![]() |
| false positives? (excelcnv.exe & *.msp) |
|
alch
Site Admin
|
I sent you a PM with file upload details.
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Clam frequently has false positive identifications of Windows/Office files after Microsoft has issued a security update or after a user installs a new version of such a file. The culprit is often a Virut.Generic detection. Current Windows/Office files with virut false positives have been "whitelisted," but a recently-changed file will not be whitelisted until someone sends it in as a false positive.
Clam can't just easily drop or change a generic signature. They take much more time/effort than the average signature to develop, and they do their job. In the case of the Virut generic signatures, they detect about 90% of the viruts. The signature just happens to include some "good" code in addition to the malware code. What's needed is some assurance that a detection--especially involving Windows/Office files is indeed a real detection by ClamWin. In my opinion, ClamWin has some responsibility for doing this. Clam is primarily concerned with static detection of email files on a Linux box, while Clam is responsibile for detection on boxes actually running Windows. Regards, Regards, |
||||||||||||
|
|
|||||||||||||
|
dwinter
|
@alch: both files mentioned in my report have been uploaded to the ftp site. thanks!
@guitarbob: also, thanks. i just wanted to get these files uploaded so they could check them thoroughly. |
||||||||||||
|
|
|||||||||||||
| false positives? (excelcnv.exe & *.msp) |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


