card
Joined: 29 Jan 2009 |
Posts: 0 |
|
|
 |
Posted: Thu Jan 29, 2009 3:45 pm |
|
 |
 |
 |
 |
I'm wondering if this is a false positive?
C:\WINDOWS\$NtUninstallKB951978$\wscript.exe: Trojan.Autorun-292 FOUND
C:\WINDOWS\ServicePackFiles\i386\wscript.exe: Trojan.Autorun-292 FOUND
I uploaded it to https://virusscan.jotti.org/ and ClamWin is the only one that turned this up. Any advice greatly appreciated.
Regards,
David
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Thu Jan 29, 2009 4:46 pm |
|
 |
 |
 |
 |
The way to handle a false positive is to submit it to Clam via their normal virus submission page at https://www.clamav.net/sendvirus/ on the web. When you go to the submission form, be sure to indicate that the file is a false positive and tell them the name of the virus that Clam falsely identifies. You can also make any additional comments you want. They will adjust their signature within a day or so, and ClamWin will also get the change.
Regards,
|
|
dwinter
Joined: 30 Dec 2008 |
Posts: 0 |
|
|
 |
Posted: Fri Jan 30, 2009 1:17 pm |
|
 |
 |
 |
 |
i think it's a false positive, a few machines were reporting it this morning.
c:\2ddf47da7698dca0ef8eea32043f\i386\wscript.ex_: trojan.autorun-292 found
c:\windows\$ntuninstallkb951978$\wscript.exe: trojan.autorun-292 found
c:\windows\servicepackfiles\i386\wscript.exe: trojan.autorun-292 found
i submitted a report on this file today.
|
|
gonavy
Joined: 14 Jul 2008 |
Posts: 0 |
|
|
 |
Posted: Fri Jan 30, 2009 6:47 pm |
|
 |
 |
 |
 |
I too got the same virus in my report. I too went to jottie and ran a scan and nothing came up. I am just wondering if these are in fact flase positives? Seeing this first thing this morning just made me have aterrific start to a terrific day.
|
|
card
Joined: 29 Jan 2009 |
Posts: 0 |
|
|
 |
Posted: Tue Feb 03, 2009 3:55 am |
|
 |
 |
 |
 |
Ok. Thanks GuitarBob, et. al. I see that dwinter submitted it.
Regards,
|
|