ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
False positives on certain tools?
Clay


Joined: 15 Oct 2007
Posts: 0
Location: US
Reply with quote
I've noticed a trend in the AV industry. That certain tools and software are being declared viris's that may not infact be. This is behaviour I would expect from a comercial av. But I was surprised and rather shaken to think that clamwin might also follow this trend. Here's 1 example: https://www.softpedia.com/get/Programming/Patchers/Registry-Patches-Creator.shtml

Is this truly a trojan or is clamwin now getting some definitions from comercial contributers? I'm one of those people who like to fix things. And I having some trouble trusting a/v's that just rip out software that they don't think I should have... Best to you guy's there at clamwin I've been using this since it was an early beta. (It never used to declare my tools viris's before though.Unlike AVG-Norton,ect..)

Edit: That reg patcher is the freeware version. It could very well be a trojan. But still the corperate trend seems to exist.

Edit2: Ooops looks like I posted this in the wrong part of the forum..(Sorry folks)
View user's profileSend private message
Re: False positives on certain tools?
b0ne


Joined: 26 Oct 2006
Posts: 0
Reply with quote
Quote:
Is this truly a trojan or is clamwin now getting some definitions from comercial contributers?


It is an amazing un-useful utility as it is just a duplication of regedit version 4, but I did check it out and it does what it advertises. It should be considered an FP.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Clam and other AVs are incorporating "tools" that can be used/installed by malware writers into their databases. If you knowingly installed it, that's okay--false positive. But if you didn't know about it, that's not okay--potential malware. The AVs have no way of knowing whether or not you know about it, so they tell you of the tool's existence, and then you can do what you want with it.

You can create your own "white list" of files for Clam/ClamWin to ignore in scanning. If you can use Clam's Sigtool, Clam says to do a "Sigtool --md5 file_to_be_whirtelisted" and put the output into a file named "something.fp"--like a file named custom.fp.

Regards,
View user's profileSend private message
Clay


Joined: 15 Oct 2007
Posts: 0
Location: US
Reply with quote
Okay. Thanks.. I was actually more concerned about something else. Other AV's have removed sam spade too. But I noticed clamwin floated right by the stuff I was mostly worried about. It got a cpupla' mid sized rar's.(I know I read it)) But went by some real big ones. I'm good thanks again..
View user's profileSend private message
False positives on certain tools?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic