ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Email.E-card FOUND and Email.Phishing.RB-1309 FOUND False??
bradpskiff


Joined: 25 Jul 2007
Posts: 0
Location: USA
Reply with quote
I've been getting these 2 consistently with clamwin-090.2.1 and 0.91.1 also. I don't detect them with Avast at all.

1. Are they false positives?
2. If not, How can I remove them?

The mailbox is too large to send to virustotal.com for multiple scanner tests.

Scan Started Wed Jul 25 07:51:06 2007
-------------------------------------------------------------------------------

C:\Documents and Settings\Bradley\Application Data\Thunderbird\Profiles\qvvodt1t.Brad\Mail\mail.comcast.net\Inbox: Not deleting/moving mailbox
C:\Documents and Settings\Bradley\Application Data\Thunderbird\Profiles\qvvodt1t.Brad\Mail\mail.comcast.net\_bs_mail: Not deleting/moving mailbox

C:\Documents and Settings\Bradley\Application Data\Thunderbird\Profiles\qvvodt1t.Brad\Mail\mail.comcast.net\Inbox: Email.E-card FOUND
C:\Documents and Settings\Bradley\Application Data\Thunderbird\Profiles\qvvodt1t.Brad\Mail\mail.comcast.net\_bs_mail: Email.Phishing.RB-1309 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 140254
Engine version: 0.91.1
Scanned directories: 50
Scanned files: 171
Skipped non-executable files: 0
Infected files: 2

Data scanned: 231.02 MB
Time: 40.407 sec (0 m 40 s)
--------------------------------------
Completed
--------------------------------------

Sincerely,

bradpskiff
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
they are likely to be false positives or harmless. you may add the whole mail to the exclusion list, keeping the <> marks to tell it is a regular expression
<C:\\Documents and Settings\\Bradley\\Application Data\\Thunderbird\\Profiles\\qvvodt1t\.Brad\\Mail\\.*>
View user's profileSend private message
SDF file extension, "Email.E-Card" (Clam AntiVirus
cbgerry


Joined: 03 Oct 2007
Posts: 0
Location: USA
Reply with quote
SDF file extension, "Email.E-Card" (Clam AntiVirus) ....

The one below is what Clam found as the 'Email.E-Card' threat and is a false positive apparently. (MSN subscriber since 2001).

Extension: SDF (Search Results)
MSN Local Machine Mail Storage File (Microsoft)
https://filext.com/file-extension/sdf

"If you have the account abc@msn.com this file will usually be named ABC-MSN-COM.SDF and is typically located in C:\DOCUMENTS AND SETTINGS\\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\MSN\DB.
.....
This is record 16328 last modified on 2004-04-06."
View user's profileSend private message
Email.E-card FOUND and Email.Phishing.RB-1309 FOUND False??
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic