On Tue, 2007-03-13 at 00:09 +0100, Pascal Duchatelle wrote:
> Thomas Sprinkmeier a écrit :
> > Is deleting it enough?
> > My advice is to nuke infected systems. Even benign programs rarely
> > uninstall cleanly; malware is nasty and designed not to go quietly.
> >
> >   
> To nuke you mean just reformatting the space and to a re-install ?

Yes.
Remember to install all patches, virus checkers, signature updates etc.
etc. from behind a nice, safe firewall (see
https://isc2.sans.org/survivaltime.html and
http://www.sans.org/rr/papers/index.php?id=1298)

Your system is dual-boot?
Re-installing windows will nuke your bootloader (probably grub or lilo).
You'll have to reinstall it afterwards. Of course, to reinstall it you
gotta boot linux first (chicken and egg :-)
Make a linux boot disk and/or have a live CD (http://www.knoppix.org/)
handy before you start.

> >   
> I naively did this unzipping already when I wanted to upgrade the YEPP 
> studio...
> The sum of the folders  + files sizes looks about the same as the size 
> of the zip archive. Could it be a false positive ?

sounds like it.....
Consider submitting the file to clamav, they're likely to be interested.

> 
> Thank you again
> 
> Pascal

glad to help.


Thomas

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://lurker.clamav.net/list/clamav-users.html

Reply via email to