bren
Joined: 12 Dec 2016 |
Posts: 0 |
|
|
 |
Posted: Mon Dec 12, 2016 3:44 pm |
|
 |
 |
 |
 |
Does anyone see "Win.Worm.Chir-1589" found while running Clamwin? It's found in Matlab compiler runtime lmgrd.exe file.
Thanks!
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Dec 12, 2016 3:54 pm |
|
 |
 |
 |
 |
In addition to ClamWin, you should be running a real-time AV on your computer, so scan that file with it and see what happens. You can also upload the file to Virus Total where it will be scanned with 50+ AVs, including the Clam AV scan engine used by ClamWin. If Clam AV is the only detecting the file on Virus Total, it is a "false positive" detection. Virus Total will notify Clam AV if it is a false positive so Clam AV can correct their signature for that virus. The Clam engine is a little more prone to detecting false positives than many other AVs. On Virus Total, I like to see at least 2 of these AVs detect something before I believe it: Avira, Bitdefender, Eset Nod 32, Kaspersky, and Sophos.
Regards,
|
|
bren
Joined: 12 Dec 2016 |
Posts: 0 |
|
|
 |
Posted: Mon Dec 12, 2016 4:59 pm |
|
 |
 |
 |
 |
Thanks! I ran Virus total and Clamwin is the only one found it.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Dec 13, 2016 1:52 am |
|
 |
 |
 |
 |
It might take Clam AV a while to correct their signature because Cisco owns Clam AV now, and no one works full-time for Clam AV. I suggest that you whitelist that file in ClamWin so it will not be detected. It may take Clam AV a couple of weeks to get around to correcting their signature, so it will probably be okay to delete the file from the whitelist after a couple of weeks. You can go to ClamWin Help, Manual, Configuration, Filters to learn about excluding (whitelisting) files or folders from ClamWin scans.
Regards,
|
|