![]() |
| Baffled: ClamXAV found Trojan that ClamWin did not |
| Re: Baffled: ClamXAV found Trojan that ClamWin did not |
|
b0ne
|
Trojan.Bat.FormatC-6 is an extremely "loose" signature. I believe it would be heavily prone to false positives. The signature basically checks every file for the following two strings: "ctty nul" "format c: /autotest /q /u" A virtual PC disk image contains many things other than files, including swap files, caches, other sorts of miscellaneous memory that may not neccesarily be present on the "c:" drive inside of the virtual machine. You're actually going to be less effective scanning a virtual pc disk image in this way because most of the signatures expect to be scanning files that are executable in nature, and have signatures at exact locations in the files. VPC disk images are not executables they're giant images. All of those offsets and file type checks inside of the definitions get tossed out the window when you scan in this fashion. |
||||||||||||||
|
|
|||||||||||||||
|
JayCee
|
Well, this is a big relief. I thank you.
Normally I don't check my XP disk images with ClamXAV. I omitted a few details in my posting, hoping to keep things brief, but perhaps I shouldn't have. This all began with my wanting to save a base XP disk image to a DVD over the weekend. Unfortunately, I found all of my backup copies were already too big. In order to make one of them fit, I found I needed to "zero out" the available space in XP, and then have Virtual PC "reclaim" that space in the XP disk image. At that point, I dragged the smallest (and oldest) backup XP disk image from my backup drive onto my Mac desktop. Since I have ClamXAV watching my Mac desktop (among other places), that immediately resulted in ClamXAV scanning the XP disk image backup -- and thats when the Trojan.Bat.FormatC-6 turned up. So, not only did I need to shrink the XP disk image before burning it to a DVD, but now I apparently had to rid it of this Trojan.Bat.FormatC-6, as well. Just for the record, I had installed ClamWin on my XP about a year ago (in place of AOL's Security Edition, which I thought was bogging XP down), but it was not on the oldest XP disk image backup I was going to try to shrink, which is why I had to install it over the weekend, in order to have it try to hunt down this Trojan.Bat.FormatC-6. Well, at least now I know it's safe to save the XP disk image to a DVD finally. Plus, now I know my XP is in fact, clean. But, just in case I forget all this, I'll be sure to save a copy of your explanation on the DVD to remind me. javascript:emoticon(' Thanks again. JC |
||||||||||||
|
|
|||||||||||||
| Baffled: ClamXAV found Trojan that ClamWin did not |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


