ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Strange virus alert
xcyanx


Joined: 21 Jan 2009
Posts: 0
Location: Athens
Reply with quote
Hello, after using clamwin i got this report

C:\Windows\Installer\1d7be6.msp: W32.Virut.Gen.D-163 FOUND

C:\Windows\Installer\1d7c08.msp: W32.Virut.Gen.D-163 FOUND

C:\Windows\Installer\1ef309.msp: W32.Virut.Gen.D-163 FOUND

C:\Windows\Installer\2222d5.msp: W32.Virut.Gen.D-163 FOUND

C:\Windows\Installer\80aa6d.msp: W32.Virut.Gen.D-163 FOUND

C:\Windows\Installer\80aa7e.msp: W32.Virut.Gen.D-163 FOUND

C:\Windows\SoftwareDistribution\Download\e17ee63510c0cc0f7e0abe192f3fe49fea1ddea3: Worm.VB-740 FOUND

The strange this is that those files were fine the last time i scanned my pc. So it is a false positive or do i rly have those viruses? thx in advance.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
It looks like to me that they are false positives. When you have several files with the same virus detected, it is often a sign of a false positive. I would send one of those Virut files to Clam AV, starting at https://www.clamav.net/sendvirus/ on the web. When you get to the upload page, be sure to tell them it is a false positive, give the exact name of the falsely detected virus, and tell in the Comments section why you think it is a false positive. Clam will adjust the signature for Clam/ClamWin in a couple of days. The Virut signatures have a lot of false positives, but they can't remove them because they are designed to detect the Virut file infector family, which is a bad group of viruses.

The Worm detection looks to me to be a false detection of a file hash of a Microsoft download of some kind. It looks like the file hash was in the name. Clam has some signatures consisting of file hashes, so that's probably why the false detection. I don't think you can do anything about that--although you could also upload it to Microsoft. If you don't need the file any more, you can just delete it.

Regards,
View user's profileSend private message
xcyanx


Joined: 21 Jan 2009
Posts: 0
Location: Athens
Reply with quote
Ok thanks a lot for your reply... I will do what you have suggested Smile
View user's profileSend private message
Strange virus alert
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic