![]() |
| explorer.exe: Trojan.GenericFF-1 FOUND (false positive!) |
|
GuitarBob
|
I mentioned this to the Clam AV team. Hopefully you will soon see results. In the meantime, you might set ClamWin's infected files option to Report Only, if at all possible--or you could exclude the files involved from ClamWin's scans via Configuration, Filters, Exclude Matching Filenames.
Regards, |
||||||||||||
|
|
|||||||||||||
|
alexsupra
|
Thank you a lot for your work. I thought about such variant with modifying of %appdata%\.clamwin\clamwin.conf (adding new "excludepatterns" values) and now i think that adding "explorer.exe" here would be great better default for my custom configuration anyway. |
||||||||||||||
|
|
|||||||||||||||
|
GuitarBob
|
Per the Clam AV team: make sure you are using the most recent version of ClamWin. Sometimes the older versions are not able to correctly process the new enhanced signatures, and that's what this looks like. If you are using the latest ClamWin (version .96.5), there may be some difference in the Clam code as ported over to ClamWin--this particular detection on .dll files can only happen if the scan engine ignores certain parts of the signature.
Please get back here if you are using the latest version of ClamWin. Regards, |
||||||||||||
|
|
|||||||||||||
| Trojan.GenericFF-1 |
|
MacX
|
Good morning,
Has there been any update on this particular false positive? I submitted a sample a week ago. Seems my machines with LogMeIn, having received an update, are now showing the Trojan.GenericFF-1 associated with the LogMeIn application files. Any assistance you can offer would be greatly appreciated. Thanks, MacX |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
This is a false positive that occurs because the ClamWin scanning engine can't properly interpret one of the new enhanced Clam AV signatures. It can't be corrected by Clam AV via its normal false positive procedure. It will be corrected when ClamWin updates to the new Clam AV engine. I understand a new version of ClamWin is about ready for beta testing. In the meantime, perhaps you should exclude the file from ClamWin scans via the Filters, Exclude Matching Filenames configuration option.
Drop Alch a private message if you would like to be involved with beta testing. We do not have many ClamWin users beta testing, so this would be a great help. An AV is no better than its users! Regards, |
||||||||||||
|
|
|||||||||||||
| Thank you... |
|
MacX
|
GuitarBob,
thank you for the info. I will also reach out to Alch as you suggested and see if we can help with the Beta. Many regards, MacX |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
After you install the new version .97 of ClamWin, there should be no more detectons of this false positive. The signature comes with a "qualifier" that the old version of ClamWin could not read/process. Each new version of the Clam AV engine may contain some signature enhancements that are not available to us Windows users until the ClamWin developers integrate the new engine.
Regards, |
||||||||||||
|
|
|||||||||||||
| explorer.exe: Trojan.GenericFF-1 FOUND (false positive!) |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


