lledorc
Joined: 24 Jul 2007 |
Posts: 0 |
|
|
 |
Posted: Tue Jul 24, 2007 3:41 am |
|
 |
 |
 |
 |
I recently heard that Clamav and Clamwin were adding numerous spyware definitions to its great database. How does ClamWin remove any found spyware since these types of code often cause changes in registry keys, core system files (via dll injection), random file generators, services, ect...
Does ClamWin have the removal capability to handle these complex infections or does it still just try and delete/quarantine the main file found?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Jul 24, 2007 1:51 pm |
|
 |
 |
 |
 |
ClamAV and ClamWin don't perform any disinfection. Disinfection requires quite a bit of programming, and a lot of the current malware contains multiple payloads and is hard to completely remove/disinfect. At the current time, all you can do in ClamWin is quarantine malware and delete it or remove it where it is found if you configure it just notify you when it finds an infection. Those options should be sufficient if the malware hasn't yet run on your system. Until a ClamWin resident version is released, you should also use a resident scanner in case malware "kicks in" before you can do a ClamWin scan.
The ClamAV developer has announced his intention to give Clam the ability to disinfect Ole files at some point, but he said that is all the disinfection they intend to do.
Regards,
|
|