ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
False positive with a .rar file
blandyuk


Joined: 07 Jun 2010
Posts: 0
Reply with quote
Clamwin keeps flagging the below file as having: Trojan.Dropper.Bancos.E.1 FOUND

But if you extract the contents and scan the folder, no viruses.

https://www.mongsville.co.uk/vb6_files.rar https://www.mongsville.co.uk/vb6_files.rar

Evil or Very Mad
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Clam compresses all sample files with gzip. If the sample was compressed with something before being gzipped, once-in-a-while a sigmaker may not go far enough and also uncompress the original file after uncompressing the gzip file. This results in a file for the compression, rather than for an uncompressed virus.

Please upload the file to Clam and report it as a false positive at https://www.clamav.net/lang/en/sendvirus/ on the web. Be sure to check the false positive block, and give them the exact name of the falsely-detected virus in the comments section. You will be doing us all a favor.

Regards,
View user's profileSend private message
False positive with a .rar file
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic