ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
How can I do with AvastBCL-Sfx.exe found, please ?
cleroy61


Joined: 27 Sep 2014
Posts: 0
Location: France - Normandie
Reply with quote
Hi everybody,

I have scan with the last clamwin v0.98.4.1 :

Report file :
Quote:
"WARNING: Can't open file C:\pagefile.sys: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\CatRoot2\tmp.edb: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\default: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\SAM: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\SECURITY: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\software: Permission denied
WARNING: Can't open file C:\WINDOWS\system32\config\system: Permission denied

C:\Program Files\AVAST Software\Avast\AvastBCL-Sfx.exe: Win.Adware.Mplug-52 FOUND"

----------- SCAN SUMMARY -----------

Known viruses: 3568446
Engine version: 0.98.4.1
Scanned directories: 8207
Scanned files: 51076
Infected files: 1

Total errors: 4

Not copied: 1

Data scanned: 9238.71 MB

Data read: 8102.77 MB (ratio 1.14:1)

Time: 11893.797 sec (198 m 13 s)

--------------------------------------

Completed

--------------------------------------


clamwin found a virus, but doesn't put in quarantime !

I have tried to delete this file but I can't !

1 - What can I do, please ?

This morning with clamwin update database, my avast free alerts me by saying clamwin is a virus !

2 - Do I delete Avast from my computer, please ?

Thank you very much
Have a nice day
Best regards
cleroy61
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Verify the file is infected by uploading it to Virus Total and see if it is detected by any other AVs besides the Clam AV engine used by ClamWin. Look for detection by at least 2 of these AVs: AntiVir, Bitdefender, Eset Nod 32, Kaspersky, or Sophos. It none of them detect it, it is probably a false positive. You should whitelist a false positive so it is not detected by ClamWin. Also upload the falsely-detected file to Clam AV at https://www.clamav.net/fp on the web so they can change their bad signature. If the file is detected by 2 of the AVs above, see below.

ClamWin says the file contains adware, which isn't as bad as a virus, but you probably do not want it around anyway. The ClamWin infected file option has 3 choices--Report, Quarantine, or Remove (never use Remove). It comes with a default of Report. If you have not changed the option since ClamWin was installed, change it to Quarantine and re-scan your computer. It should remove the infected file then. If the option is already set to Quarantine, uninstall Avast and re-install it and see if it is still detected by ClamWin. You should download Avast from the official link at their website.

If you are unable to remove the file, then install Malwarebytes Free Antimalware and to a Quick Scan. If nothing is found, then do a Full Scan.

Thank you for using ClamWin.

Regards,
View user's profileSend private message
cleroy61


Joined: 27 Sep 2014
Posts: 0
Location: France - Normandie
Reply with quote
Thank you very much for replying me !

With Virus Total, only clamwin had detected it : ClamAV Win.Adware.Mplug-52 20140927 ; Others, the results are Ok !

I didn't try others AVs.

I have used Malwarebytes Free Antimalware and it found 4 malwares putting in quarantime !

I have written to : https://www.clamav.net/fp and added the Clamwin analysis report.

The option in my ClamWin is quarantime ;

I'm going to uninstall Avast and trying to launch Clamwin

Thank you very much
Have a nice day
Best regards
cleroy61
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
If Clam AV is the only AV detecting the file, then it is probably a false positive detection.

ClamWin is not a real-time scanner. It does not scan files when they are put on your computer. It only scans files when you do a manual scan or a scheduled scan. Because of this, you should use a real-time scanner like Avast for real-time protection and use ClamWin as a backup scanner. The Clam AV scan engine tends to have more false positives than most AVs, and Clam AV does not develop as many new virus signatures as most AVs.

Avast has recently not been doing as well in the AV tests as it used to do. I think Panda Free Antivirus and Qihoo Total Security are pretty good, and they are both free. Both will work with ClamWin--just exclude the ClamWin quarantine and database folders from the other AV scans to prevent conflicts.

Regards,
View user's profileSend private message
How can I do with AvastBCL-Sfx.exe found, please ?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic