![]() |
![]() | Windows system files identified as viruses | ![]() |
![]() |
![]() | ![]() |
GuitarBob
![]() |
![]() |
You can submit a copy of those files to Clam AV starting at https://www.clamav.net/sendvirus/ on the web. After reading this page, you can go to the actual submission page. There, be sure to indicate you think it is a false positive, tell them why you think so, and give the exact name of the virus. If there is a false positive, Clam will make sure your files are excluded from detectionl.
I always have trouble getting them to process large files, so please get back here to let us know whether or not you still get a detection after a couple of days. ClamWin has given Clam some of the larger files on behalf of users. A common malware trick is to insert itself in the Windows directory or to infect a Windows file so that you will get a warning if you try to delete it. Clam has had lots of fase positives on the generic Virut malware lately. In the meantime, be sure ClamWin is set to Report Only--don't use Quarantine or Remove for the infected files option. Regards, |
|||||||||||
|
![]() |
![]() | ![]() |
scarlett_156
![]() |
![]() |
Yeah I did that. It does say that these are "virut" viruses. I am not ruling out that they are viruses, but their age indicates that they are probably not. Thanks for the help!
![]() |
|||||||||||
|
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
could you please upload those files somewhere? PM me for FTP server details if you need.
|
|||||||||||
|
![]() |
![]() | ![]() |
scarlett_156
![]() |
![]() |
Here is a "virus" found from last night's scan, looks like the same type as above, on my comp since December, 2007:
C:\WINDOWS\SoftwareDistribution\Download\d2c1d0c034c68640cf949db8e0b3df1a\o12convsp1-en-us.cab: W32.Virut.Gen.D-163 FOUND I did upload those files to clamwin's FTP. Until I hear otherwise, I will assume that these are false positives. Thanks for reading. |
|||||||||||
|
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
thanks,
I think the previous files you uploaded are no longer detected |
|||||||||||
|
![]() |
![]() | ![]() |
scarlett_156
![]() |
![]() |
Thanks, you guys. I really appreciate the help!
![]() |
|||||||||||
|
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
Thank you, with your help these files are no longer detected as false positives for all clamav and clamwin users.
|
|||||||||||
|
![]() |
![]() | ![]() |
dwinter
![]() |
![]() |
The following files were reported on a local machine:
C:\Windows\Installer\2bc8a93.msp: W32.Virut.Gen.D-163 Found C:\Windows\Installer\6c4e2a.msp: W32.Virut.Gen.D-163 Found C:\Windows\Installer\754db8cb.msp: W32.Virut.Gen.D-163 Found C:\Windows\Installer\fc717a7.msp: W32.Virut.Gen.D-163 Found They might also be false positives. Here is the archive containing the MSP files: https://sodpit.com/files/W32.Virut.Gen.D-163.7z Thank you, Darren |
|||||||||||
|
![]() |
![]() | ![]() |
alch
Site Admin
![]() |
![]() |
Thanks. These must be MS Office 12 updates
Can't download: sodpit.com could not be found |
|||||||||||
|
![]() |
![]() | Windows system files identified as viruses | ![]() |
|
||
![]() |
![]() |
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.