ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Worm found in Destop ini file on windows 7
swilson23


Joined: 03 Nov 2009
Posts: 0
Reply with quote
Hello,

I just did a clean install with windows 7 and when I scan my system I get the followin message:

C:\Users\Scott & Lori\Desktop\desktop.ini: Worm.Autorun-2190 FOUND

A friend of mine also just did a windows 7 install and is getting the same message.

Is this a false positive?

Thanks for your help.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
The best way to verify a detection is false is to upload it to Jotti or VirusTotal. If just a few AVs there find an infection, it is probably a false positive, and you should tell Clam about it. I like to see 5 or more AVs to verify an infection.

Regards,
View user's profileSend private message
grantbourque


Joined: 05 Nov 2009
Posts: 0
Reply with quote
https://virusscan.jotti.org/en/scanresult/d833ae59a68d433d5cb6004df20e194f80e2d69f/aeee7a6e1109590dafd9bd9c653d55161f44242e

VirusTotal had the same result.

If it is a false positive, why in the world would it be named Worm.Autorun? Seems kind of odd doesn't it? Do you think it'd be safe to remove?

I've never had a virus before (or a false-positive for that matter) and I practice very conservative computer habits. I almost had a heart attack when ClamWin told me about this.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
A false positive happens because viruses can use some of the same code as a "good" file. A virus is just another program.

Send the false positive to Clam at https://www.clamav.net/sendvirus/ on the web so they can fix the signature. Be sure and check the false positive block when you get to the upload page.

Regards,
View user's profileSend private message
pcbloods


Joined: 11 Nov 2009
Posts: 0
Location: U.K
Reply with quote
Hi exactly the same happened to me just recently. AVG finds nothing wrong and I have just had the message on a fresh Win 7 install.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
The only way to fix a false positive in ClamWin is to verify it is false with one or more other antivirus programs and then send a copy of the false positive file to Clam starting at https://www.clamav.net/sendvirus/ on the web. Be sure to indicate it is a false positive and tell the name of the false virus. They will check it out and adjust the signature for Clam and ClamWin.

Regards,
View user's profileSend private message
Mikef12


Joined: 14 Nov 2009
Posts: 0
Location: Philly
Reply with quote
GuitarBob wrote:
The only way to fix a false positive in ClamWin is to verify it is false with one or more other antivirus programs and then send a copy of the false positive file to Clam starting at https://www.clamav.net/sendvirus/ on the web. Be sure to indicate it is a false positive and tell the name of the false virus. They will check it out and adjust the signature for Clam and ClamWin.

Regards,


Another way, particularly if it's a text file like desktop.ini, is to look at it in notepad.

I just had the same thing happen in Vista Ult. It was a false positive.

Cheers,

Mike
View user's profileSend private message
Worm found in Destop ini file on windows 7
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic