 | WIN.TROJAN.RAMNIT-2501 FALSE POSITIVE? |  |
ADVRESOURCE
Joined: 18 Jun 2014 |
Posts: 0 |
Location: TUCSON |
|
 |
Posted: Wed Jun 18, 2014 4:02 pm |
|
 |
 |
 |
 |
I get a virus detection for the following file: c:\program files (x86)\yahoo!\messenger\rgx.dll . I found that computers that did not have the latest virus definitions weren't able to detect this. However, once the new definitions were loaded, the virus was detected. I uninstalled and reinstalled the messenger files and the same results occurred. I ran the VirusTotal program and only ClamWin and AVG found issue of around 50 scanning programs. Please assist. I sent to ClamAV and they said that they're software doesn't detect this virus.
|
|
 |
 | |  |
ROCKNROLLKID
Joined: 23 Sep 2013 |
Posts: 0 |
Location: **UNKNOWN** |
|
 |
Posted: Wed Jun 18, 2014 5:12 pm |
|
 |
 |
 |
 |
You can submit false positives to ClamAV via this link: https://www.clamav.net/lang/en/sendvirus/ there is a link for you to submit false positives there. If you include in the message the virustotal link, they might look into what the issue is. This progress will take a few days, so in the meantime you can ignore the file. AVG is also known to have false positives to, so I am sure that it's a false positive.
|
|
ADVRESOURCE
Joined: 18 Jun 2014 |
Posts: 0 |
Location: TUCSON |
|
 |
Posted: Thu Jun 19, 2014 3:42 pm |
|
 |
 |
 |
 |
I submitted my false positive to ClamAV via the link provided. They wrote back immediately stating that the ClamAV virus definitions do not find the win.trojan.ramnit-2501 virus. What more can I do?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Thu Jun 19, 2014 9:26 pm |
|
 |
 |
 |
 |
The file is probably detected by ClamWin .98.3 and not by the new Clam AV .98.4 detection engine. ClamWin has not ported the Clam AV engine over to Windows yet--will probably do that in a couple of weeks. All you can do now is to exclude/whitelist the filename.extension in ClamWin.
Each Clam AV version has new detections/improvements that ClamWin can not handle until the ClamWin developers synchronize their version with Clam AV. The detection is probably due to a new signature type that ClamWin can not process yet.
Regards,
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by
phpBB © phpBB Group
Design by
phpBBStyles.com |
Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.