ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Is this a false positive? WinCon.SFX - Win.Trojan.Webmoner
Ashen


Joined: 18 Jun 2013
Posts: 0
Reply with quote
Hey.

Clamwin on our webserver issued an alert.
But I think it is a false positive... how can we check if it is really infected or just a false positive?

C:\Program Files\WinRAR\WinCon.SFX: Win.Trojan.Webmoner-169 FOUND
C:\Program Files\WinRAR\WinCon.SFX: moved to 'C:\ProgramData\.clamwin\quarantine\WinCon.SFX.infected'

Thank you.
K.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
To verify a false positive, upload the file to either Jotti or Virus Total. Both services will check the file with multiple antivirus programs, including the Clam AV engine that ClamWin uses. If several other AVs besides Clam detect an infection, it is probably not a false positive. I like to see at least 2 of these AVs detect something: Avira AntiVir, Bit Defender, Eset Nod32, Kaspersky, and Sophos. If the file is not a Windows PE, I will accept only 1 AV because most AVs do not do very well at detecting viruses in other files. I like to use Jotti because it is smaller and therefore quicker, but Virus Total has more detailed information about a file.

If a file turns out to be a false positive detection, please upload it to Clam AV at their web site so they can correct their signature. Use the Submit A File link, and then use the Report A False Positive link--do not use the link for reporting virus infections.
Thank you for using ClamWin!

Regards,
View user's profileSend private message
Is this a false positive? WinCon.SFX - Win.Trojan.Webmoner
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic