Mailing List Archive

[clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender
3. To which (.tmp) file do you refer?
There was an image attached with the name. :D
Note the most recent version of ClamWin announced at www.clamwin.com
is 0.99.4 (released March 1st 2018). The current release of ClamAV is
0.103.0 (released September 14th 2020, available at www.clamav.net).:O

Ok, now i'll try the 'clamav-0.103.0-win-x64-portable' :)
https://mastodont.cat/@alejandroindependiente (https://mastodont.cat/@alejandroindependiente)

-------- Mensaje reenviado -------
De: "G.W. Haywood via clamav-users" <clamav-users@lists.clamav.net (mailto:clamav-users@lists.clamav.net?to=%22G.W.%20Haywood%20via%20clamav-users%22%20<clamav-users@lists.clamav.net>)>
Para: "Alejandro Hernández via clamav-users" <clamav-users@lists.clamav.net (mailto:clamav-users@lists.clamav.net?to=%22Alejandro%20Hern%C3%A1ndez%20via%20clamav-users%22%20<clamav-users@lists.clamav.net>)>
CC: "G.W. Haywood" <clamav@jubileegroup.co.uk (mailto:clamav@jubileegroup.co.uk?to=%22G.W.%20Haywood%22%20<clamav@jubileegroup.co.uk>)>
Enviado: 27 de noviembre de 2020 16:48
Asunto: Re: [clamav-users] Clamav File - Virus detected by Microsoft Defender
Hi there, On Fri, 27 Nov 2020, Alejandro Hernández via clamav-users wrote: while I run a scan in 'portable clamwin', Microsoft Defender detects
this (.tmp) file as a virus:
1. The 'portable clamwin' product is not ClamAV, although I believe it
does use a scanning engine based on ClamAV's engine. If you have any
questions about it, you probably need to ask at forum.clamwin.com.

2. Microsoft Defender is a Microsoft Product, if you have concerns
about it, you should ask on a Microsoft support forum. I have no idea
where that might be.

3. To which (.tmp) file do you refer?
Is it normal?
I can't say whether anything is normal or not until I fully understand
the question. I should not be at all surprised to see different scan
results from different scanning engines for the same scanned file. If
you meant to ask why Microsoft Defender finds a virus but ClamWin does
not, then that's a good question. The answer may be because no sample
has yet been submitted for inclusion in the virus databases, or, if it
has, either the team at Cisco/Sourcefire/Talos hasn't yet processed it
or they screwed up (unlikely but it does happen); perhaps your ClamWin
database hasn't been updated; or maybe the scanning engine in ClamWin
is not capable of detecting the virus.

Note the most recent version of ClamWin announced at www.clamwin.com
is 0.99.4 (released March 1st 2018). The current release of ClamAV is
0.103.0 (released September 14th 2020, available at www.clamav.net).

I can see no justification for using an anti-virus product when its
provider apparently does not keep it up to date.

--

73,
Ged.

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net (mailto:clamav-users@lists.clamav.net)
https://lists.clamav.net/mailman/listinfo/clamav-users (https://lists.clamav.net/mailman/listinfo/clamav-users)
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq (https://github.com/vrtadmin/clamav-faq)

http://www.clamav.net/contact.html#ml (http://www.clamav.net/contact.html#ml)
Re: [clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender [ In reply to ]
Hi there,

On Sat, 28 Nov 2020, Alejandro Hern?ndez via clamav-users wrote:
> On Fri, 27 Nov 2020, G.W. Haywood worte:
>
> > 3. To which (.tmp) file do you refer?
>
> There was an image attached with the name. :D

No, I don't think so. :(

But FWIW AFAICT you did not, as seemingly claimed by Mr. Walter H,
send 40MBytes of attachments to this mailing list. :)

> Ok, now i'll try the 'clamav-0.103.0-win-x64-portable' :)

:)

Please let us know whether or not that is an improvement.

--

73,
Ged.

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender [ In reply to ]
On Sat, 28 Nov 2020, G.W. Haywood via clamav-users wrote:

> Hi there,
>
> On Sat, 28 Nov 2020, Alejandro Hern?ndez via clamav-users wrote:
>> On Fri, 27 Nov 2020, G.W. Haywood worte:
>>
>> > 3. To which (.tmp) file do you refer?
>>
>> There was an image attached with the name. :D
>
> No, I don't think so. :(
>
> But FWIW AFAICT you did not, as seemingly claimed by Mr. Walter H,
> send 40MBytes of attachments to this mailing list. :)

I received a message matching that description
and I find it in the archive at:
https://lists.clamav.net/pipermail/clamav-users/2020-October/010095.html

I was surprised that the list delivered it.

--
Andrew C. Aitchison Kendal, UK
andrew@aitchison.me.uk

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender [ In reply to ]
Hi there,

On Sat, 28 Nov 2020, Andrew C Aitchison via clamav-users wrote:
> On Sat, 28 Nov 2020, G.W. Haywood via clamav-users wrote:
>>
>> But FWIW AFAICT you did not, as seemingly claimed by Mr. Walter H,
>> send 40MBytes of attachments to this mailing list. :)
>
> I received a message matching that description
> and I find it in the archive at:
> https://lists.clamav.net/pipermail/clamav-users/2020-October/010095.html
>
> I was surprised that the list delivered it.

Thanks for the pointer, and I stand corrected - I should have checked
the online archives. I've just checked our logs again, as I thought
that perhaps I'd missed a rejection. But that message was definitely
never offered to our servers. If it had been, then on grounds of size
alone it would have been rejected. A little odd, and a pity that this
isn't the same thread, but I'm not going to lose any sleep over it.

More importantly as you say, it's rather surprising that an anti-virus
mailing list would send a message like that to *anyone* other than the
list's administrators.

Micah?

--

73,
Ged.

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender [ In reply to ]
I'm sorry for the inconveniences.

The 'clamav tmp file' detected by M-Defender was:
file: C:\Users\Alejandro\AppData\Local\Temp\ClamWinPortableTemp\clamav-04c260ec0d7bc2675378f5ead51c44d0.00001648.clamtmp

Detected: Trojan:Win32/Wacatac.C!ml


https://mastodont.cat/@alejandroindependiente

28 de noviembre de 2020 13:50, "G.W. Haywood via clamav-users" <clamav-users@lists.clamav.net>
escribió:

> Hi there,
>
> On Sat, 28 Nov 2020, Andrew C Aitchison via clamav-users wrote:
>
>> On Sat, 28 Nov 2020, G.W. Haywood via clamav-users wrote:
>>>>> But FWIW AFAICT you did not, as seemingly claimed by Mr. Walter H,
>>> send 40MBytes of attachments to this mailing list. :)
>>
>> I received a message matching that description
>> and I find it in the archive at:
>> https://lists.clamav.net/pipermail/clamav-users/2020-October/010095.html
>>
>> I was surprised that the list delivered it.
>
> Thanks for the pointer, and I stand corrected - I should have checked
> the online archives. I've just checked our logs again, as I thought
> that perhaps I'd missed a rejection. But that message was definitely
> never offered to our servers. If it had been, then on grounds of size
> alone it would have been rejected. A little odd, and a pity that this
> isn't the same thread, but I'm not going to lose any sleep over it.
>
> More importantly as you say, it's rather surprising that an anti-virus
> mailing list would send a message like that to *anyone* other than the
> list's administrators.
>
> Micah?
>
> --
> 73,
> Ged.
>
> _______________________________________________
>
> clamav-users mailing list
> clamav-users@lists.clamav.net
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
>
> http://www.clamav.net/contact.html#ml

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender [ In reply to ]
Hi there,

On Sat, 28 Nov 2020, Alejandro Hern?ndez via clamav-users wrote:

> The 'clamav tmp file' detected by M-Defender was:
> file: C:\Users\Alejandro\AppData\Local\Temp\ClamWinPortableTemp\clamav-04c260ec0d7bc2675378f5ead51c44d0.00001648.clamtmp
>
> Detected: Trojan:Win32/Wacatac.C!ml

Now I think I understand.

It appears that you ran ClamWinPortable, which produced some temporary
files and left them lying around in the filesystem. ClamAV does use
the filesystem for temporary storage, so that isn't very surprising.

Windows Defender then found something in one of these temporary files.

It's possible that this is a 'false positive'. False positives are
not uncommon. Or it might be that ClamWin really did find something
nasty, and left some evidence in its temporary directory. I know very
little about how ClamWin behaves.

But one of the tricks that malware authors get up to is disguising the
files that they create in your filesystem as something else. So if it
seems likely that the temporary file really was created by ClamWin (it
should for example have a timestamp at a time when ClamWin was running)
and wasn't created by malware (which I think is unlikely but possible)
then the simplest thing to do would be to delete it. If you are going
to remove ClamWin 0.99.4 and install 0.103 the you can probably delete
everything relating to ClamWinPortable anyway. You might want first
to upload the file to VirusTotal or Jotti's virus scan to see if the
dozen or more other virus scanners they use think it's a problem.

https://virustotal.com/
https://virusscan.jotti.org/

Has the computer ever suffered from malware?

--

73,
Ged.

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml
Re: [clamav-users] Fwd: Re: Clamav File - Virus detected by Microsoft Defender [ In reply to ]
> Has the computer ever suffered from malware?
Yes. ;P



https://mastodont.cat/@alejandroindependiente

29 de noviembre de 2020 1:22, "G.W. Haywood via clamav-users" <clamav-users@lists.clamav.net>
escribió:

> Hi there,
>
> On Sat, 28 Nov 2020, Alejandro Hernández via clamav-users wrote:
>
>> The 'clamav tmp file' detected by M-Defender was:
>> file:
>> C:\Users\Alejandro\AppData\Local\Temp\ClamWinPortableTemp\clamav-04c260ec0d7bc2675378f5ead51c44d0.00
>> 01648.clamtmp
>>
>> Detected: Trojan:Win32/Wacatac.C!ml
>
> Now I think I understand.
>
> It appears that you ran ClamWinPortable, which produced some temporary
> files and left them lying around in the filesystem. ClamAV does use
> the filesystem for temporary storage, so that isn't very surprising.
>
> Windows Defender then found something in one of these temporary files.
>
> It's possible that this is a 'false positive'. False positives are
> not uncommon. Or it might be that ClamWin really did find something
> nasty, and left some evidence in its temporary directory. I know very
> little about how ClamWin behaves.
>
> But one of the tricks that malware authors get up to is disguising the
> files that they create in your filesystem as something else. So if it
> seems likely that the temporary file really was created by ClamWin (it
> should for example have a timestamp at a time when ClamWin was running)
> and wasn't created by malware (which I think is unlikely but possible)
> then the simplest thing to do would be to delete it. If you are going
> to remove ClamWin 0.99.4 and install 0.103 the you can probably delete
> everything relating to ClamWinPortable anyway. You might want first
> to upload the file to VirusTotal or Jotti's virus scan to see if the
> dozen or more other virus scanners they use think it's a problem.
>
> https://virustotal.com
> https://virusscan.jotti.org
>
> Has the computer ever suffered from malware?
>
> --
>
> 73,
> Ged.
>
> _______________________________________________
>
> clamav-users mailing list
> clamav-users@lists.clamav.net
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
>
> http://www.clamav.net/contact.html#ml

_______________________________________________

clamav-users mailing list
clamav-users@lists.clamav.net
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml