oldyellr
Joined: 16 Nov 2018 |
Posts: 0 |
|
|
 |
Posted: Sun Mar 08, 2020 5:31 pm |
|
 |
 |
 |
 |
I have Clamwin scheduled to rum on my Win XP computer weekly. It always comes up with similar results. 6 infected files and files it can't access. Below is the last scan report, which is typical. How do I fix this?
Scan Started Thu Mar 05 03:00:00 2020
-------------------------------------------------------------------------------
*** Scanning Programs in Computer Memory ***
*** Memory Scan: using ToolHelp ***
*** Scanned 54 processes - 506 modules ***
*** Computer Memory Scan Completed ***
C:\Documents and Settings\john\Application Data\Thunderbird\Profiles\zyote3gs.default\Mail\Local Folders\Ebay: Html.Phishing.Auction-106 FOUND
C:\Documents and Settings\john\Application Data\Thunderbird\Profiles\zyote3gs.default\Mail\Local Folders\z SAVE.sbd\Airmiles: Heuristics.Phishing.Email.SpoofedDomain FOUND
C:\Documents and Settings\john\Application Data\Thunderbird\Profiles\zyote3gs.default\Mail\Local Folders\z SAVE.sbd\spamstuff: Html.Phishing.Pay-155 FOUND
WARNING: Can't open file \\?\C:\hiberfil.sys: Permission denied
C:\old_c\WINDOWS\Application Data\Thunderbird\Profiles\pldqwwbs.default\Mail\Local Folders\SAVE.sbd\Airmiles: Heuristics.Phishing.Email.SpoofedDomain FOUND
WARNING: Can't open file \\?\C:\pagefile.sys: Permission denied
C:\Program Files\Eudora\SAVE.fol\ebay.mbx: Html.Phishing.Auction-106 FOUND
C:\Program Files\Eudora\SAVE.fol\spamstuf.mbx: Html.Phishing.Pay-155 FOUND
WARNING: Can't open file \\?\C:\WINDOWS\SoftwareDistribution\EventCache\{9AB6567B-4B72-41BB-BA15-5EDA0A0DE626}.bin: Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\CatRoot2\tmp.edb: Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\config\DEFAULT: Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\config\SAM: Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\config\SECURITY: Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\config\SOFTWARE: Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\config\SYSTEM: Permission denied
----------- SCAN SUMMARY -----------
Known viruses: 6761062
Engine version: 0.99.4
Scanned directories: 62715
Scanned files: 404416
Infected files: 6
Total errors: 378
Data scanned: 158854.21 MB
Data read: 519558.60 MB (ratio 0.31:1)
Time: 262929.703 sec (4382 m 9 s)
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Mon Mar 09, 2020 3:03 am |
|
 |
 |
 |
 |
Don't worry about the permissions denied items. These files are probably being used by some software in the background at the time of the scan.
ClamWin comes with a default treatment of only reporting infected files. The infected file options are report, remove, or quarantine. Do not ever remove a detected file because it might keep your computer from working if it happens to be a system file. Just change the default infected file option to Quarantine so you can restore it if need by with the QRestore utility in the ClamWin\bin folder. This will get put any detected files in quarantine. ClamWin also has lots of false detections (false positives), so you should scan quarantined files with the free online Virus Total scanning service. If Clam AV (the engine used by ClamWin) is the only AV to detect a file, Virus Total will tell Clam AV about it so they can change their erroneous virus signature. You can also report false positives to Clam AV at https://www.clamav.net/contact on the web--use the link to report malware.
I do not recommend the use of ClamWin any more. It is not a real-time scanner, it scans too slow, and it has not been updated/improved for well over a year now. I recommend you use a real-time scanner such as Microsoft's free/simple Windows Defender on newer computers. If you have an older computer, I recommend you use OS Armor from the people at No Virus Thanks. OS Armor is not an antivirus, but it makes some simple changes to your computer's configuration that will protect it from lots of malware better than many antivirus programs. You can also use OS Armor along with Windows Defender.
Regards,
|
|