![]() |
![]() | Nod32 found 2 Trojans made by ClamWin | ![]() |
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
Clamwin creates temp filers when it unpacks archives, therefore it can be a real virus packed in an archive or a false positive from Nod32.
You may scan the quarantined file at https://www.virustotal.com and see what other AV vendors think about it. |
|||||||||||
|
![]() |
![]() | ![]() |
deanz
![]() |
![]() |
Thanks for that link, here is the result.
https://i42.tinypic.com/2nsq8oh.jpg https://i42.tinypic.com/2nsq8oh.jpg |
|||||||||||
|
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
I like to see a least 5 AVs spot something before I say it is infected. Even then, however, you have to look at the AVs that are spotting an infection and how they spot it. In this case, note that AntiVir and Secure Gateway have the same exact name--they probably share a common signature database (to save costs). The detection is spotted via heuristics (a guess--it's not an exact name) because the file uses the XPack packer. QuickHeal also spots the file via heuristics--"suspicious, DNA Scan." It also looks to me like NOD32 may be spotting the infection via heuristics--"Kryptik" looks like it may refer to a packer/crypt program.
Some AVs are pretty agressive with their heuristics--they would rather be wrong than have a virus slip by their product and hurt one of their customers. They also do pretty well on tests that contain lots of infected files. I think you have a false positive here and you should tell NOD32 about it. When you get close to 10 AVs spotting something, that's probably a real infection. Regards, |
|||||||||||
|
![]() |
![]() | ![]() |
deanz
![]() |
![]() |
Thanks GuitarBob for that reply, I was kinda hoping that Nod was just a bit too aggressive. I noticed Nod sent 3 files off for checking and the ClamWin file was one of them so maybe sometime soon when I rerun ClamWin Nod will be happy with it
![]() Cheers, Dean. |
|||||||||||
|
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
You should tell an AV if you think it has detected a false positive. Many people do not, so you help to improve the AV's detection and prevent problems for a "good" piece of software when you report false positives. I once had a NOD 32 false positive on the GoBack hard drive snapshot program because it made a change in the master boot record of Windows. NOD 32 fixed in in about one day.
Regards,[/list] |
|||||||||||
|
![]() |
![]() | ![]() |
ols
![]() |
![]() |
No, it depend.
|
|||||||||||
|
![]() |
![]() | Nod32 found 2 Trojans made by ClamWin | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.