Fozzie Bear
Joined: 06 Mar 2013 |
Posts: 0 |
Location: UK |
|
 |
Posted: Wed Mar 06, 2013 8:42 am |
|
 |
 |
 |
 |
Has anyone experienced this issue. Clamwin has recently done a full scan of my win7 home server and warned of viruses found during the scan. This is the relevant section of the log
C:\Vista\Vista\AERTACap.dll: Win.Trojan.Fakesmoke-102 FOUND
C:\Vista\Vista\AERTARen.dll: Win.Trojan.Fakesmoke-103 FOUND
C:\Intel_GLAN\PRO1000\Win32\NDIS5x\e1e5132.sys: Win.Trojan.Agent-170411 FOUND
C:\Intel_GLAN\PRO1000\Win32\NDIS5x\e1y5132.sys: Win.Trojan.Agent-170446 FOUND
Do you think this is a false identification? The drivers have been installed since the system was built and I dont remember clamwin reporting this as a problem before.
Fozzie
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Wed Mar 06, 2013 12:57 pm |
|
 |
 |
 |
 |
This could very well be a false positive detection. The way Clam does their automated signatures sometimes results in some false positives on Windows system files. I see at least one almost every day. The best way to verify a false positive is to upload it to either the Jotti or Virus Total scanning services, where they will scan a file with multiple AVs, including the Clam Engine used by ClamWin. If a couple of quality AVs detect something, it is probably not a false positive. If it is a false positive, visit the Clam AV "submit a file" page and report it via the false positive link. You will be doing all Clam and ClamWin users a favor.
Regards,
|
|
bobp0303
Joined: 01 Mar 2015 |
Posts: 0 |
Location: New York |
|
 |
Posted: Sun Mar 01, 2015 5:14 am |
|
 |
 |
 |
 |
This file appears to be necessary to the system. How can I attach the file image so the ClamWin database gets updated?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sun Mar 01, 2015 5:32 am |
|
 |
 |
 |
 |
Clam AV provides the scanning engine and signature database used by ClamWin. Upload the file to Clam AV as a false positive, and also scan it on Virus Total. That's the best way I can tell you to get it corrected.
Regards,
|
|
bobp0303
Joined: 01 Mar 2015 |
Posts: 0 |
Location: New York |
|
 |
Posted: Sun Mar 01, 2015 5:38 am |
|
 |
 |
 |
 |
I play keyboards -- funny connection! I've already run it through the virus detector and it's adjudged to be not a virus. I'll upload the file and see if we can get the database updated appropriately.
Best regards,
|
|
ROCKNROLLKID
Joined: 23 Sep 2013 |
Posts: 0 |
Location: **UNKNOWN** |
|
 |
Posted: Sun Mar 01, 2015 7:43 pm |
|
 |
 |
 |
 |
I edited out your email so no one sends you spam.
|
|