ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
False Positive with ACT! for Windows 7?
nick.mucci


Joined: 12 Feb 2007
Posts: 0
Location: Lawrence, KS
Reply with quote
Hi,

I just noticed today that ClamWin has "found" a virus in one of my ACT! database files. Its an 83MB *.rdb file. ClamWin claims it has found "Suspect.Zip" but I'm not so sure. I'm running engine 0.88.7 and my virus database files are as follows:

main.cvd is up to date (version: 42, sigs: 83951, f-level: 10, builder: tkojm)
daily.cvd is up to date (version: 2560, sigs: 6116, f-level: 9, builder: ccordes)

Any help or insight into this would be most appreciated.

-Nick
View user's profileSend private message
Suspect.Zip
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
A search of the ClamAV signature database at https://clamav-du.securesites.net/cgi-bin/clamgrok didnt turn up anything. If you have the item in quarantine, you could upload it to VirusTotal and scan it with other antivirus programs at https://www.virustotal.com/en/virustotalf.html. If none of the other antivirus programs find anything, it is probably a false positive, which it sounds like since it isn't even in ClamWin's signature database. Send the item to ClamAV (maybe at https://cgi.clamav.net/sendvirus.cgi) so they are aware of the false positive and can fix it.

Regards,
View user's profileSend private message
Re: False Positive with ACT! for Windows 7?
b0ne


Joined: 26 Oct 2006
Posts: 0
Reply with quote
nick.mucci wrote:
ClamWin claims it has found "Suspect.Zip" but I'm not so sure.


Suspect.Zip is similar to Broken.Exe, it isn't actually any "virus" or anything containing a signature. It just means that it is a suspicious zip file. Microsoft probably password encrypts their zips which would make it "suspicious."

Ignore it.
View user's profileSend private message
Thank you
nick.mucci


Joined: 12 Feb 2007
Posts: 0
Location: Lawrence, KS
Reply with quote
Thanks for your help. I've used other scanners on the file and turned up nothing. The people who make ACT! are MS fans and everything goes into an MSSQL database, so perhaps there is some MS voodoo going on in the file. Also thanks for the heads up on those other sites, I appreciate it.
View user's profileSend private message
False Positive
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Most likely there was a difference between the zip file header and something in the file. ClamWin did its job.

Regards,
View user's profileSend private message
False Positive with ACT! for Windows 7?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic