ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
uninst.exe in "baidu hi" looks suspicious.does it
mozartghost


Joined: 10 Mar 2010
Posts: 0
Location: Shanghai China
Reply with quote
View user's profileSend private messageSend e-mail
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
If only 2 AVs find an infection, I would suspect that it is a false positive detection. The only exception would be if the virus infecting the file is very new and the AV fraternity has not had a chance to see it yet. You also have to look at the AVs that are doing the detecting. If a couple of the large AVs spot an infection, like McAfee, Symantec, Microsoft, and Trend Micro, it is probably an infection. Additionally, these AVs have pretty good heuristics/generic detection (but sometimes give false positives): AntiVir (Avira), NOD32, and Sophos. So if only one of the large AVs spot something, but a couple of these also spot it, there is probably an infection.

Submit the file to Threat Expert at https://www.threatexpert.com/submit.aspx on the web. They will actually execute the file and send a report to your email address. Their reports usually include a threat ranking. If it has any rank at all, it is probably malicous. Anubis at https://anubis.iseclab.org/ on the web performs a similar service, but it is sponsored by the academic world, while Threat Expert is in the AV community (PC Tools).

Send any false positives to Clam AV at https://www.clamav.net/sendvirus/ on the web.

Regards,
View user's profileSend private message
uninst.exe in "baidu hi" looks suspicious.does it
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic