Lordninefingers
Joined: 20 Jul 2010 |
Posts: 0 |
Location: Lenoir City |
|
 |
Posted: Tue Jul 20, 2010 7:43 pm |
|
 |
 |
 |
 |
Clamwin always marks/deletes five files from my PowerDVD player software. I am using Windows Vista with PowerDVD 7.3 installed. These files are used for the playback of Blu-Ray Discs and requires me to reinstall the OEM software. This software is NOT pirated nor does any other virus scanner register these files as "infected". Any solutions as to how to keep Clamwin from removing these files everytime I run my virus scanner?
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cl264dec.ax: Trojan.Crypt-280 FOUND
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cl264dec.ax: moved to 'C:\Documents and Settings\All Users.WINDOWS\.clamwin\quarantine\cl264dec.ax.infected'
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldabc.dll: Trojan.Crypt-280 FOUND
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldabc.dll: moved to 'C:\Documents and Settings\All Users.WINDOWS\.clamwin\quarantine\cldabc.dll.infected'
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldabcd.dll: Trojan.Crypt-280 FOUND
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldabcd.dll: moved to 'C:\Documents and Settings\All Users.WINDOWS\.clamwin\quarantine\cldabcd.dll.infected'
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldor2.dll: Trojan.Crypt-280 FOUND
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldor2.dll: moved to 'C:\Documents and Settings\All Users.WINDOWS\.clamwin\quarantine\cldor2.dll.infected'
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldor2d.dll: Trojan.Crypt-280 FOUND
C:\Program Files\CyberLink\PowerDVD\VideoFilter\cldor2d.dll: moved to 'C:\Documents and Settings\All Users.WINDOWS\.clamwin\quarantine\cldor2d.dll.infected'
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Wed Jul 21, 2010 1:51 am |
|
 |
 |
 |
 |
What you have here is a false positive. That is usually the case when you have multiple infections of the same virus/malware. False positives (and undetected viruses) should be reported to Clam AV at their submission site, which is at https://www.clamav.net/lang/en/sendvirus/ on the web. This is the doorway. When you get to the site where you upload the false positive sample (you only need one for multiple false positive detections), be sure to indicate it is a false positive, and provide the exact name of the false positive virus/malware in the comments section. Clam will correct their signature usually within a couple of days. You will be helping all ClamWin users because Clam AV furnishes the scanning and signatures used by ClamWin.
In the meantime, just set your ClamWin infected files detection option under General Preferences to Report Only. I keep mine set to this all the time. and check out all reported infections by uploading them to Jotti or VirusTotal where they can be scanned with multiple AVs.
Regards,
|
|