Hi!
I'm a Linux user (Ubuntu 10.04 Lucid Lynx) and I have two partitions on my machine: One with Linux (with ClamAV 0.97.3 installed) and another one with Windows XP (with Avast installed). From times to times, I mount in Linux my Windows partition to look for viruses that Avast may have missed and today I have found something a little bit strange, because these files were qualified as malware by ClamAV:
Quote: |
/media/149C980D72D5DF52/Documents and Settings/username/Configuraç?es locais/Temp/ICReinstall/cnet2_RCATSetup_exe.exe: Adware.Downloader-207 FOUND
/media/149C980D72D5DF52/Documents and Settings/username/Configuraç?es locais/Temp/jre-6u30-windows-i586-iftw-rv.exe: Trojan.Agent-269363 FOUND
/media/149C980D72D5DF52/Documents and Settings/username/Configuraç?es locais/Temp/is1598539481/179088_Setup.CIS: Adware.BHO-1806 FOUND
/media/149C980D72D5DF52/System Volume Information/_restore{39F94AFC-893A-4291-BAA7-23240F463AC7}/RP180/A0059002.exe: Adware.Downloader-207 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 1168645
Engine version: 0.97.3
Scanned directories: 8893
Scanned files: 63193
Infected files: 4
Data scanned: 12923.92 MB
Data read: 17905.96 MB (ratio 0.72:1)
Time: 3848.002 sec (64 m 8 s) |
I updated the ClamAV engine exactly before the scanning -- and I think it is the newest one available. I update the engine using a PPA (ppa.launchpad.net/ubuntu-clamav/ppa/ubuntu lucid main).
Those results seem a little bit strange to me, because they are listing a JRE as a malware. Is that correct?
I used Jotti to confirm those results. Here you are what it got:
https://virusscan.jotti.org/en/scanresult/f0ab7097747958d3e177e08bfa5fa9b93c94afa8/24ee28f405cc180050c0017da6cbfcb624a8366f cnet2_RCATSetup_exe.exe
https://virusscan.jotti.org/en/scanresult/a27eb431c550812ccb03d9d827a9511d7ae24584 A0059002.exe
https://virusscan.jotti.org/en/scanresult/d6090bcc734ce3606047da55d0e9a52af0dee8a4 179088_Setup.CIS
https://virusscan.jotti.org/en/scanresult/1b5bf7f49bce7a355b26ea8a003b11804b0cce54/ce12b3e466dd6b74ac0c9dc8185e4e5e7b93caa0 jre-6u30-windows-i586-iftw-rv.exe
What do you think about that? Should those files be removed from the Windows XP partition?
Many thanks in advance!
See You!!