jaz-e
Joined: 01 Mar 2007 |
Posts: 0 |
|
|
 |
Posted: Thu Mar 01, 2007 5:54 pm |
|
 |
 |
 |
 |
Norton AV has repeatedly detected files of the form C:\Documents and Settings\...\Local Settings\Temp\clamav-2609d426fb6cf59b86611f360d823374.000010f8.clamtmp as Backdoor.Trojan. It is deleting the file as well. It appears its Auto-Protect feature may be doing this around the time of my clamwin scheduled scans. When I look at the containing folder (...Temp\) there are folders of similarly-formed names which contain a single file (clamav-unchm.bin). Can this be explained? What should I do? (Engine version: 0.90)
|
|
sherpya
Joined: 22 Mar 2006 |
Posts: 0 |
Location: Italy |
|
 |
Posted: Thu Mar 01, 2007 6:36 pm |
|
 |
 |
 |
 |
temporaly files of clamav contain signatures of virus so they match if using another av, the virus db itself it's an archive, and it shouldn't be detected,
but you should temporaly disable onaccess av before starting clamwin scanner to avoid this kind of problems
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Thu Mar 01, 2007 6:39 pm |
|
 |
 |
 |
 |
Not to worry! As it scans, ClamWin creates temp files. Sometimes one of these files isn't deleted--for instance, if a scan is stopped. The temp files can contain a virus signature--not a virus, just the signature, and they are supposed to be deleted by ClamWin the next time it runs. Until then, another antivirus program with a resident scanner may see these files and detect them as a virus. I understand the ClamWin developers are working to scramble the data in these temp files to prevent this in the future.
Regards,
|
|
jaz-e
Joined: 01 Mar 2007 |
Posts: 0 |
|
|
 |
Posted: Thu Mar 01, 2007 9:21 pm |
|
 |
 |
 |
 |
Wow! Thanks for the quick responses! I disabled as suggested and ran a test scan without any Norton issues. Nice work!
|
|