![]() |
| How to restore system32 files that are quarantined? |
|
GuitarBob
|
If you only have a text file (restore helper file) in quarantine, no file was put in quarantine. When there is only a text file, the file was used/deleted too quickly for ClamWin to act. This is usually okay--say when you are installing a program that uses temp files, but viruses can do this also. I regard a temp .exe file as very suspicious. If that is the case, scan the computer with the Malwarebytes free antimalware program.
You can restore any files that ClamWin puts in quarantine with the QRecover.exe restore file in the ClamWin\program\bin folder. Run it and highlight any file(s) that you want to restore. I do not believe there are no instructions for QRecover, but it is fairly intuitive. If there is any doubt about a quarantined file, run it by Virus Total before you restore it. Be sure to whitelist any false positives for a while--because it could take the Clam AV people a couple of weeks to correct the signature. ClamWin gets its scan engine/virus signatures from Clam AV. You can ignore Virus Total detections from the smaller/mediocre AV programs if there are no accompanying detections by major AVs. I consider Clam AV to be mediocre. That is why I suggested that a detection is probably valid if 2 out of the 5 AVs above detect something. Regards, |
||||||||||||
|
|
|||||||||||||
|
Milardo
|
Thanks for the reply. I've found the files which i know pnkbstrA.exe is from even balance punkbuster a anticheat game program found in games such as wolfenstein enemy territory and battlefield heroes and battlefield play for free. Although it says that clamav doesn't detect anything in virustotal. The other two are .msi files when highlight them seem to be from cyberlink. I think im ok with not using malwarebytes but thanks for that info i will keep it in mind. So with that in mind i think my system is clean for now.
|
||||||||||||
|
|
|||||||||||||
|
ROCKNROLLKID
|
if ClamAV isn't detecting the file, but ClamWin is, then my guess would be there are some porting issues with ClamWin. You are using the latest .98.6 version right?
|
||||||||||||
|
|
|||||||||||||
|
Milardo
|
Hi, yes i am using 0.98.6 of ClamWin
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
There can be a difference in AV versions and signature databases between your computer and an online service. Sometimes the online services aren't up-to-date.
Regards, |
||||||||||||
|
|
|||||||||||||
| How to restore system32 files that are quarantined? |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


