ADVRESOURCE
Joined: 18 Jun 2014 |
Posts: 0 |
Location: TUCSON |
|
 |
Posted: Wed Jun 18, 2014 4:02 pm |
|
 |
 |
 |
 |
I get a virus detection for the following file: c:\program files (x86)\yahoo!\messenger\rgx.dll . I found that computers that did not have the latest virus definitions weren't able to detect this. However, once the new definitions were loaded, the virus was detected. I uninstalled and reinstalled the messenger files and the same results occurred. I ran the VirusTotal program and only ClamWin and AVG found issue of around 50 scanning programs. Please assist. I sent to ClamAV and they said that they're software doesn't detect this virus.
|
|
ROCKNROLLKID
Joined: 23 Sep 2013 |
Posts: 0 |
Location: **UNKNOWN** |
|
 |
Posted: Wed Jun 18, 2014 5:12 pm |
|
 |
 |
 |
 |
You can submit false positives to ClamAV via this link: https://www.clamav.net/lang/en/sendvirus/ there is a link for you to submit false positives there. If you include in the message the virustotal link, they might look into what the issue is. This progress will take a few days, so in the meantime you can ignore the file. AVG is also known to have false positives to, so I am sure that it's a false positive.
|
|
ADVRESOURCE
Joined: 18 Jun 2014 |
Posts: 0 |
Location: TUCSON |
|
 |
Posted: Thu Jun 19, 2014 3:42 pm |
|
 |
 |
 |
 |
I submitted my false positive to ClamAV via the link provided. They wrote back immediately stating that the ClamAV virus definitions do not find the win.trojan.ramnit-2501 virus. What more can I do?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Thu Jun 19, 2014 9:26 pm |
|
 |
 |
 |
 |
The file is probably detected by ClamWin .98.3 and not by the new Clam AV .98.4 detection engine. ClamWin has not ported the Clam AV engine over to Windows yet--will probably do that in a couple of weeks. All you can do now is to exclude/whitelist the filename.extension in ClamWin.
Each Clam AV version has new detections/improvements that ClamWin can not handle until the ClamWin developers synchronize their version with Clam AV. The detection is probably due to a new signature type that ClamWin can not process yet.
Regards,
|
|