 |
 | windows 2003 server |  |
bthomson
Joined: 26 Jul 2011 |
Posts: 0 |
|
|
 |
Posted: Tue Jul 26, 2011 12:20 am |
|
 |
 |
 |
 |
When I run ClamWin I get probably 50 warnings saying that a particular file was not accessable.
This renders the scan useless. What to do?
Bruce
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Jul 26, 2011 12:40 am |
|
 |
 |
 |
 |
It is normal for some files to be not accessable to ClamWin. If it happens all the time, and you are sure the file is not infected, exclude it from ClamWin scans via the Configure, Filters, Exclude Matching Filenames option.
Regards,
|
|
bthomson
Joined: 26 Jul 2011 |
Posts: 0 |
|
|
 |
Posted: Tue Jul 26, 2011 12:53 am |
|
 |
 |
 |
 |
how can I be sure the files have not been infected by a hacker?
|
|
 |
 | |  |
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Jul 26, 2011 2:48 am |
|
 |
 |
 |
 |
Most permission denied files are okay/not infected. That is certainly a pretty big flag, and viruses don't like to be flagged! They would more than likely hide the file via rootkit or by classifying the file as a hidden protected system file.
You can always upload a file to Jotti at https://virusscan.jotti.org/en or to Virus Total at https://www.virustotal.com/ on the web. Either service will scan your files (one at a time) with multiple AV programs, including Clam AV, which furnishes the scan engine and signature database used by ClamWin. If several AVs say it is infected, it probably is. If more than 10 of AVs see an infection, there is a good chance (not a certailnty though) of an infection. I have 5 "trigger" AVs which I use as an indicatior: AntiVir, Bitdefender, Kaspersky, NOD32, and Sophos. If 2 of these AVs say something is infected, I will believe it (in most cases).
Regards,
|
|
 |
 | |  |
bthomson
Joined: 26 Jul 2011 |
Posts: 0 |
|
|
 |
Posted: Tue Jul 26, 2011 3:00 am |
|
 |
 |
 |
 |
thanks for your help - I think I'm going to have well over 100 of these files, "permission denied".
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Jul 26, 2011 1:56 pm |
|
 |
 |
 |
 |
That is a lot, but I guess it is on multiple machines, right? Even on one machine, you can get a lot of permission denied files, depending upon what is running when the scan is active. You might upload a few of the most common files to Jotti/Virus Total for a check.
Regards,
|
|
bthomson
Joined: 26 Jul 2011 |
Posts: 0 |
|
|
 |
Posted: Tue Jul 26, 2011 2:56 pm |
|
 |
 |
 |
 |
thanks again for your comments and have a gr8 day!!
|
|
banjkeee
Joined: 24 Aug 2011 |
Posts: 0 |
|
|
 |
Posted: Wed Aug 24, 2011 2:10 pm |
|
 |
 |
 |
 |
Quote: |
You can always upload a file to Jotti at https://virusscan.jotti.org/en or to Virus Total at https://www.virustotal.com/ on the web. |
thanx for the hint. i'm running NOD32 antivirus and when i check my system there plenty of files with denied access. now i'll use these sites to check files if i'm not sure.
https://www.reema.fr/wakka.php?wiki=mobilebooster
https://ecodiag.eu/wakka.php?wiki=MobilePhoneSignalBooster
|
Last edited by banjkeee on Tue Aug 05, 2014 11:19 am; edited 3 times in total
|
 |
 | |  |
hashin
Joined: 24 Nov 2011 |
Posts: 0 |
|
|
 |
Posted: Sat Nov 26, 2011 10:10 am |
|
 |
 |
 |
 |
I too have had such issues with Clam win. I would recommend you to not worry regarding the warnings since some files cannot be accessed by Clam win. I would also like to suggest you to not take the false positives seriously since certain versions do indicate of it.Its always good to use emergency data recovery softwares, to fight the unexpected happenings, there are many top companies like https://www.datanumen.com/aexr Datanumen,data recovery etc are providing such softwares.
|
Last edited by hashin on Fri Dec 02, 2011 9:42 am; edited 1 time in total
|
 |
 | |  |
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sun Nov 27, 2011 1:37 pm |
|
 |
 |
 |
 |
If one ClamWin user has a false positive, then many others will also have it, so you should report all false positives to Clam AV at https://www.clamav.net/lang/en/sendvirus/ on the web. If you are using Clam Sentinel, Clam can not do anything about the "suspicious files" falsely-detected ("infected files" that are falsely-detected should still be reported to Clam. The Sentinel user can whitelist his own falsely-detected "suspicious" files, which rely on Sentinel's own heuristics--not Clam's signatures.
Regards,
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
|  |