Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 28th, 2006, 10:12 PM
tansu's Avatar
tansu tansu is offline
Frequent Poster
 
Join Date: Sep 2005
Posts: 210
Default Is it good or not? [About Clamwin]

Cheers,
I have more than 25 Virual Machines in my PC. One of them which is named "DenemeTest5" is heavily infected with more than 200 known viruses and this VM is surfed through very dangerous web sites and downloaded tones of malware from them. I use it to test some software reviews for my website.
What ever. I run Nod32 for on-access and Kaspersky 4.5 personal pro, Bitdefender 8 free edition, Clamwin for on-demand also Ewido anti malware on access and Adaware on-demand on the pc, not on the VM. I run a full scan with all of them except ClamWin everyweek, and they find nothing at all.
Today I made a full scan with Clamwin and get this alert:
--------------------------------------

Scan started: Sat Jan 28 20:57:21 2006



ERROR: Can't open file C:\WINDOWS\system32\config\default

ERROR: Can't open file C:\WINDOWS\system32\config\SAM

ERROR: Can't open file C:\WINDOWS\system32\config\SECURITY

ERROR: Can't open file C:\WINDOWS\system32\config\software

ERROR: Can't open file C:\WINDOWS\system32\config\system



C:\Documents and Settings\Tansu\My Documents\My Virtual Machines\DenemeTest5\Windows XP Professional-cl1.vmdk: Hacker.2 FOUND

-- summary --

Known viruses: 43165

Engine version: 0.88

Scanned directories: 5581

Scanned files: 66063

Infected files: 1



Data scanned: 18434.98 MB

Time: 10891.628 sec (181 m 31 s)

-------------------

Completed

Now my question is, while others scan this VM and found nothing, ClamWin found this. Is this a good thing for ClamWin or bad thing? Does a good Av should find somethings in Virtual machines?
Regards
__________________
Turkish
Redmond, we have problem here!
  #2  
Old January 29th, 2006, 12:37 AM
metallicakid15's Avatar
metallicakid15 metallicakid15 is offline
Frequent Poster
 
Join Date: Dec 2005
Posts: 454
Default

sounds good..

dont rely on my responce you might want to wait for a expert to respond
__________________
Metallica #1 band in the World, Slayer # 2, Megadeth # 3

Last edited by Bubba : January 30th, 2006 at 09:39 AM. Reason: combined posts
  #3  
Old January 29th, 2006, 05:00 AM
sweater's Avatar
sweater sweater is offline
Very Frequent Poster
 
Join Date: Jun 2005
Location: The Philippines, the New Jerusalem
Posts: 1,592
I Say! Re: Is it good or not? [About Clamwin]

I am not expert.

I also got some errors like yours, but maybe it's natural for some antivirus to produce this but as long as it didn't cause some malfunctions on your system and it scans and runs smoothly I think its okay. ClamWin finds several trojans on my pc not detected by my anti-trojan scanners.... so Clam is probably one of the best I think, but the only problem w this AV was that it's scans very slow compared to my other scanners. This is the slowest scanner I have ever used.
  #4  
Old January 29th, 2006, 09:50 AM
Bob D's Avatar
Bob D Bob D is offline
Frequent Poster
 
Join Date: Apr 2005
Location: Mass., USA
Posts: 966
Default Re: Is it good or not? [About Clamwin]

I notice some false positives when scanning with the Clam.
Cut/Paste from previous thread:

Open source AV has quite a following.
Primarily used on server end by some big players like Fastmail.
Reviews rarely give it a stellar rating, however, due to being open source, they've had some remarkable signature update response times.
I do like it's simplicity (just hope you're not in a hurry when doing a full scan).

Quote:
Tony W:
Re: how long it take to add any new virus to database in KAV and nod32 ?

ClamAV 2005-10-06 01:00
AntiVir 2005-10-06 01:13
Kaspersky 2005-10-06 01:26
F-Prot 2005-10-06 01:50
Sophos 2005-10-06 03:07
Command 2005-10-06 03:42
Panda 2005-10-06 03:53
McAfee 2005-10-06 at 05:13
Symantec 2005-10-06 at 06:36
F-Secure 2005-10-06 06:45

Quote:
olcay:
I submitted this exe few days ago but NOD still misses it

Service
Service load:
0% 100%
File: 126547.exe
Status:
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 31dc90567e7f5a1c85fa7a8cdb9f118b
Packers detected:
WISESFX DROPPER
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found Trojan.D
downloader.Small.BKE, Application.Adware.NewDotNet.B.Dropper
ClamAV
Found Adware.NewDotNet.B-4
Dr.Web
Found Trojan.DownLoader.3945, Adware.NewDotNet
F-Prot Antivirus
Found nothing
Fortinet
Found Adware/SmallShopper
Kaspersky Anti-Virus
Found Trojan-Downloader.Win32.Small.bke, not-a-virus:AdWare.Win32.NewDotNet
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found AdWare.Win32.NewDotNet
  #5  
Old January 30th, 2006, 01:33 AM
tansu's Avatar
tansu tansu is offline
Frequent Poster
 
Join Date: Sep 2005
Posts: 210
Default Re: Is it good or not? [About Clamwin]

But I need an answer about, should an AV find malwares in a Virtual Machine?
Regards
__________________
Turkish
Redmond, we have problem here!
  #6  
Old January 30th, 2006, 04:58 AM
Happy Bytes
 
Posts: n/a
Default Re: Is it good or not? [About Clamwin]

Quote:
Originally Posted by tansu
But I need an answer about, should an AV find malwares in a Virtual Machine?
Regards

Why should they? They should find malware on a RUNNING VMWare within the installed AV on this VMWare Partition, but not in an image file. How will you clean this file out from the VMWare image file anyway?
  #7  
Old January 30th, 2006, 05:01 AM
Happy Bytes
 
Posts: n/a
Default Re: Is it good or not? [About Clamwin]

ClaimAV doesn't have any proper filetype/virusrecord matching. That means it's possible that it can detect a Win32 Executable infector in some strange file, even without any proper MZ/PE Header.
  #8  
Old January 30th, 2006, 10:41 AM
tansu's Avatar
tansu tansu is offline
Frequent Poster
 
Join Date: Sep 2005
Posts: 210
Default Re: Is it good or not? [About Clamwin]

Thanks for the answares..
__________________
Turkish
Redmond, we have problem here!
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:51 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums