![]() |
| False Positives |
|
GuitarBob
|
Yes, I think the issue is back because Microsoft had some patch(es) Tuesday that affected Excel. Every time it patches something, it changes the file, and there are new problems with false positives. The files with false positives are "whitelisted" based on their MD5 hash. When Microsoft issues a new patch for a file, the file hash changes and the whitelisted file has is no good! There must be an easier way! Those patches make a lot of work for everyone. I have had little niggling problems with my computer lots of times because of them.
Please submit false positives to Clam AV at https://www.clamav.net/sendvirus/ on the web. Tell them all the particulars--false positive virus name, etc. and upload the problem file to them. I understand they have increased the size allowed for false positives, so hopefully it will handle what is submitted. Regards, |
||||||||||||
|
|
|||||||||||||
|
jebenson
|
Thanks for the reply. I had surmised that an update was the issue, but it's nice to have confirmation. I have already uploaded the files.
Thanks again. |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
The operating system/Office suite false positives are really caused by Microsoft supporting its buggy operating system (Windows). Unfortunately, ClamWin/Clam AV users have to cope with it.
If we all used Open Office, that would help some, and if we all used another operating system, that would pretty much stop it! Regards, |
||||||||||||
|
|
|||||||||||||
| False Positives |
|
terriart
|
How do you know if something is a false positive? I had trouble with the McAfee freezing my computer and shutting down some of my programs, but now I am getting all these Trojan messages. Makes me nervous. Just got ClaimWin yesterday. |
||||||||||||||
|
|
|||||||||||||||
| False Positives |
|
terriart
|
Sorry -- I did the first post wrong. Newbie.
Thank you so much. |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
If you get several detections of the same virus, it is likely to be a false positive. With a few exceptions, viruses tend to be stealthy, and infecting lots of files is not a good way to hide from detection.
You can verify whether or not a detection is a false positive by uploading the file in question to Jotti or VirusTotal. Both services perform free scans of a file with multiple antivirus products, including Clam AV, which furnishes the detection engine and signatures for ClamWin. If several other AVs besides Clam find a file is infected, it probably is. I like to see at least 5 AVs detect something before I believe it is infected. I also like to see a couple of these AVs verify something: Avast, Bitdefender, Kaspersky, NOD32, Sophos, Microsoft, Symantec, McAfee. Jotti is at https://virusscan.jotti.org/en-gb on the web. VirusTotal is at https://www.virustotal.com/ on the web. Regards, |
||||||||||||
|
|
|||||||||||||
|
terriart
|
GuitarBob,
Thank you so much. I will do that. I really appreciate your help. |
||||||||||||
|
|
|||||||||||||
| FileFormatConverters.exe |
|
DG12
|
Is this a false positive or a know virus?
FileFormatConverters.exe 28,868,230 12/09/2008 |
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Upload the file in quesiton to Jotti at https://virusscan.jotti.org/en-gb on the web or to VirusTotal at https://www.virustotal.com/ on the web. If several other AVs (besides Clam AV) spot an infection, it is probably a real infection and not a false positive. If you are still in doubt, if a couple of these AVs spot an infection, it it is probably real: Avast, Bitdefender, Kaspersky, NOD32, and Sophos.
If it turns out to be a false positive, visit Clam AV at https://www.clamav.net/lang/en/sendvirus/ to submit the file to Clam so they can correct it. When you get to the upload page, be sure to indiciate it is a false positive, and tell them the exact name of the false positive in the Comments section--also tell the results on Jotti/VirusTotal. Regards, |
||||||||||||
|
|
|||||||||||||
| False Positives |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


