ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Strange Scan Results
nosophorus


Joined: 16 Mar 2012
Posts: 0
Location: Nowhere
Reply with quote
Hi!

I'm a Linux user (Ubuntu 10.04 Lucid Lynx) and I have two partitions on my machine: One with Linux (with ClamAV 0.97.3 installed) and another one with Windows XP (with Avast installed). From times to times, I mount in Linux my Windows partition to look for viruses that Avast may have missed and today I have found something a little bit strange, because these files were qualified as malware by ClamAV:

Quote:
/media/149C980D72D5DF52/Documents and Settings/username/Configuraç?es locais/Temp/ICReinstall/cnet2_RCATSetup_exe.exe: Adware.Downloader-207 FOUND

/media/149C980D72D5DF52/Documents and Settings/username/Configuraç?es locais/Temp/jre-6u30-windows-i586-iftw-rv.exe: Trojan.Agent-269363 FOUND

/media/149C980D72D5DF52/Documents and Settings/username/Configuraç?es locais/Temp/is1598539481/179088_Setup.CIS: Adware.BHO-1806 FOUND

/media/149C980D72D5DF52/System Volume Information/_restore{39F94AFC-893A-4291-BAA7-23240F463AC7}/RP180/A0059002.exe: Adware.Downloader-207 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 1168645
Engine version: 0.97.3
Scanned directories: 8893
Scanned files: 63193
Infected files: 4
Data scanned: 12923.92 MB
Data read: 17905.96 MB (ratio 0.72:1)
Time: 3848.002 sec (64 m 8 s)


I updated the ClamAV engine exactly before the scanning -- and I think it is the newest one available. I update the engine using a PPA (ppa.launchpad.net/ubuntu-clamav/ppa/ubuntu lucid main).

Those results seem a little bit strange to me, because they are listing a JRE as a malware. Is that correct?

I used Jotti to confirm those results. Here you are what it got:

https://virusscan.jotti.org/en/scanresult/f0ab7097747958d3e177e08bfa5fa9b93c94afa8/24ee28f405cc180050c0017da6cbfcb624a8366f cnet2_RCATSetup_exe.exe
https://virusscan.jotti.org/en/scanresult/a27eb431c550812ccb03d9d827a9511d7ae24584 A0059002.exe
https://virusscan.jotti.org/en/scanresult/d6090bcc734ce3606047da55d0e9a52af0dee8a4 179088_Setup.CIS
https://virusscan.jotti.org/en/scanresult/1b5bf7f49bce7a355b26ea8a003b11804b0cce54/ce12b3e466dd6b74ac0c9dc8185e4e5e7b93caa0 jre-6u30-windows-i586-iftw-rv.exe

What do you think about that? Should those files be removed from the Windows XP partition?

Many thanks in advance!

See You!!
View user's profileSend private message
Strange Scan Results
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic