ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
False positive detection
Expertone


Joined: 02 Jan 2013
Posts: 0
Reply with quote
I've just installed a Fujitsu server and i receive a false positive from a complete o/s scan:

Code:
----------- SCAN SUMMARY -----------
Known viruses: 1506893
Engine version: 0.97.6
Scanned directories: 11719
Scanned files: 503182
Infected files: 0
Data scanned: 50933.85 MB
Data read: 42144.40 MB (ratio 1.21:1)
Time: 8114.277 sec (135 m 14 s)

Scan Started Wed Jan 02 11:14:24 2013
-------------------------------------------------------------------------------


C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\LAN\INTEL\Pro1000147\W2K3\e1k5132.sys: WIN.Trojan.Agent-49406 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\LAN\INTEL\Pro1000147\W2K3\e1q5132.sys: WIN.Trojan.Agent-51597 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\LAN\INTEL\Pro1000147\W2K8\e1k6032.sys: WIN.Trojan.Agent-44454 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\LAN\INTEL\Pro1000147\W2K8\e1q6032.sys: WIN.Trojan.Agent-44625 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\LAN\INTEL\Pro1000158\W2K8\e1q6032.sys: WIN.Trojan.Agent-49836 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\WinPE\pro1000lgcy\e1k6032.sys: WIN.Trojan.Agent-44454 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\WinPE\pro1000lgcy\e1q6032.sys: WIN.Trojan.Agent-44625 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\Firmware\PrimSupportPack-Win\Intel_LAN_Pro1000_GE\V02.10\Intel_LAN_Pro1000_GE.zip: WIN.Trojan.Agent-49406 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\Firmware\PrimSupportPack-Win\Intel_LAN_Pro1000_GE_E\V03.10\Intel_LAN_Pro1000_GE_E.zip: WIN.Trojan.Agent-49406 FOUND
C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\Firmware\PrimSupportPack-Win\Intel_LAN_Pro1000_GE_Q\V03.10\Intel_LAN_Pro1000_GE_Q.zip: WIN.Trojan.Agent-49406 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 1512787
Engine version: 0.97.6
Scanned directories: 768
Scanned files: 3968
Infected files: 10
Data scanned: 3131.20 MB
Data read: 3263.55 MB (ratio 0.96:1)
Time: 548.699 sec (9 m 8 s)


Because is a complete fresh install i doubt that these drivers are already infected cause they are installed from a system DVD.

Thank You
ExP
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
We are getting some reports of false positive detections by ClamWin that are not detected by Clam AV, which furnishes its scan engine and virus signatures to ClamWin. See if you can upload a couple of those files to Clam AV (one at a time) starting at https://www.clamav.net/lang/en/sendvirus/ on the web. Go to the false positive report link. Some people have reported that Clam AV will not accept the file because it does not detect it.

Let us know what happens.

Regards,
View user's profileSend private message
Expertone


Joined: 02 Jan 2013
Posts: 0
Reply with quote
i try to submit one but seems the engine recognize as a virus:

Result:

This virus is already recognized by ClamAV 0.97.6/16448/Wed Jan 9 06:41:55 2013 (timezone: -0500 ) as WIN.Trojan.Agent-49406 . Be careful when submitting samples and remember to run freshclam!
Check the FAQ now



Please correct the above errors and retry.

Thank you for helping the ClamAV project.

i've submitted the first file:

C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\LAN\INTEL\Pro1000147\W2K3\e1k5132.sys
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
I think you used the virus submission form and not the false positive form. When you get to the ClamAV sendvirus page, there are 2 links together--one is for real viruses and one is for false positive detections. Make sure you use the false positive link.

Regards,
View user's profileSend private message
Expertone


Joined: 02 Jan 2013
Posts: 0
Reply with quote
i've sent the false positive form but no one answered.

here the virustotal check of one file as you can see only clamAV see it as a trojan

C:\Program Files (x86)\Fujitsu\ServerView Suite\Installation Manager\Content\V10.11.08.09\DRV\LAN\INTEL\Pro1000147\W2K8\e1q6032.sys: WIN.Trojan.Agent-44625 FOUND

https://www.virustotal.com/file/e3d28deb42ea0bdff8ac157064d9f662c60a18e282b310d7e19fe68fa9741c2e/analysis/

Is possible that who manage the detection engine ermove these false positive? every tiem my server is scanned receive that list.
Or add a feature to exclude folders!

ty
ExP
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You will not get a receipt for false positive submissions unless you are on the mailing list for Clam signature update notifications. The receipts are included in the detailed list of signature updates. There are so many items in list of signature updates, it is hard to find anything. If you had the submission received message at the top of the page after you submitted the false positive, they have received your submission, and they will address it within a few days (say 2 to 7 days depending upon how busy they are). If you look around on the Clam AV web page, you can probably find out how to get on the mailing list for signature update notifications.

You can configure ClamWin to exclude files/folders from scans. Go to Configuration, Filters, Exclude Matching Filenames. If you exclude a folder, use this format: C:\Malware\* in ClamWin. Exclude a file in this format: filename.extension in ClamWin.

Regards,
View user's profileSend private message
False positive detection
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic