ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
False positive: bpftpserver.exe: Trojan.Agent.ND FOUND
gbsjr


Joined: 14 Feb 2011
Posts: 0
Reply with quote
Quote:
*** Scanning Programs in Computer Memory ***
*** Memory Scan: using ToolHelp ***

C:\Program Files\BulletProof FTP Server v2.3\bpftpserver.exe: Trojan.Agent.ND FOUND
Unloading program C:\Program Files\BulletProof FTP Server v2.3\bpftpserver.exe from memory

*** Scanned 33 processes - 386 modules ***
*** Computer Memory Scan Completed ***

C:\Documents and Settings\Administrator\Desktop\Desktop Docs\BPFTP Server.zip: Trojan.Agent.ND FOUND


This is the ftp server that has been running along with clamwin for over 3 years on my server.

I will set clamwin to do nothing with it. Just so you know.

Gary
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Just to be sure, I suggest you upload the file to Virus Total or Jotti on the web. Either service will scan files for free (one at a time) with multiple AVs, including Clam AV, which furnishes the scanning engine for ClamWin. If several other AVs say it is infected, it probably is for real. I like to see a couple of these AVs verify an infection: AntiVir, Avast, Bit Defender, NOS 32, and Sophos. If the file turns out to be a false positive, submit it to Clam AV so they can correct the signature.

Lately there have been some false positives (primarily generic/heuristic detections) due to ClamWin still using the previous scan engine instead of the new one, but this detection does not look like that is the case here. ClamWin is now testing its Windows port of the new Clam engine, and it should be ready for release soon.

Regards,
View user's profileSend private message
Doxxxer


Joined: 14 Feb 2011
Posts: 0
Reply with quote
Hi gbsjr
its the same for me. 30 min ago ClamWin put my BulletProof FTP server into quarantane!
More AV tests are useless as this .exe-file may have the structure of a virus but it is, in fact, a ftp server.

Coding folks, you should change the engine or give us the chance tu EXclude some files we do not want to be tested. Other AV software has this simple feature.
Thanks a lot for a quick update.

Doxxxer
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You can exclude files or folders from ClamWin's scheduled scans via configuration, filters, exclude matching filenames. Example for a folder: C:\Users\Bob\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine on my machine. Example for a file: xtoph.exe on my machine.

Clam AV furnishes the scan engine and signature database for ClamWin. All false positives (and undetected viruses) should be submitted to Clam AV, which can be accessed via the ClamWin menu: Help, About, Clam AV and then Submit A File on the Clam AV home page. If it is a false positive, on the submisson page, be sure to choose "false positive". Put the name of the false positive detection or undetected virus in the comments section.

The Clam AV sigmakers should fix the false positive or get a signature for an undetected virus within a couple of days. Sometimes a false positive might take a bit longer, as the original sigmaker is generally responsible for his own corrections and may not be available. Clam has one full time sigmaker and several part-timers. It's a small outfit not funded by most of its users, as is ClamWin.

Regards,
View user's profileSend private message
Doxxxer


Joined: 14 Feb 2011
Posts: 0
Reply with quote
@GuitarBob:
Thanks a lot! You solved my problem.

Thread could be closed now ...

Doxxxer
View user's profileSend private message
False positive: bpftpserver.exe: Trojan.Agent.ND FOUND
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic