cornbread99
Joined: 01 Mar 2007 |
Posts: 0 |
Location: USA |
|
 |
Posted: Sat Mar 03, 2007 6:10 pm |
|
 |
 |
 |
 |
Anybody know if this is a false positive or not?
K:\U3 Smart Software Downloads\Security\DFSP_060724_U3_LOCALIZED_ESD_STOMP.exe: Trojan.Pocks FOUND
----------- SCAN SUMMARY -----------
Known viruses: 96244
Engine version: 0.90
Scanned directories: 0
Scanned files: 1
Skipped non-executable files: 0
Infected files: 1
Data scanned: 16.47 MB
Time: 18.454 sec (0 m 18 s)
--------------------------------------
Completed
--------------------------------------
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sat Mar 03, 2007 8:15 pm |
|
 |
 |
 |
 |
You said:
"Anybody know if this is a false positive or not? "
Just to be sure, you might configure ClamWin to quarantine and run another scan to put it there. Then I suggest you upload the file to VirusTotal at https://www.virustotal.com/en/virustotalf.html. They will check it for you free against multiple antivirus programs. If ClamWin is the only one that finds it, it is probably a false positive, you can restore it and tell the ClamAV people about the false positive at https://cgi.clamav.net/sendvirus.cgi.
Regards,
|
|
cornbread99
Joined: 01 Mar 2007 |
Posts: 0 |
Location: USA |
|
 |
Posted: Sat Mar 03, 2007 9:43 pm |
|
 |
 |
 |
 |
I've run AD-AWARE SE PERSONAL and AVG FREE on it. I also went to five major FREE ANTIVIRUS SCANNER sites and none of them marked it as infected.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sat Mar 03, 2007 10:05 pm |
|
 |
 |
 |
 |
Then it probably is a false positive, but make sure that the virus is in the databases of the antivirus software you have used. Kaspersky usually does a good job, but I'm not sure about AVG. You can find various names for a virus used by different antivirus programs at:
https://www.virusbtn.com/resources/vgrep/index.xml?
Regards,
|
|
alch
Site Admin
Joined: 27 Nov 2005 |
Posts: 0 |
|
|
 |
Posted: Sun Mar 04, 2007 12:50 am |
|
 |
 |
 |
 |
please see this FAQ
https://www.clamwin.com/content/view/40/27/
|
|