect. In this case, you might try getting into Windows Safe Mode and then run a scan. If that doesn't work, try a scan with other AV products, including an online scan. I have had good luck at removal with Antimalwarebytes' Antimalware program and with Dr. Web's Cureit program. Go to the ClamWin Antimalware Page for additional help/suggestions.
Regards,
|