ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Addressing False Positives In Windows Systems Files
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
I see that AVG recently "killed" an important Windows XP file. You can read about it at https://securityandthe.net/2008/11/10/avg-virus-scanner-removes-critical-windows-file/ on the Web. The article mentioned ClamWin as one of the alternative scanners to AVG.

How about the efficacy of overriding Quarantine and using Report Only during ClamWin scans when a Windows file is "infected"? The user could then check the file via Jotti/VirusTotal to verify the infection. If this could be done without too much trouble, we could safely use Quarantine, and we would never have a ClamWin user losing access to Windows again because of a false positive in a system file.

Regards,
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
teorically windows files can be verified using windows api and ms signature, unfortunately this process is slow, an idea may be do sign check only if the file is detected as virus
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
and I'm glad to see that we are not the only ones that killed system files Very Happy
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
All AVs have similar problems. Malware is just another program, and many programs have similar code, so false positives happen. Clam did not have enough Windows programs on their false positive "farm" where signatures are checked before they are published. I think they are better now.

Most current malware isn't going to kill a major system file. Malware users can't make any money from a dead computer!

Regards,
View user's profileSend private message
false positives
solos


Joined: 07 May 2009
Posts: 0
Location: belgium
Reply with quote
where can i sent clamwin reports (and screenshots) containing possible fals pos ?

regards bart
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Clam AV furnishes the scanning engine/signature database that ClamWin uses. You can upload both false positive files and undetected virus files to Clam starting at https://www.clamav.net/sendvirus/ on the web. After reading this, there is a link to the the Clam submission/upload page to upload a copy of the file concerned. Be sure to give them the exact name of the virus or false positive virus. If it is a false positive, tell them why you think it is false in the comment block.

Regards,
View user's profileSend private message
Addressing False Positives In Windows Systems Files
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic