Eric VERNIER
Joined: 17 Jun 2006 |
Posts: 0 |
|
|
 |
Posted: Sat Aug 11, 2007 8:14 am |
|
 |
 |
 |
 |
Hello,
Clamwin has found a virus with the name E.mail/E-card-6, but clamwin does not remove it or put it in the quarantine folder.
Could you telle me how I can remone manually this virus
Thank you wery much
Eric VERNIER
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sat Aug 11, 2007 1:58 pm |
|
 |
 |
 |
 |
ClamWin has to be configured to put malware in its quarantine folder. In in the General Configuration tab in the Configuration menu you can select to Report Only, Remove or Quarantine. I believe Report Only is the default, but the ClamWin Virus Scan Report will tell you where the malware is located on your hard drive, and you can then navigate there in Windows Explorer and remove it manually by right click/delete. ClamWin doesn't automatically remove something in quarantine either. Once you you configure to quarantine malware, the File Locations tab will tell you the location of the quarantine folder, and you will have to manually remove it from there--a good idea because ClamWin will scan the quarantine folder in a total hard drive scan and find malware there again.
You should probably upload a copy of the malware to VirusTotal.Com for a free check against several antivirus programs to make sure it is not a false positive (they happen sometimes). If a couple of other AVs spot malware, you can be sure it's not a false positive. If Clam is the only AV to find malware, it's probably a false positive and you need to go to the Clam virus submission page on the Web at https://cgi.clamav.net/sendvirus.cgi to upload a copy of it and tell them about it.
Regards,
|
|
Christoph
Joined: 11 Jul 2007 |
Posts: 0 |
|
|
 |
Posted: Sat Aug 11, 2007 3:37 pm |
|
 |
 |
 |
 |
Eric VERNIER wrote: |
Hello,
Clamwin has found a virus with the name E.mail/E-card-6, but clamwin does not remove it or put it in the quarantine folder.
Could you telle me how I can remone manually this virus
Thank you wery much
Eric VERNIER |
Could you report the full detection report - including the path and the file it was found in?
|
|
Eric VERNIER
Joined: 17 Jun 2006 |
Posts: 0 |
|
|
 |
Posted: Sun Aug 12, 2007 7:35 pm |
|
 |
 |
 |
 |
OK for the report. Here te clamwin report :
C:\Documents and Settings\Eric\Application Data\Thunderbird\Profiles\wtd271cu.default\Mail\pop.wanadoo-1.fr\Inbox: Email.Phishing.RB-1035 FOUND
C:\Documents and Settings\Eric\Application Data\Thunderbird\Profiles\wtd271cu.default\Mail\pop.wanadoo-1.fr\Inbox: Not deleting/moving mailbox
C:\Documents and Settings\Eric\Application Data\Thunderbird\Profiles\wtd271cu.default\Mail\pop.wanadoo-1.fr\Junk: Email.Phishing.RB-1035 FOUND
C:\Documents and Settings\Eric\Application Data\Thunderbird\Profiles\wtd271cu.default\Mail\pop.wanadoo-1.fr\Junk: Not deleting/moving mailbox
Usually clamwin put viruses into quarantine forder or delter it lite the configuration, but in this case it can detete or move this virus?
Please, could you help me ?
Tank you very much.
Eric VERNIER
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sun Aug 12, 2007 8:45 pm |
|
 |
 |
 |
 |
I believe this thread will help: https://forums.clamwin.com/viewtopic.php?t=1076
Regards,
|
|