 |
 | Urgent help needed |  |
amit
Joined: 20 Jan 2006 |
Posts: 0 |
Location: israel |
|
 |
Posted: Fri Jan 20, 2006 11:07 am |
|
 |
 |
 |
 |
the clam found many infected files almost all exe files
they were all quarantined
the system cannot work
is there any automatic unquarantine solution
before i clean it i need to fix this problem
amit
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Fri Jan 20, 2006 12:44 pm |
|
 |
 |
 |
 |
no, unquarantine is not yet available.
You can parse the log file and create a batch file which will copy quarantined files to the original location.
|
|
 | thanks... |  |
amit
Joined: 20 Jan 2006 |
Posts: 0 |
Location: israel |
|
 |
Posted: Fri Jan 20, 2006 12:53 pm |
|
 |
 |
 |
 |
thanks... however creating a batch file will take longer then manually removing the files from the quarantine directory
it took almost all my EXE files with it... and i suspect its a wrong identification...
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Sat Jan 21, 2006 6:24 am |
|
 |
 |
 |
 |
I meant to parse the log file by use of a scripting language (awk, perl, python, etc)
I don't think that clamwin could mistakenly identify all of your exe's, it would be the first case in history. If there is a false positive clamwin marks one or two files but never all.
|
|
 | never |  |
amit
Joined: 20 Jan 2006 |
Posts: 0 |
Location: israel |
|
 |
Posted: Sat Jan 21, 2006 12:33 pm |
|
 |
 |
 |
 |
never in my life i encountered a worm that effected 300 exe files including system files as well as the clam files themselves
and i stopped just before it reached the system and system 32 directories
so i was wondering if its possible
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Sat Jan 21, 2006 2:07 pm |
|
 |
 |
 |
 |
sounds like a bug in the detection code then. Very unusual.
|
|
amit
Joined: 20 Jan 2006 |
Posts: 0 |
Location: israel |
|
 |
Posted: Sat Jan 21, 2006 2:19 pm |
|
 |
 |
 |
 |
and terribly problematic... this but is far more complicated because while running in the background it quarantine the files however keep then still in their places i.e duplicating them, untill you find yourself with a hard drive space problem. then when you run a scan it will completely remove all the EXEs (almost every one of them !!!) to the quarantine and you are stuck with a system that no exe file is in the place
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Sat Jan 21, 2006 2:22 pm |
|
 |
 |
 |
 |
can you tell me which virus clamwin detected in those files? Also please paste a portion of scan log
|
|
amit
Joined: 20 Jan 2006 |
Posts: 0 |
Location: israel |
|
 |
Posted: Mon Jan 23, 2006 10:24 am |
|
 |
 |
 |
 |
W32 parite.B
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Mon Jan 23, 2006 12:17 pm |
|
 |
 |
 |
 |
then it may NOT be a false positive...
take a look here:
https://www.viruslist.com/en/viruses/encyclopedia?virusid=20924
Quote: |
The virus searches for Win32 EXE PE files with .scr and .exe extensions on all logical drives of computer, and also in shared resources of local network, and infects them.
|
|
|
 |
 | |  |
Grongle
Joined: 31 Jan 2006 |
Posts: 0 |
Location: Vancouver, Canada |
|
 |
Posted: Tue Jan 31, 2006 4:17 pm |
|
 |
 |
 |
 |
I would like to hear more about this. amit, have you found out anything since?
I am looking at the forums to consider whether I should begin using ClamWin. I have been using AntiVir Personal for years, and I really liked it, but it looks like it is going to cost $$$ or else be a poor ghost of what it once was. I can go to AVG, but maybe ClamWin is the thing to try.
If ClamWin breaks complete systems, as this thread suggested at the beginning, no thanks.
If ClamWin has in this example shown its strength, then great. Although, you have to say, that is some virus. If it went through every Windows EXE in every drive, I'm not sure what a person would have left. I guess he could take off his personal data and do a low-level format of the disk and start as from Day One. Pretty rough virus.
I was thinking of doing a night-run on my system with ClamWin, but, um, I WILL still have a working system in the morning, right? According to AntiVir Personal, my system is clean as clean can be.
|
|
 |
 | |  |
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Tue Jan 31, 2006 11:35 pm |
|
 |
 |
 |
 |
Quote: |
I was thinking of doing a night-run on my system with ClamWin, but, um, I WILL still have a working system in the morning, right? According to AntiVir Personal, my system is clean as clean can be. |
you can do that safely with clamwin. By default after installation it is set to report viruses only - no quarantining or interfering with the infected files in any other way.
|
|
 | not sure what to do |  |
murdok
Joined: 02 Feb 2006 |
Posts: 0 |
Location: Colorado |
|
 |
Posted: Thu Feb 02, 2006 10:35 pm |
|
 |
 |
 |
 |
clamwin creates the following report each time it runs:
Infected files: 1
Not moved: 1
Data scanned: 7838.86 MB
Time: 4589.068 sec (76 m 29 s)
--------------------------------------
Scan started: Thu Feb 2 14:00:01 2006
File excluded 'C:\Documents and Settings\All Users\.clamwin\quarantine\Dc45.exe'
ERROR: Can't open file C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
ERROR: Can't open file C:\WINDOWS\system32\config\default
ERROR: Can't open file C:\WINDOWS\system32\config\SAM
ERROR: Can't open file C:\WINDOWS\system32\config\SECURITY
ERROR: Can't open file C:\WINDOWS\system32\config\software
ERROR: Can't open file C:\WINDOWS\system32\config\system
C:\Documents and Settings\All Users\.clamwin\quarantine\Dc45.exe: Adware.NewDotNet.B-4 FOUND
-- summary --
Known viruses: 43959
Engine version: 0.88
Scanned directories: 3109
Scanned files: 46846
Infected files: 1
Not moved: 1
Data scanned: 7882.10 MB
Time: 5014.707 sec (83 m 34 s)
need help on what to do about it
|
|
 |
 | |  |
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Thu Feb 02, 2006 10:38 pm |
|
 |
 |
 |
 |
please start a new thread, your post is unrelated to the discussion above.
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
|  |