ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Malware or false-positive?
Rappaping


Joined: 13 Aug 2011
Posts: 0
Reply with quote
File:
https://www.nirsoft.net/utils/regdllview.zip

Virustotal scanning:
https://www.virustotal.com/file-scan/report.html?id=8cd04808d7bf502767721dbed6b5e44be6ff4edf361be1dcc357fee53b44a4ec-1313241465

Is this file a real malware or a false-positive?


Last edited by Rappaping on Sat Aug 13, 2011 1:03 pm; edited 1 time in total
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Your link only led to the Virus Total submission page--there was no scan result. Anyway, Clam will sometimes register a PUA detection on some Nirsoft stuff. A PUA is not an indication of a real virus--it only indicates a file that is a Potentially Unwanted Application. A PUA is a file that is a virus tool or one that has been created with a virus tool. If you know about the file and are using it, that is fine. They flag the file as PUA in case you are not aware of it.

If the file is not a PUA, I like to see at least 10 AVs recognize it as infected with a virus. If less than 10 AVs see it as infected, I like to see it recognized by at least 2 of these AVs: AntiVir, Bitdefender, Kaspersky, Nod32, or Sophos, before I accept it as infected. To be sure, re-scan the file, in case some AVs have just placed it in their signatures.

Anubis at https://anubis.iseclab.org/ on the web will actually run the file for you in a sandbox and let you know what happens. They will even rate it for you as to degree of maliciousness.

Regards,
View user's profileSend private message
Malware or false-positive?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic